Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2011-3575Improper Restriction of Operations within the Bounds of a Memory Buffer in IBM Lotus Domino

Severity
9.0CRITICALNVD
EPSS
24.6%
top 3.85%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedSep 19
Latest updateMay 17

Description

Stack-based buffer overflow in the NSFComputeEvaluateExt function in Nnotes.dll in IBM Lotus Domino 8.5.2 allows remote authenticated users to execute arbitrary code via a long tHPRAgentName parameter in an fmHttpPostRequest OpenForm action to WebAdmin.nsf.

CVSS vector

AV:N/AC:L/C:C/I:C/A:CExploitability: 8.0 | Impact: 10.0

Affected Packages1 packages

NVDibm/lotus_domino8.5.2

🔴Vulnerability Details

2
GHSA
GHSA-vqx2-g8xp-v37c: Stack-based buffer overflow in the NSFComputeEvaluateExt function in Nnotes2022-05-17
CVEList
CVE-2011-3575: Stack-based buffer overflow in the NSFComputeEvaluateExt function in Nnotes2011-09-17

💥Exploits & PoCs

1
Exploit-DB
IBM Lotus Domino 8.5.2 - 'NSFComputeEvaluateExt()' Remote Stack Buffer Overflow2011-09-20
CVE-2011-3575 — IBM Lotus Domino vulnerability | cvebase