Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-1999-0770

Publication date:
29/07/1999
Firewall-1 sets a long timeout for connections that begin with ACK or other packets except SYN, allowing an attacker to conduct a denial of service via a large number of connection attempts to unresponsive systems.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-0700

Publication date:
29/07/1999
Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-1017

Publication date:
28/07/1999
Seattle Labs Emurl 2.0, and possibly earlier versions, stores e-mail attachments in a specific directory with scripting enabled, which allows a malicious ASP file attachment to execute when the recipient opens the message.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2000-0323

Publication date:
28/07/1999
The Microsoft Jet database engine allows an attacker to modify text files via a database query, aka the "Text I-ISAM" vulnerability.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-1018

Publication date:
27/07/1999
IPChains in Linux kernels 2.2.10 and earlier does not reassemble IP fragments before checking the header information, which allows a remote attacker to bypass the filtering rules using several fragments with 0 offsets.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-0710

Publication date:
25/07/1999
The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory, which allows remote attackers to use it as an intermediary to connect to other systems.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-0224

Publication date:
23/07/1999
Denial of service in Windows NT messenger service through a long username.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-1165

Publication date:
21/07/1999
GNU fingerd 1.37 does not properly drop privileges before accessing user information, which could allow local users to (1) gain root privileges via a malicious program in the .fingerrc file, or (2) read arbitrary files via symbolic links from .plan, .forward, or .project files.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-1338

Publication date:
21/07/1999
Delegate proxy 5.9.3 and earlier creates files and directories in the DGROOT with world-writable permissions.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-0811

Publication date:
21/07/1999
Buffer overflow in Samba smbd program via a malformed message command.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-0810

Publication date:
21/07/1999
Denial of service in Samba NETBIOS name service daemon (nmbd).
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-1535

Publication date:
20/07/1999
Buffer overflow in AspUpload.dll in Persits Software AspUpload before 1.4.0.2 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument in the HTTP request.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025