Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2012-5521

Publication date:
25/11/2019
quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal
Severity CVSS v4.0: Pending analysis
Last modification:
18/08/2020

CVE-2012-5527

Publication date:
25/11/2019
Claws Mail vCalendar plugin: credentials exposed on interface
Severity CVSS v4.0: Pending analysis
Last modification:
11/12/2019

CVE-2012-5535

Publication date:
25/11/2019
gnome-system-log polkit policy allows arbitrary files on the system to be read
Severity CVSS v4.0: Pending analysis
Last modification:
09/12/2019

CVE-2012-5518

Publication date:
25/11/2019
vdsm: certificate generation upon node creation allowing vdsm to start and serve requests from anyone who has a matching key (and certificate)
Severity CVSS v4.0: Pending analysis
Last modification:
09/12/2019

CVE-2012-5582

Publication date:
25/11/2019
opendnssec misuses libcurl API
Severity CVSS v4.0: Pending analysis
Last modification:
09/12/2019

CVE-2012-5630

Publication date:
25/11/2019
libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.
Severity CVSS v4.0: Pending analysis
Last modification:
04/12/2019

CVE-2012-5578

Publication date:
25/11/2019
Python keyring has insecure permissions on new databases allowing world-readable files to be created
Severity CVSS v4.0: Pending analysis
Last modification:
04/12/2019

CVE-2019-14822

Publication date:
25/11/2019
A flaw was discovered in ibus in versions before 1.5.22 that allows any unprivileged user to monitor and send method calls to the ibus bus of another user due to a misconfiguration in the DBus server setup. A local attacker may use this flaw to intercept all keystrokes of a victim user who is using the graphical interface, change the input method engine, or modify other input related configurations of the victim user.
Severity CVSS v4.0: Pending analysis
Last modification:
07/06/2022

CVE-2019-10214

Publication date:
25/11/2019
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.
Severity CVSS v4.0: Pending analysis
Last modification:
28/10/2021

CVE-2019-14891

Publication date:
25/11/2019
A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed if a workload process triggers an out-of-memory (OOM) condition for the cgroup. An attacker could abuse this flaw to get host network access on an cri-o host.
Severity CVSS v4.0: Pending analysis
Last modification:
28/02/2020

CVE-2019-14815

Publication date:
25/11/2019
A vulnerability was found in Linux Kernel, where a Heap Overflow was found in mwifiex_set_wmm_params() function of Marvell Wifi Driver.
Severity CVSS v4.0: Pending analysis
Last modification:
13/07/2023

CVE-2019-10174

Publication date:
25/11/2019
A vulnerability was found in Infinispan such that the invokeAccessibly method from the public class ReflectionUtil allows any application class to invoke private methods in any class with Infinispan's privileges. The attacker can use reflection to introduce new, malicious behavior into the application.
Severity CVSS v4.0: Pending analysis
Last modification:
20/02/2022