Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2017-7563

Publication date:
07/06/2017
In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protection mechanism. This issue occurs because of inconsistency in the number of execute-never bits (one bit versus two bits).
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2015-8326

Publication date:
07/06/2017
The IPTables-Parse module before 1.6 for Perl allows local users to write to arbitrary files owned by the current user.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2015-7514

Publication date:
07/06/2017
OpenStack Ironic 4.2.0 through 4.2.1 does not "clean" the disk after use, which allows remote authenticated users to obtain sensitive information.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2015-7888

Publication date:
07/06/2017
Directory traversal vulnerability in the WifiHs20UtilityService on the Samsung S6 Edge LRX22G.G925VVRU1AOE2 allows remote attackers to overwrite or create arbitrary files as the system-level user via a .. (dot dot) in the name of a file, compressed into a zipped file named cred.zip, and downloaded to /sdcard/Download.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2015-7326

Publication date:
07/06/2017
XML External Entity (XXE) vulnerability in Milton Webdav before 2.7.0.3.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2015-7723

Publication date:
07/06/2017
AMD fglrx-driver before 15.7 allows local users to gain privileges via a symlink attack.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2015-7724

Publication date:
07/06/2017
AMD fglrx-driver before 15.9 allows local users to gain privileges via a symlink attack. NOTE: This vulnerability exists due to an incomplete fix for CVE-2015-7723.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2017-9499

Publication date:
07/06/2017
In ImageMagick 7.0.5-7 Q16, an assertion failure was found in the function SetPixelChannelAttributes, which allows attackers to cause a denial of service via a crafted file.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2017-9500

Publication date:
07/06/2017
In ImageMagick 7.0.5-8 Q16, an assertion failure was found in the function ResetImageProfileIterator, which allows attackers to cause a denial of service via a crafted file.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2017-9501

Publication date:
07/06/2017
In ImageMagick 7.0.5-7 Q16, an assertion failure was found in the function LockSemaphoreInfo, which allows attackers to cause a denial of service via a crafted file.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2017-7314

Publication date:
07/06/2017
An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, while creating a new role, a list of database tables and their columns is available.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025

CVE-2017-7313

Publication date:
07/06/2017
An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, it is possible to read any customer name, master Customer Id, and email address. In other words, anyone can search for users/customers in the system - no authentication is required.
Severity CVSS v4.0: Pending analysis
Last modification:
20/04/2025