Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2001-1533

Publication date:
31/12/2001
Microsoft Internet Security and Acceleration (ISA) Server 2000 allows remote attackers to cause a denial of service via a flood of fragmented UDP packets. NOTE: the vendor disputes this issue, saying that it requires high bandwidth to exploit, and the server does not experience any instability. Therefore this "laws of physics" issue might not be included in CVE
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2001-1583

Publication date:
31/12/2001
lpd daemon (in.lpd) in Solaris 8 and earlier allows remote attackers to execute arbitrary commands via a job request with a crafted control file that is not properly handled when lpd invokes a mail program. NOTE: this might be the same vulnerability as CVE-2000-1220.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2001-1534

Publication date:
31/12/2001
mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable information including host IP address, system time and server process ID, which allows local users to obtain session ID's and bypass authentication when these session ID's are used for authentication.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2001-1497

Publication date:
31/12/2001
Microsoft Internet Explorer 4.0 through 6.0 could allow local users to differentiate between alphanumeric and non-alphanumeric characters used in a password by pressing certain control keys that jump between non-alphanumeric characters, which makes it easier to conduct a brute-force password guessing attack.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2001-1539

Publication date:
31/12/2001
Stack consumption vulnerability in Internet Explorer The JavaScript settimeout function in Internet Explorer allows remote attackers to cause a denial of service (crash) via the JavaScript settimeout function. NOTE: the vendor could not reproduce the problem.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2001-1556

Publication date:
31/12/2001
The log files in Apache web server contain information directly supplied by clients and does not filter or quote control characters, which could allow remote attackers to hide HTTP requests and spoof source IP addresses when logs are viewed with UNIX programs such as cat, tail, and grep.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2001-1466

Publication date:
30/12/2001
Buffer overflow in VanDyke SecureCRT before 3.4.2, when using the SSH-1 protocol, allows remote attackers to execute arbitrary code via a long (1) username or (2) password.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2001-1207

Publication date:
30/12/2001
Buffer overflows in DayDream BBS 2.9 through 2.13 allow remote attackers to possibly execute arbitrary code via the control codes (1) ~#MC, (2) ~#TF, or (3) ~#RA.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2001-1210

Publication date:
30/12/2001
Cisco ubr900 series routers that conform to the Data-over-Cable Service Interface Specifications (DOCSIS) standard must ship without SNMP access restrictions, which can allow remote attackers to read and write information to the MIB using arbitrary community strings.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2001-1205

Publication date:
30/12/2001
Directory traversal vulnerability in lastlines.cgi for Last Lines 2.0 allows remote attackers to read arbitrary files via '..' sequences in the $error_log variable.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2001-1206

Publication date:
30/12/2001
Matrix CGI vault Last Lines 2.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the $error_log variable.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2001-1432

Publication date:
29/12/2001
Directory traversal vulnerability in Cherokee Web Server allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025