Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2018-17243

Publication date:
20/09/2018
Global Search in Zoho ManageEngine OpManager before 12.3 123205 allows SQL Injection.
Severity CVSS v4.0: Pending analysis
Last modification:
03/12/2018

CVE-2018-17232

Publication date:
20/09/2018
SQL injection vulnerability in archivebot.py in docmarionum1 Slack ArchiveBot (aka slack-archive-bot) before 2018-09-19 allows remote attackers to execute arbitrary SQL commands via the text parameter to cursor.execute().
Severity CVSS v4.0: Pending analysis
Last modification:
26/09/2019

CVE-2018-17235

Publication date:
20/09/2018
The function mp4v2::impl::MP4Track::FinishSdtp() in mp4track.cpp in libmp4v2 2.1.0 mishandles compatibleBrand while processing a crafted mp4 file, which leads to a heap-based buffer over-read, causing denial of service.
Severity CVSS v4.0: Pending analysis
Last modification:
11/04/2023

CVE-2018-17236

Publication date:
20/09/2018
The function MP4Free() in mp4property.cpp in libmp4v2 2.1.0 internally calls free() on a invalid pointer, raising a SIGABRT signal.
Severity CVSS v4.0: Pending analysis
Last modification:
11/04/2023

CVE-2018-17237

Publication date:
20/09/2018
A SIGFPE signal is raised in the function H5D__chunk_set_info_real() of H5Dchunk.c in the HDF HDF5 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. This issue is different from CVE-2018-11207.
Severity CVSS v4.0: Pending analysis
Last modification:
09/08/2023

CVE-2018-17233

Publication date:
20/09/2018
A SIGFPE signal is raised in the function H5D__create_chunk_file_map_hyper() of H5Dchunk.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.
Severity CVSS v4.0: Pending analysis
Last modification:
09/08/2023

CVE-2018-17234

Publication date:
20/09/2018
Memory leak in the H5O__chunk_deserialize() function in H5Ocache.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (memory consumption) via a crafted HDF5 file.
Severity CVSS v4.0: Pending analysis
Last modification:
09/08/2023

CVE-2018-17231

Publication date:
19/09/2018
Telegram Desktop (aka tdesktop) 1.3.14 might allow attackers to cause a denial of service (assertion failure and application exit) via an "Edit color palette" search that triggers an "index out of range" condition. NOTE: this issue is disputed by multiple third parties because the described attack scenario does not cross a privilege boundary
Severity CVSS v4.0: Pending analysis
Last modification:
05/08/2024

CVE-2018-17229

Publication date:
19/09/2018
Exiv2::d2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted image file.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2018-17230

Publication date:
19/09/2018
Exiv2::ul2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted image file.
Severity CVSS v4.0: Pending analysis
Last modification:
24/08/2020

CVE-2018-17228

Publication date:
19/09/2018
nmap4j 1.1.0 allows attackers to execute arbitrary commands via shell metacharacters in an includeHosts call.
Severity CVSS v4.0: Pending analysis
Last modification:
03/10/2019

CVE-2018-8889

Publication date:
19/09/2018
A directory traversal vulnerability in the Connect Service of the BlackBerry Enterprise Mobility Server (BEMS) 2.8.17.29 and earlier could allow an attacker to retrieve arbitrary files in the context of a BEMS administrator account.
Severity CVSS v4.0: Pending analysis
Last modification:
04/12/2018