cbcvebase.
CVE-2006-3778
published 2006-07-24

CVE-2006-3778: IBM Lotus Notes 6.0, 6.5, and 7.0 does not properly handle replies to e-mail messages with alternate name users when the (1) "Save As Draft" option is used or…

PriorityP419medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.48%
71.0th percentile
IBM Lotus Notes 6.0, 6.5, and 7.0 does not properly handle replies to e-mail messages with alternate name users when the (1) "Save As Draft" option is used or (2) a "," (comma) is inside the "phrase" portion of an address, which can cause the e-mail to be sent to users that were deleted from the To, CC, and BCC fields, which allows remote attackers to obtain the list of original recipients.

Affected

3 ranges
VendorProductVersion rangeFixed in
ibmlotus_notes
ibmlotus_notes
ibmlotus_notes
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.