cbcvebase.

Ibm Lotus Domino vulnerabilities

80 known vulnerabilities affecting ibm/lotus_domino.

Total CVEs
80
CISA KEV
0
Public exploits
10
Exploited in wild
1
Severity breakdown
CRITICAL18HIGH14MEDIUM40LOW8

Vulnerabilities

Page 2 of 4
CVE-2013-4068P3HIGHCVSS 7.1v8.5.3.0v8.5.3.1+4 more2013-09-20
CVE-2013-4068 [HIGH] CWE-119 CVE-2013-4068: Buffer overflow in iNotes in IBM Domino 8.5.3 before FP5 IF1 and 9.0 before IF4 allows remote authen Buffer overflow in iNotes in IBM Domino 8.5.3 before FP5 IF1 and 9.0 before IF4 allows remote authenticated users to execute arbitrary code via unspecified vectors, aka SPR PTHN9ADPA8.
nvd
CVE-2007-0068P3CRITICALCVSS 9.3v7.0v7.0.1+1 more2007-06-06
CVE-2007-0068 [CRITICAL] CVE-2007-0068: IBM Lotus Domino 7.0.x before 7.0.3 does not revalidate the signature on a signed scheduled agent af IBM Lotus Domino 7.0.x before 7.0.3 does not revalidate the signature on a signed scheduled agent after the agent is modified, which allows remote authenticated users to gain privileges via a modified agent in a server database.
nvd
CVE-2007-1739P3HIGHCVSS 7.8v7.0v7.0.1+1 more2007-03-28
CVE-2007-1739 [HIGH] CVE-2007-1739: Heap-based buffer overflow in the LDAP server in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 Heap-based buffer overflow in the LDAP server in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to cause a denial of service (crash) via a long, malformed DN request, which causes only the lower 16 bits of the string length to be used in memory allocation.
nvd
CVE-2011-1393P4HIGHCVSS 7.8≤ 8.5.2v8.0+16 more2011-12-27
CVE-2011-1393 [HIGH] CVE-2011-1393: Unspecified vulnerability in the authentication functionality in the server in IBM Lotus Domino 8.x Unspecified vulnerability in the authentication functionality in the server in IBM Lotus Domino 8.x before 8.5.2 FP4 allows remote attackers to cause a denial of service (daemon crash) via a crafted Notes RPC packet.
nvd
CVE-2010-0358P4CRITICALCVSS 10.0v7.0v8.5.0.12010-01-20
CVE-2010-0358 [CRITICAL] CVE-2010-0358: Heap-based buffer overflow in the server in IBM Lotus Domino 7 and 8.5 FP1 allows remote attackers t Heap-based buffer overflow in the server in IBM Lotus Domino 7 and 8.5 FP1 allows remote attackers to cause a denial of service (daemon exit) and possibly have unspecified other impact via a long string in a crafted LDAP message to a TCP port, a different vulnerability than CVE-2009-3087.
nvd
CVE-2010-0276P4CRITICALCVSS 10.0v8.0.2.32010-01-09
CVE-2010-0276 [CRITICAL] CVE-2010-0276: IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 does not properl IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 does not properly handle navigation of the "Try Lotus iNotes anyway" link from the page that reports use of an unsupported browser, which has unspecified impact and attack vectors, aka SPR LSHR7TBMQU.
nvd
CVE-2006-0119P4CRITICALCVSS 10.0v6.5.0v6.5.1+3 more2006-01-09
CVE-2006-0119 [CRITICAL] CVE-2006-0119: Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 have unknown Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 have unknown impact and attack vectors, due to "potential security issues" as identified by SPR numbers (1) GPKS6C9J67 in Agents, (2) JGAN6B6TZ3 and (3) KSPR699NBP in the Router, (4) GPKS5YQGPT in Security, or (5) HSAO6BNL6Y in the Web Server. NOTE: vector 3 is related to
nvd
CVE-2003-0122P4MEDIUMCVSS 5.0v4.6.1v4.6.3+17 more2003-03-18
CVE-2003-0122 [MEDIUM] CVE-2003-0122: Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote attackers to execute arbitrary code via a long distinguished name (DN) during NotesRPC authentication and an outer field length that is less than that of the DN field.
nvd
CVE-2004-2311P4LOWCVSS 3.6PoCv6.5.12004-12-31
CVE-2004-2311 [LOW] CVE-2004-2311: Directory traversal vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows local users to cre Directory traversal vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows local users to create folders or determine the existence of files via a .. (dot dot) in the new folder dialog.
nvd
CVE-2014-0892P4MEDIUMCVSS 5.0v8.5.0v8.5.0.1+20 more2014-04-23
