Ibm Lotus Domino vulnerabilities
80 known vulnerabilities affecting ibm/lotus_domino.
Total CVEs
80
CISA KEV
0
Public exploits
10
Exploited in wild
1
Severity breakdown
CRITICAL18HIGH14MEDIUM40LOW8
Vulnerabilities
Page 1 of 4
CVE-2007-1675P2CRITICALCVSS 10.0ExploitedPoCv6.5.0v6.5.1+7 more2007-03-28
CVE-2007-1675 [CRITICAL] CVE-2007-1675: Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus
Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to cause a denial of service via a long username.
nvd
CVE-2008-2240P2CRITICALCVSS 10.0PoCv6.0v6.5+3 more2008-05-22
CVE-2008-2240 [CRITICAL] CWE-119 CVE-2008-2240: Stack-based buffer overflow in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x
Stack-based buffer overflow in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long Accept-Language HTTP header.
nvd
CVE-2010-3407P2CRITICALCVSS 9.3PoCv8.0v8.0.1+9 more2010-09-16
CVE-2010-3407 [CRITICAL] CWE-119 CVE-2010-3407: Stack-based buffer overflow in the MailCheck821Address function in nnotes.dll in the nrouter.exe ser
Stack-based buffer overflow in the MailCheck821Address function in nnotes.dll in the nrouter.exe service in the server in IBM Lotus Domino 8.0.x before 8.0.2 FP5 and 8.5.x before 8.5.1 FP2 allows remote attackers to execute arbitrary code via a long e-mail address in an ORGANIZER:mailto header in an iCalendar calendar-invitation e-mail message, aka
nvd
CVE-2011-1519P2CRITICALCVSS 10.0PoCv7.0v7.0.1+31 more2011-03-25
CVE-2011-1519 [CRITICAL] CVE-2011-1519: The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials aga
The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname specified by the client, which allows remote attackers to bypass authentication, and consequently execute arbitrary code, by placing this pathname in the COOKIEFILE field. NOTE: this might overlap CVE-2011-0920.
nvd
CVE-2011-3575P3CRITICALCVSS 9.0PoCv8.5.22011-09-19
CVE-2011-3575 [CRITICAL] CWE-119 CVE-2011-3575: Stack-based buffer overflow in the NSFComputeEvaluateExt function in Nnotes.dll in IBM Lotus Domino
Stack-based buffer overflow in the NSFComputeEvaluateExt function in Nnotes.dll in IBM Lotus Domino 8.5.2 allows remote authenticated users to execute arbitrary code via a long tHPRAgentName parameter in an fmHttpPostRequest OpenForm action to WebAdmin.nsf.
nvd
CVE-2005-2428P3MEDIUMCVSS 5.0PoCv5.0v6.0+1 more2005-08-03
CVE-2005-2428 [MEDIUM] CVE-2005-2428: Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data f
Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the HTTPPasswordChangeDate field, (3) the client
nvd
CVE-2007-0977P3HIGHCVSS 7.1PoCv5.0v6.02007-02-16
CVE-2007-0977 [HIGH] CVE-2007-0977: IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword
IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword hashes from names.nsf in a manner accessible through Readviewentries and OpenDocument requests to the defaultview view, a different vector than CVE-2005-2428.
nvd
CVE-2012-4821P3CRITICALCVSS 9.3v8.0v8.0.1+21 more2013-01-11
CVE-2012-4821 [CRITICAL] CVE-2012-4821: Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1
Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lo
nvd
CVE-2011-0915P3CRITICALCVSS 10.0≤ 8.5.2.2v4.6.1+72 more2011-02-08
CVE-2011-0915 [CRITICAL] CWE-119 CVE-2011-0915: Stack-based buffer overflow in nrouter.exe in IBM Lotus Domino before 8.5.3 allows remote attackers
Stack-based buffer overflow in nrouter.exe in IBM Lotus Domino before 8.5.3 allows remote attackers to execute arbitrary code via a long name parameter in a Content-Type header in a malformed Notes calendar (aka iCalendar or iCal) meeting request, aka SPR KLYH87LL23.
