Vulnerabilities

With the aim of informing, warning and helping professionals with the latest security vulnerabilities in technology systems, we have made a database available for users interested in this information, which is in Spanish and includes all of the latest documented and recognised vulnerabilities.

This repository, with over 75,000 registers, is based on the information from the NVD (National Vulnerability Database) – by virtue of a partnership agreement – through which INCIBE translates the included information into Spanish.

On occasions this list will show vulnerabilities that have still not been translated, as they are added while the INCIBE team is still carrying out the translation process. The CVE  (Common Vulnerabilities and Exposures) Standard for Information Security Vulnerability Names is used with the aim to support the exchange of information between different tools and databases.

All vulnerabilities collected are linked to different information sources, as well as available patches or solutions provided by manufacturers and developers. It is possible to carry out advanced searches, as there is the option to select different criteria to narrow down the results, some examples being vulnerability types, manufacturers and impact levels, among others.

Through RSS feeds or Newsletters we can be informed daily about the latest vulnerabilities added to the repository. Below there is a list, updated daily, where you can discover the latest vulnerabilities.

CVE-2004-2218

Publication date:
31/12/2004
SQL injection vulnerability in pmwh.php in PHPMyWebHosting 0.3.4 and earlier allows remote attackers to modify SQL statements via the password parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
11/07/2017

CVE-2004-2220

Publication date:
31/12/2004
F-Secure Anti-Virus for Microsoft Exchange 6.30 and 6.31 does not properly detect certain password-protected files in a ZIP file, which allows remote attackers to bypass anti-virus protection.
Severity CVSS v4.0: Pending analysis
Last modification:
11/07/2017

CVE-2004-2221

Publication date:
31/12/2004
Buffer overflow in SoftCart.exe in Mercantec SoftCart 4.00b allows remote attackers to execute arbitrary code via a long parameter in an HTTP GET request.
Severity CVSS v4.0: Pending analysis
Last modification:
11/07/2017

CVE-2004-2222

Publication date:
31/12/2004
Directory traversal vulnerability in index.php in FsPHPGallery before 1.2 allows remote attackers to list arbitrary directories via the dir parameter.
Severity CVSS v4.0: Pending analysis
Last modification:
07/11/2023

CVE-2004-2223

Publication date:
31/12/2004
FsPHPGallery before 1.2 allows remote attackers to cause a denial of service via an image with a large size attribute, which causes a crash when the server attempts to resize the image.
Severity CVSS v4.0: Pending analysis
Last modification:
11/07/2017

CVE-2004-2224

Publication date:
31/12/2004
Appfoundry Message Foundry 2.75 .0003 allows remote attackers to cause a denial of service (crash) via an HTTP GET request that contains MS-DOS device names such as com1.
Severity CVSS v4.0: Pending analysis
Last modification:
11/07/2017

CVE-2004-2226

Publication date:
31/12/2004
Mozilla Mail 1.7.1 and 1.7.3, and Thunderbird before 0.9, when HTML-Mails is enabled, allows remote attackers to determine valid e-mail addresses via an HTML e-mail that references a Cascading Style Sheets (CSS) document on the attacker's server.
Severity CVSS v4.0: Pending analysis
Last modification:
11/07/2017

CVE-2004-2227

Publication date:
31/12/2004
Mozilla Firefox before 1.0 truncates long filenames in the file download dialog box, which makes it easier for remote attackers to trick users into downloading files with dangerous extensions.
Severity CVSS v4.0: Pending analysis
Last modification:
11/07/2017

CVE-2004-2228

Publication date:
31/12/2004
Mozilla Firefox before 1.0 is installed with world-writable permissions on Mac OS X, which allows local users to gain privileges.
Severity CVSS v4.0: Pending analysis
Last modification:
11/07/2017

CVE-2004-2229

Publication date:
31/12/2004
Multiple unknown vulnerabilities in Oracle 9i Lite Mobile Server 5.0.0.0.0 through 5.0.2.9.0 allow remote authenticated users to gain privileges.
Severity CVSS v4.0: Pending analysis
Last modification:
11/07/2017

CVE-2004-2230

Publication date:
31/12/2004
Heap-based buffer overflow in isakmpd on OpenBSD 3.4 through 3.6 allows local users to cause a denial of service (panic) and corrupt memory via IPSEC credentials on a socket.
Severity CVSS v4.0: Pending analysis
Last modification:
11/07/2017

CVE-2004-2231

Publication date:
31/12/2004
Zero G Software InstallAnywhere 5.0.6, 5.0.7, and earlier allows local users to overwrite arbitrary files via a symlink attack on the (1) persistent_state or (2) env.properties.X temporary files.
Severity CVSS v4.0: Pending analysis
Last modification:
11/07/2017