Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2007-1675Improper Restriction of Operations within the Bounds of a Memory Buffer in IBM Lotus Domino

7 documents5 sources
Severity
10.0CRITICALNVD
EPSS
77.0%
top 1.04%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedMar 28
Latest updateMay 1

Description

Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to cause a denial of service via a long username.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 10.0 | Impact: 10.0

Affected Packages1 packages

NVDibm/lotus_domino9 versions+8

Patches

🔴Vulnerability Details

3
GHSA
GHSA-6h36-pmmf-r3cx: Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap2022-05-01
CVEList
CVE-2007-1675: Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap2007-03-28
VulnCheck
IBM domino Out-of-bounds Write2007

💥Exploits & PoCs

3
Exploit-DB
Lotus Domino IMAP4 Server 6.5.4 - Remote Buffer Overflow2007-07-20
Exploit-DB
IBM Lotus Domino Server 6.5 - Remote Overflow2007-03-31
Exploit-DB
IBM Lotus Domino Server 6.5 - 'Username' Remote Denial of Service2007-03-29
CVE-2007-1675 — IBM Lotus Domino vulnerability | cvebase