nvd
CVE-2012-4822P3CRITICALCVSS 9.3v8.0v8.0.1+21 more2013-01-11
CVE-2012-4822 [CRITICAL] CVE-2012-4822: Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1
Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lo
nvd
CVE-2012-4823P3CRITICALCVSS 9.3v8.0v8.0.1+21 more2013-01-11
CVE-2012-4823 [CRITICAL] CVE-2012-4823: Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and ear
Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes
nvd
CVE-2011-0913P3CRITICALCVSS 10.0≤ 8.5.2.2v4.6.1+72 more2011-02-08
CVE-2011-0913 [CRITICAL] CWE-119 CVE-2011-0913: Stack-based buffer overflow in ndiiop.exe in the DIIOP implementation in the server in IBM Lotus Dom
Stack-based buffer overflow in ndiiop.exe in the DIIOP implementation in the server in IBM Lotus Domino before 8.5.3 allows remote attackers to execute arbitrary code via a GIOP getEnvironmentString request, related to the local variable cache.
nvd
CVE-2011-0914P3CRITICALCVSS 10.0≤ 8.5.2.2v4.6.1+72 more2011-02-08
CVE-2011-0914 [CRITICAL] CWE-189 CVE-2011-0914: Integer signedness error in ndiiop.exe in the DIIOP implementation in the server in IBM Lotus Domino
Integer signedness error in ndiiop.exe in the DIIOP implementation in the server in IBM Lotus Domino before 8.5.3 allows remote attackers to execute arbitrary code via a GIOP client request, leading to a heap-based buffer overflow.
nvd
CVE-2012-4820P3CRITICALCVSS 9.3v8.0v8.0.1+21 more2013-01-11
CVE-2012-4820 [CRITICAL] CVE-2012-4820: Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and ear
Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes
nvd
CVE-2013-3027P3CRITICALCVSS 9.3v9.0.0.02013-08-09
CVE-2013-3027 [CRITICAL] CWE-189 CVE-2013-3027: Integer overflow in the DWA9W ActiveX control in iNotes in IBM Domino 9.0 before IF3 allows remote a
Integer overflow in the DWA9W ActiveX control in iNotes in IBM Domino 9.0 before IF3 allows remote attackers to execute arbitrary code via a crafted web page, aka SPR PTHN97XHFW.
nvd
CVE-2014-3086P3HIGHCVSS 7.5v8.5.3.0v9.0.1.02014-08-12
CVE-2014-3086 [HIGH] CVE-2014-3086: Unspecified vulnerability in the IBM Java Virtual Machine, as used in IBM WebSphere Real Time 3 befo
Unspecified vulnerability in the IBM Java Virtual Machine, as used in IBM WebSphere Real Time 3 before Service Refresh 7 FP1 and other products, allows remote attackers to gain privileges by leveraging the ability to execute code in the context of a security manager.
nvd
CVE-2007-3510P3CRITICALCVSS 9.0v6.5.5v6.5.6+2 more2007-10-29
CVE-2007-3510 [CRITICAL] CWE-119 CVE-2007-3510: Buffer overflow in the IMAP service in IBM Lotus Domino before 6.5.6 FP2, and 7.x before 7.0.3, allo
Buffer overflow in the IMAP service in IBM Lotus Domino before 6.5.6 FP2, and 7.x before 7.0.3, allows remote authenticated users to execute arbitrary code via a long mailbox name.
nvd
CVE-2004-2310P4MEDIUMCVSS 4.3PoCv6.5.12004-12-31
CVE-2004-2310 [MEDIUM] CVE-2004-2310: Cross-site scripting (XSS) vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows remote atta
Cross-site scripting (XSS) vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows remote attackers to inject arbitrary web script or HTML via a Domino command in the Quick Console.
nvd
CVE-2013-0487P3HIGHCVSS 8.5v8.5.0v8.5.0.1+14 more2013-03-27
CVE-2013-0487 [HIGH] CWE-287 CVE-2013-0487: The Java Console in IBM Domino 8.5.x allows remote authenticated users to hijack temporary credentia
The Java Console in IBM Domino 8.5.x allows remote authenticated users to hijack temporary credentials by leveraging knowledge of configuration details, aka SPR KLYH8TNNDN.
nvd
CVE-2004-1621P4MEDIUMCVSS 4.3PoCv6.0v6.0.1+6 more2004-10-18
CVE-2004-1621 [MEDIUM] CVE-2004-1621: NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM L
NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Domino R6, and possibly earlier versions, allows remote attackers to execute arbitrary web script or HTML via square brackets at the beginning and end of (1) computed for display, (2) computed when composed, or (3) computed text element fields.
nvd
1 / 4Next →