Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-6951

Publication date:
13/02/2018
An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_type function in pch.c, aka a "mangled rename" issue.
Severity CVSS v4.0: Pending analysis
Last modification:
17/04/2019

CVE-2018-6952

Publication date:
13/02/2018
A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6.
Severity CVSS v4.0: Pending analysis
Last modification:
17/04/2019

CVE-2017-18183

Publication date:
13/02/2018
An issue was discovered in QPDF before 7.0.0. There is an infinite loop in the QPDFWriter::enqueueObject() function in libqpdf/QPDFWriter.cc.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2017-18186

Publication date:
13/02/2018
An issue was discovered in QPDF before 7.0.0. There is an infinite loop due to looping xref tables in QPDF.cc.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-6928

Publication date:
13/02/2018
PHP Scripts Mall News Website Script 2.0.4 has SQL Injection via a search term.
Severity CVSS v4.0: Pending analysis
Last modification:
07/03/2018

CVE-2018-6948

Publication date:
13/02/2018
In CCN-lite 2, the function ccnl_prefix_to_str_detailed can cause a buffer overflow, when writing a prefix to the buffer buf. The maximal size of the prefix is CCNL_MAX_PREFIX_SIZE; the buffer has the size CCNL_MAX_PREFIX_SIZE. However, when NFN is enabled, additional characters are written to the buffer (e.g., the "NFN" and "R2C" tags). Therefore, sending an NFN-R2C packet with a prefix of size CCNL_MAX_PREFIX_SIZE can cause an overflow of buf inside ccnl_prefix_to_str_detailed.
Severity CVSS v4.0: Pending analysis
Last modification:
16/03/2018

CVE-2018-0487

Publication date:
13/02/2018
ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a crafted certificate chain that is mishandled during RSASSA-PSS signature verification within a TLS or DTLS session.
Severity CVSS v4.0: Pending analysis
Last modification:
10/02/2020

CVE-2018-0488

Publication date:
13/02/2018
ARM mbed TLS before 1.3.22, before 2.1.10, and before 2.7.0, when the truncated HMAC extension and CBC are used, allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption) via a crafted application packet within a TLS or DTLS session.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2018-6911

Publication date:
13/02/2018
The VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a single argument (aka the command parameter).
Severity CVSS v4.0: Pending analysis
Last modification:
02/08/2019

CVE-2018-6293

Publication date:
13/02/2018
Arbitrary File Read in Saperion Web Client version 7.5.2 83166.
Severity CVSS v4.0: Pending analysis
Last modification:
06/03/2018

CVE-2018-6292

Publication date:
13/02/2018
Remote Code Execution in Saperion Web Client version 7.5.2 83166.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-1297

Publication date:
13/02/2018
When using Distributed Test only (RMI based), Apache JMeter 2.x and 3.x uses an unsecured RMI connection. This could allow an attacker to get Access to JMeterEngine and send unauthorized code.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023