Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2001-1497

Publication date:
31/12/2001
Microsoft Internet Explorer 4.0 through 6.0 could allow local users to differentiate between alphanumeric and non-alphanumeric characters used in a password by pressing certain control keys that jump between non-alphanumeric characters, which makes it easier to conduct a brute-force password guessing attack.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2001-1539

Publication date:
31/12/2001
Stack consumption vulnerability in Internet Explorer The JavaScript settimeout function in Internet Explorer allows remote attackers to cause a denial of service (crash) via the JavaScript settimeout function. NOTE: the vendor could not reproduce the problem.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2001-1556

Publication date:
31/12/2001
The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allow remote attackers to hide HTTP requests and spoof source IP addresses when logs are viewed with UNIX programs such as cat, tail, and grep.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2001-1466

Publication date:
30/12/2001
Buffer overflow in VanDyke SecureCRT before 3.4.2, when using the SSH-1 protocol, allows remote attackers to execute arbitrary code via a long (1) username or (2) password.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2001-1207

Publication date:
30/12/2001
Buffer overflows in DayDream BBS 2.9 through 2.13 allow remote attackers to possibly execute arbitrary code via the control codes (1) ~#MC, (2) ~#TF, or (3) ~#RA.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2001-1210

Publication date:
30/12/2001
Cisco ubr900 series routers that conform to the Data-over-Cable Service Interface Specifications (DOCSIS) standard must ship without SNMP access restrictions, which can allow remote attackers to read and write information to the MIB using arbitrary community strings.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2001-1205

Publication date:
30/12/2001
Directory traversal vulnerability in lastlines.cgi for Last Lines 2.0 allows remote attackers to read arbitrary files via '..' sequences in the $error_log variable.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2001-1206

Publication date:
30/12/2001
Matrix CGI vault Last Lines 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the $error_log variable.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2001-1432

Publication date:
29/12/2001
Directory traversal vulnerability in Cherokee Web Server allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2001-1433

Publication date:
29/12/2001
Cherokee web server before 0.2.7 does not properly drop root privileges after binding to port 80, which could allow remote attackers to gain privileges via other vulnerabilities.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2001-1204

Publication date:
28/12/2001
Directory traversal vulnerability in phprocketaddin in Total PC Solutions PHP Rocket Add-in for FrontPage 1.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2001-1202

Publication date:
28/12/2001
Cross-site scripting vulnerability in DeleGate 7.7.0 and 7.7.1 does not quote scripting commands within a "403 Forbidden" error page, which allows remote attackers to execute arbitrary Javascript on other clients via a URL that generates an error.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025