Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2004-0504

Publication date:
18/08/2004
Ethereal 0.10.3 allows remote attackers to cause a denial of service (crash) via certain SIP messages between Hotsip servers and clients.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-0505

Publication date:
18/08/2004
The AIM dissector in Ethereal 0.10.3 allows remote attackers to cause a denial of service (assert error) via unknown attack vectors.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-0506

Publication date:
18/08/2004
The SPNEGO dissector in Ethereal 0.9.8 to 0.10.3 allows remote attackers to cause a denial of service (crash) via unknown attack vectors that cause a null pointer dereference.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-0507

Publication date:
18/08/2004
Buffer overflow in the MMSE dissector for Ethereal 0.10.1 to 0.10.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-0514

Publication date:
18/08/2004
Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to "handling of directory services lookups."
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-0515

Publication date:
18/08/2004
Unknown vulnerability in LoginWindow for Mac OS X 10.3.4, related to "handling of console log files."
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-0516

Publication date:
18/08/2004
Unknown vulnerability in Mac OS X 10.3.4, related to "package installation scripts," a different vulnerability than CVE-2004-0517.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-0517

Publication date:
18/08/2004
Unknown vulnerability in Mac OS X 10.3.4, related to "handling of process IDs during package installation," a different vulnerability than CVE-2004-0516.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-0769

Publication date:
18/08/2004
Buffer overflow in LHA allows remote attackers to execute arbitrary code via long pathnames in LHarc format 2 headers for a .LHZ archive, as originally demonstrated using the "x" option but also exploitable through "l" and "v", and fixed in header.c, a different issue than CVE-2004-0771.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-0779

Publication date:
18/08/2004
The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only sent via SSL encrypted sessions to the site, which allows a remote attacker to cause a cached password to be sent in cleartext to a spoofed site.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-0518

Publication date:
18/08/2004
Unknown vulnerability in AppleFileServer for Mac OS X 10.3.4, related to "the use of SSH and reporting errors," has unknown impact and attack vectors.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-0519

Publication date:
18/08/2004
Multiple cross-site scripting (XSS) vulnerabilities in SquirrelMail 1.4.2 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via multiple attack vectors, including the mailbox parameter in compose.php.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025