Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-1999-0999

Publication date:
19/11/1999
Microsoft SQL 7.0 server allows a remote attacker to cause a denial of service via a malformed TDS packet.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-0987

Publication date:
18/11/1999
Windows NT does not properly download a system policy if the domain user logs into the domain with a space at the end of the domain name.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2000-0352

Publication date:
18/11/1999
Pine before version 4.21 does not properly filter shell metacharacters from URLs, which allows remote attackers to execute arbitrary commands via a malformed URL.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-1519

Publication date:
17/11/1999
Gene6 G6 FTP Server 2.0 allows a remote attacker to cause a denial of service (resource exhaustion) via a long (1) user name or (2) password.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-1092

Publication date:
17/11/1999
tin 1.40 creates the .tin directory with insecure permissions, which allows local users to read passwords from the .inputhistory file.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2000-0073

Publication date:
17/11/1999
Buffer overflow in Microsoft Rich Text Format (RTF) reader allows attackers to cause a denial of service via a malformed control word.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-0793

Publication date:
17/11/1999
Internet Explorer allows remote attackers to read files by redirecting data to a Javascript applet.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-1508

Publication date:
16/11/1999
Web server in Tektronix PhaserLink Printer 840.0 and earlier allows a remote attacker to gain administrator access by directly calling undocumented URLs such as ncl_items.html and ncl_subjects.html.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-1051

Publication date:
16/11/1999
Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-1457

Publication date:
16/11/1999
Buffer overflow in thttpd HTTP server before 2.04-31 allows remote attackers to execute arbitrary commands via a long date string, which is not properly handled by the tdate_parse function.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-1549

Publication date:
16/11/1999
Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modify the user's configuration file and execute commands.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-1190

Publication date:
15/11/1999
Buffer overflow in POP3 server of Admiral Systems EmailClub 1.05 allows remote attackers to execute arbitrary commands via a long "From" header in an e-mail message.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025