Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-1999-1519

Publication date:
17/11/1999
Gene6 G6 FTP Server 2.0 allows a remote attacker to cause a denial of service (resource exhaustion) via a long (1) user name or (2) password.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-1092

Publication date:
17/11/1999
tin 1.40 creates the .tin directory with insecure permissions, which allows local users to read passwords from the .inputhistory file.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2000-0073

Publication date:
17/11/1999
Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-0793

Publication date:
17/11/1999
Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-1508

Publication date:
16/11/1999
Web server in Tektronix PhaserLink Printer 840.0 and earlier allows a remote attacker to gain administrator access by directly calling undocumented URLs such as ncl_items.html and ncl_subjects.html.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-1051

Publication date:
16/11/1999
Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-1457

Publication date:
16/11/1999
Buffer overflow in thttpd HTTP server before 2.04-31 allows remote attackers to execute arbitrary commands via a long date string, which is not properly handled by the tdate_parse function.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-1549

Publication date:
16/11/1999
Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modify the user's configuration file and execute commands.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-1190

Publication date:
15/11/1999
Buffer overflow in POP3 server of Admiral Systems EmailClub 1.05 allows remote attackers to execute arbitrary commands via a long "From" header in an e-mail message.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-1528

Publication date:
14/11/1999
ProSoft Netware Client 5.12 on Macintosh MacOS 9 does not automatically log a user out of the NDS tree when the user logs off the system, which allows other users of the same system access to the unprotected NDS session.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-1110

Publication date:
14/11/1999
Windows Media Player ActiveX object as used in Internet Explorer 5.0 returns a specific error code when a file does not exist, which allows remote malicious web sites to determine the existence of files on the client.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2000-0165

Publication date:
13/11/1999
The Delegate application proxy has several buffer overflows which allow a remote attacker to execute commands.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025