Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2003-0700

Publication date:
17/02/2004
The C-Media PCI sound driver in Linux before 2.4.22 does not use the get_user function to access userspace in certain conditions, which crosses security boundaries and may facilitate the exploitation of vulnerabilities, a different vulnerability than CVE-2003-0699.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2003-0903

Publication date:
17/02/2004
Buffer overflow in a component of Microsoft Data Access Components (MDAC) 2.5 through 2.8 allows remote attackers to execute arbitrary code via a malformed UDP response to a broadcast request.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2003-0924

Publication date:
17/02/2004
netpbm 9.25 and earlier does not properly create temporary files, which allows local users to overwrite arbitrary files.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-1180

Publication date:
16/02/2004
Unknown vulnerability in the rwho daemon (rwhod) before 0.17, on little endian architectures, allows remote attackers to cause a denial of service (application crash).
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-2082

Publication date:
13/02/2004
The samiftp.dll library in Sami FTP Server 1.1.3 allows remote authenticated users to cause a denial of service (pmsystem.exe crash) via a GET request wit a large number of leading "/" (slash) characters.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-2088

Publication date:
12/02/2004
Sophos Anti-Virus 3.78 allows remote attackers to bypass virus scanning by using a qmail generated Delivery Status Notification (DSN) where the original email is not included in the bounce message.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2003-1214

Publication date:
11/02/2004
Unknown vulnerability in the server login for VisualShapers ezContents 2.02 and earlier allows remote attackers to bypass access restrictions and gain access to restricted functions.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-2083

Publication date:
11/02/2004
Opera Web Browser 7.0 through 7.23 allows remote attackers to trick users into executing a malicious file by embedding a CLSID in the file name, which causes the malicious file to appear as a trusted file type, aka "File Download Extension Spoofing."
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-2091

Publication date:
10/02/2004
Microsoft Baseline Security Analyzer (MBSA) 1.2 does not correctly identify systems that have been patched but remain vulnerable to exploit until the system is rebooted, possibly giving the administrator a false sense of security.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-2078

Publication date:
09/02/2004
Red-M Red-Alert 2.7.5 with software 3.1 build 24 allows remote attackers to cause a denial of service (reboot and loss of logged events) via a long request to TCP port 80, possibly triggering a buffer overflow.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-2079

Publication date:
09/02/2004
Red-M Red-Alert 2.7.5 with software 3.1 build 24 binds authentication to IP addresses, which allows remote attackers to bypass authentication by connecting from the same IP address as an active authenticated user.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025

CVE-2004-2080

Publication date:
09/02/2004
Red-M Red-Alert 2.7.5 with software 3.1 build 24 converts multiple spaces in a Service Set Identifier (SSID) to a single space, which prevents Red-Alert from correctly identifying the SSID.
Severity CVSS v4.0: Pending analysis
Last modification:
03/04/2025