Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2014-1348

Publication date:
01/07/2014
Mail in Apple iOS before 7.1.2 advertises the availability of data protection for attachments but stores cleartext attachments under mobile/Library/Mail/, which makes it easier for physically proximate attackers to obtain sensitive information by mounting the data partition.
Severity CVSS v4.0: Pending analysis
Last modification:
07/01/2017

CVE-2014-1349

Publication date:
01/07/2014
Use-after-free vulnerability in Safari in Apple iOS before 7.1.2 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an invalid URL.
Severity CVSS v4.0: Pending analysis
Last modification:
07/01/2017

CVE-2014-1350

Publication date:
01/07/2014
Settings in Apple iOS before 7.1.2 allows physically proximate attackers to bypass an intended iCloud password requirement, and turn off the Find My iPhone service, by leveraging incorrect state management.
Severity CVSS v4.0: Pending analysis
Last modification:
07/01/2017

CVE-2014-1351

Publication date:
01/07/2014
Siri in Apple iOS before 7.1.2 allows physically proximate attackers to bypass an intended lock-screen passcode requirement, and read a contact list, via a Siri request that refers to a contact ambiguously.
Severity CVSS v4.0: Pending analysis
Last modification:
07/01/2017

CVE-2014-1352

Publication date:
01/07/2014
Lock Screen in Apple iOS before 7.1.2 does not properly enforce the limit on failed passcode attempts, which makes it easier for physically proximate attackers to conduct brute-force passcode-guessing attacks via unspecified vectors.
Severity CVSS v4.0: Pending analysis
Last modification:
07/01/2017

CVE-2014-1353

Publication date:
01/07/2014
Lock Screen in Apple iOS before 7.1.2 does not properly manage the telephony state in Airplane Mode, which allows physically proximate attackers to bypass the lock protection mechanism, and access a certain foreground application, via unspecified vectors.
Severity CVSS v4.0: Pending analysis
Last modification:
07/01/2017

CVE-2014-1354

Publication date:
01/07/2014
CoreGraphics in Apple iOS before 7.1.2 does not properly restrict allocation of stack memory for processing of XBM images, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted image data.
Severity CVSS v4.0: Pending analysis
Last modification:
07/01/2017

CVE-2014-1355

Publication date:
01/07/2014
The IOKit implementation in the kernel in Apple iOS before 7.1.2 and Apple TV before 6.1.2, and in IOReporting in Apple OS X before 10.9.4, allows local users to cause a denial of service (NULL pointer dereference and reboot) via crafted API arguments.
Severity CVSS v4.0: Pending analysis
Last modification:
08/03/2019

CVE-2014-1356

Publication date:
01/07/2014
Heap-based buffer overflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbitrary code via a crafted application that sends IPC messages.
Severity CVSS v4.0: Pending analysis
Last modification:
08/03/2019

CVE-2014-1357

Publication date:
01/07/2014
Heap-based buffer overflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbitrary code via a crafted application that generates log messages.
Severity CVSS v4.0: Pending analysis
Last modification:
08/03/2019

CVE-2014-1358

Publication date:
01/07/2014
Integer overflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbitrary code via a crafted application.
Severity CVSS v4.0: Pending analysis
Last modification:
08/03/2019

CVE-2014-1359

Publication date:
01/07/2014
Integer underflow in launchd in Apple iOS before 7.1.2, Apple OS X before 10.9.4, and Apple TV before 6.1.2 allows attackers to execute arbitrary code via a crafted application.
Severity CVSS v4.0: Pending analysis
Last modification:
30/06/2022