Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2021-25498

Publication date:
06/10/2021
A possible buffer overflow vulnerability in maetd_eco_cb_mode of libSPenBase library of Samsung Notes prior to Samsung Notes version 4.3.02.61 allows arbitrary code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
14/10/2021

CVE-2021-25497

Publication date:
06/10/2021
A possible buffer overflow vulnerability in maetd_cpy_slice of libSPenBase library of Samsung Notes prior to Samsung Notes version 4.3.02.61 allows arbitrary code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
14/10/2021

CVE-2021-25496

Publication date:
06/10/2021
A possible buffer overflow vulnerability in maetd_dec_slice of libSPenBase library of Samsung Notes prior to Samsung Notes version 4.3.02.61 allows arbitrary code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
14/10/2021

CVE-2021-29908

Publication date:
06/10/2021
The IBM TS7700 Management Interface is vulnerable to unauthenticated access. By accessing a specially-crafted URL, an attacker may gain administrative access to the Management Interface without authentication. IBM X-Force ID: 207747.
Severity CVSS v4.0: Pending analysis
Last modification:
12/07/2022

CVE-2021-41121

Publication date:
06/10/2021
Vyper is a Pythonic Smart Contract Language for the EVM. In affected versions when performing a function call inside a literal struct, there is a memory corruption issue that occurs because of an incorrect pointer to the the top of the stack. This issue has been resolved in version 0.3.0.
Severity CVSS v4.0: Pending analysis
Last modification:
02/08/2023

CVE-2021-25492

Publication date:
06/10/2021
Lack of boundary checking of a buffer in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows OOB read.
Severity CVSS v4.0: Pending analysis
Last modification:
26/04/2022

CVE-2021-25495

Publication date:
06/10/2021
A possible heap buffer overflow vulnerability in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows arbitrary code execution.
Severity CVSS v4.0: Pending analysis
Last modification:
26/04/2022

CVE-2021-25493

Publication date:
06/10/2021
Lack of boundary checking of a buffer in libSPenBase library of Samsung Notes prior to Samsung Note version 4.3.02.61 allows OOB read
Severity CVSS v4.0: Pending analysis
Last modification:
13/10/2021

CVE-2021-25491

Publication date:
06/10/2021
A vulnerability in mfc driver prior to SMR Oct-2021 Release 1 allows memory corruption via NULL-pointer dereference.
Severity CVSS v4.0: Pending analysis
Last modification:
13/10/2021

CVE-2021-25488

Publication date:
06/10/2021
Lack of boundary checking of a buffer in recv_data() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read.
Severity CVSS v4.0: Pending analysis
Last modification:
13/10/2021

CVE-2021-25484

Publication date:
06/10/2021
Improper authentication in InputManagerService prior to SMR Oct-2021 Release 1 allows monitoring the touch event.
Severity CVSS v4.0: Pending analysis
Last modification:
13/10/2021

CVE-2021-25486

Publication date:
06/10/2021
Exposure of information vulnerability in ipcdump prior to SMR Oct-2021 Release 1 allows an attacker detect device information via analyzing packet in log.
Severity CVSS v4.0: Pending analysis
Last modification:
13/10/2021