CVE-2014-0892 [MEDIUM] CWE-200 CVE-2014-0892: IBM Notes and Domino 8.5.x before 8.5.3 FP6 IF3 and 9.x before 9.0.1 FP1 on 32-bit Linux platforms u IBM Notes and Domino 8.5.x before 8.5.3 FP6 IF3 and 9.x before 9.0.1 FP1 on 32-bit Linux platforms use incorrect gcc options, which makes it easier for remote attackers to execute arbitrary code by leveraging the absence of the NX protection mechanism and placing crafted x86 code on the stack, aka SPR KLYH9GGS9W.
nvd
CVE-2014-0822P4HIGHCVSS 7.8v8.5.0v8.5.0.1+19 more2014-02-06
CVE-2014-0822 [HIGH] CVE-2014-0822: The IMAP server in IBM Domino 8.5.x before 8.5.3 FP6 IF1 and 9.0.x before 9.0.1 FP1 allows remote at The IMAP server in IBM Domino 8.5.x before 8.5.3 FP6 IF1 and 9.0.x before 9.0.1 FP1 allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors, aka SPR KLYH9F4S2Z.
nvd
CVE-2006-5818P4HIGHCVSS 7.2≤ 6.5.5≤ 7.0.1+14 more2006-11-08
CVE-2006-5818 [HIGH] CVE-2006-5818: Multiple buffer overflows in tunekrnl in IBM Lotus Domino 6.x before 6.5.5 FP2 and 7.x before 7.0.2 Multiple buffer overflows in tunekrnl in IBM Lotus Domino 6.x before 6.5.5 FP2 and 7.x before 7.0.2 allow local users to gain privileges and execute arbitrary code via unspecified vectors.
nvd
CVE-2004-0669P4HIGHCVSS 7.5v6.5.0v6.5.12004-08-06
CVE-2004-0669 [HIGH] CVE-2004-0669: Lotus Domino 6.5.0 and 6.5.1, with IMAP enabled, allows remote authenticated users to change their q Lotus Domino 6.5.0 and 6.5.1, with IMAP enabled, allows remote authenticated users to change their quota by using the IMAP setquota command.
nvd
CVE-2005-2712P4HIGHCVSS 7.8v6.0v6.0.1+16 more2005-12-31
CVE-2005-2712 [HIGH] CVE-2005-2712: The LDAP server (nldap.exe) in IBM Lotus Domino before 7.0.1, 6.5.5, and 6.5.4 FP2 allows remote att The LDAP server (nldap.exe) in IBM Lotus Domino before 7.0.1, 6.5.5, and 6.5.4 FP2 allows remote attackers to cause a denial of service (crash) via a long bind request, which triggers a null dereference.
nvd
CVE-2008-0243P4HIGHCVSS 7.8v7.0v7.0.1+1 more2008-01-12
CVE-2008-0243 [HIGH] CVE-2008-0243: Unspecified vulnerability in Lotus Domino 7.0.2 before Fix Pack 3 allows attackers to cause a denial Unspecified vulnerability in Lotus Domino 7.0.2 before Fix Pack 3 allows attackers to cause a denial of service via unknown vectors.
nvd
CVE-2006-0121P4HIGHCVSS 7.8v6.5.0v6.5.1+3 more2006-01-09
CVE-2006-0121 [HIGH] CVE-2006-0121: Multiple memory leaks in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a d Multiple memory leaks in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (memory consumption and crash) via unknown vectors related to (1) unspecified vectors during the SSL handshake (SPR# MKIN67MQVW), (2) the stash file during the SSL handshake (SPR# MKIN693QUT), and possibly other vectors. NOTE: due to insufficient
nvd
CVE-2007-5544P4HIGHCVSS 7.8fixed in 6.5.5≥ 7.0, < 7.0.2+2 more2007-10-29
CVE-2007-5544 [HIGH] CWE-732 CVE-2007-5544: IBM Lotus Notes before 6.5.6, and 7.x before 7.0.3; and Domino before 6.5.5 FP3, and 7.x before 7.0. IBM Lotus Notes before 6.5.6, and 7.x before 7.0.3; and Domino before 6.5.5 FP3, and 7.x before 7.0.2 FP1; uses weak permissions (Everyone:Full Control) for memory mapped files (shared memory) in IPC, which allows local users to obtain sensitive information, or inject Lotus Script or other character sequences into a session.
nvd
CVE-2007-5700P4MEDIUMCVSS 6.3v6.5.5v6.5.6+2 more2007-10-29
CVE-2007-5700 [MEDIUM] CVE-2007-5700: The Evaluate LotusScript method in IBM Lotus Domino before 7.0.3 uses an incorrect security context The Evaluate LotusScript method in IBM Lotus Domino before 7.0.3 uses an incorrect security context for @ formula commands in some circumstances, which might allow remote authenticated users to gain privileges and obtain sensitive information.
nvd
CVE-2002-0086P4HIGHCVSS 7.2v5.0.4v5.0.72002-03-15
CVE-2002-0086 [HIGH] CVE-2002-0086: Buffer overflow in bindsock in Lotus Domino 5.0.4 and 5.0.7 on Linux allows local users to gain root Buffer overflow in bindsock in Lotus Domino 5.0.4 and 5.0.7 on Linux allows local users to gain root privileges via a long (1) Notes_ExecDirectory or (2) PATH environment variable.
nvd
CVE-2013-4050P4MEDIUMCVSS 6.0v8.5.0v9.0.0.02013-11-08
CVE-2013-4050 [MEDIUM] CWE-352 CVE-2013-4050: Cross-site request forgery (CSRF) vulnerability in webadmin.nsf in Domino Web Administrator in IBM D Cross-site request forgery (CSRF) vulnerability in webadmin.nsf in Domino Web Administrator in IBM Domino 8.5 and 9.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
nvd
Ibm Lotus Domino vulnerabilities | cvebase