Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2004-1608

Publication date:
18/10/2004
SQL injection vulnerability in SalesLogix 6.1 allows remote attackers to execute arbitrary SQL statements via the id parameter in a view operation.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-1609

Publication date:
18/10/2004
SalesLogix 6.1 includes usernames, passwords, and other sensitive information in the headers of an HTTP response, which could allow remote attackers to gain access.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-1611

Publication date:
18/10/2004
SalesLogix 6.1 does not verify if a user is authenticated before performing sensitive operations, which could allow remote attackers to (1) execute arbitrary SLX commands on the server or spoof the server via a man-in-the-middle (MITM) attack, or (2) obtain the database password via a GetConnection request to TCP port 1707.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-1612

Publication date:
18/10/2004
Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot) in a ProcessQueueFile request.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-1616

Publication date:
18/10/2004
Links allows remote attackers to cause a denial of service (memory consumption) via a web page or HTML email that contains a table with a td element and a large rowspan value,as demonstrated by mangleme.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-1610

Publication date:
18/10/2004
SalesLogix 6.1 uses client-specified pathnames for writing certain files, which might allow remote authenticated users to create arbitrary files and execute code via the (1) vMME.AttachmentPath or (2) vMME.LibraryPath variables.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-1614

Publication date:
18/10/2004
Mozilla allows remote attackers to cause a denial of service (application crash from invalid memory access) via an "unusual combination of visual elements," including several large MARQUEE tags with large height parameters, as demonstrated by mangleme.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-1615

Publication date:
18/10/2004
Opera allows remote attackers to cause a denial of service (invalid memory reference and application crash) via a web page or HTML email that contains a TBODY tag with a large COL SPAN value, as demonstrated by mangleme.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-1603

Publication date:
18/10/2004
cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-1621

Publication date:
18/10/2004
NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Domino R6, and possibly earlier versions, allows remote attackers to execute arbitrary web script or HTML via square brackets at the beginning and end of (1) computed for display, (2) computed when composed, or (3) computed text element fields. NOTE: the vendor has disputed this issue, saying that it is not a problem with Notes/Domino itself, but with the applications that do not properly handle this feature
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-1599

Publication date:
16/10/2004
Cross-site scripting (XSS) vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to execute arbitrary web script or HTML via the (1) query or (2) nick parameters.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-1600

Publication date:
16/10/2004
index.php in CoolPHP 1.0-stable allows remote attackers to gain sensitive information via an invalid op parameter, which reveals the path in an error message.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025