Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-1999-0446

Publication date:
12/04/1999
Local users can perform a denial of service in NetBSD 1.3.3 and earlier versions by creating an unusual symbolic link with the ln command, triggering a bug in VFS.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-0444

Publication date:
12/04/1999
Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-1323

Publication date:
09/04/1999
Norton AntiVirus for Internet Email Gateways (NAVIEG) 1.0.1.7 and earlier, and Norton AntiVirus for MS Exchange (NAVMSE) 1.5 and earlier, store the administrator password in cleartext in (1) the navieg.ini file for NAVIEG, and (2) the ModifyPassword registry key in NAVMSE.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-0470

Publication date:
09/04/1999
A weak encryption algorithm is used for passwords in Novell Remote.NLM, allowing them to be easily decrypted.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-0801

Publication date:
09/04/1999
BMC Patrol allows remote attackers to gain access to an agent by spoofing frames.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-0287

Publication date:
09/04/1999
Vulnerability in the Wguest CGI program.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-0471

Publication date:
09/04/1999
The remote proxy server in Winroute allows a remote attacker to reconfigure the proxy without authentication through the "cancel" button.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-0468

Publication date:
09/04/1999
Internet Explorer 5.0 allows a remote server to read arbitrary files on the client's file system using the Microsoft Scriptlet Component.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-1196

Publication date:
07/04/1999
Hummingbird Exceed X version 5 allows remote attackers to cause a denial of service via malformed data to port 6000.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-0473

Publication date:
07/04/1999
The rsync command before rsync 2.3.1 may inadvertently change the permissions of the client's working directory to the permissions of the directory being transferred.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-0472

Publication date:
07/04/1999
The SNMP default community name "public" is not properly removed in NetApps C630 Netcache, even if the administrator tries to disable it.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-1999-1245

Publication date:
06/04/1999
vacm ucd-snmp SNMP server, version 3.52, does not properly disable access to the public community string, which could allow remote attackers to obtain sensitive information.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025