Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-19761

Publication date:
30/11/2018
There is an illegal address access at fromsixel.c (function: sixel_decode_raw_impl) in libsixel 1.8.2 that will cause a denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
26/12/2018

CVE-2018-19763

Publication date:
30/11/2018
There is a heap-based buffer over-read at writer.c (function: write_png_to_file) in libsixel 1.8.2 that will cause a denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
26/12/2018

CVE-2018-19757

Publication date:
30/11/2018
There is a NULL pointer dereference at function sixel_helper_set_additional_message (status.c) in libsixel 1.8.2 that will cause a denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
26/12/2018

CVE-2018-19755

Publication date:
30/11/2018
There is an illegal address access at asm/preproc.c (function: is_mmacro) in Netwide Assembler (NASM) 2.14rc16 that will cause a denial of service (out-of-bounds array access) because a certain conversion can result in a negative integer.
Severity CVSS v4.0: Pending analysis
Last modification:
21/12/2018

CVE-2018-19760

Publication date:
30/11/2018
cfg_init in confuse.c in libConfuse 3.2.2 has a memory leak.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-19762

Publication date:
30/11/2018
There is a heap-based buffer overflow at fromsixel.c (function: image_buffer_resize) in libsixel 1.8.2 that will cause a denial of service or possibly unspecified other impact.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2018-19497

Publication date:
29/11/2018
In The Sleuth Kit (TSK) through 4.6.4, hfs_cat_traverse in tsk/fs/hfs.c does not properly determine when a key length is too large, which allows attackers to cause a denial of service (SEGV on unknown address with READ memory access in a tsk_getu16 call in hfs_dir_open_meta_cb in tsk/fs/hfs_dent.c).
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2018-19527

Publication date:
29/11/2018
i4 assistant 7.85 allows XSS via a crafted machine name field within iOS settings.
Severity CVSS v4.0: Pending analysis
Last modification:
26/12/2018

CVE-2018-1000818

Publication date:
29/11/2018
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-19132. Reason: This candidate is a reservation duplicate of CVE-2018-19132. Notes: All CVE users should reference CVE-2018-19132 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2018-1000819

Publication date:
29/11/2018
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-19131. Reason: This candidate is a reservation duplicate of CVE-2018-19131. Notes: All CVE users should reference CVE-2018-19131 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2018-19750

Publication date:
29/11/2018
DomainMOD through 4.11.01 has XSS via the admin/domain-fields/ notes field in an Add Custom Field action for Custom Domain Fields.
Severity CVSS v4.0: Pending analysis
Last modification:
27/12/2018

CVE-2018-19752

Publication date:
29/11/2018
DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar.
Severity CVSS v4.0: Pending analysis
Last modification:
21/12/2018