Ibm Lotus Domino vulnerabilities
80 known vulnerabilities affecting ibm/lotus_domino.
Total CVEs
80
CISA KEV
0
Public exploits
10
Exploited in wild
0
Severity breakdown
CRITICAL18HIGH14MEDIUM40LOW8
Vulnerabilities
Page 2 of 4
CVE-2013-0489MEDIUMCVSS 6.0v8.5.0v8.5.0.1+14 more2013-03-27
CVE-2013-0489 [MEDIUM] CWE-352 CVE-2013-0489: Cross-site request forgery (CSRF) vulnerability in webadmin.nsf (aka the Web Administrator client) i
Cross-site request forgery (CSRF) vulnerability in webadmin.nsf (aka the Web Administrator client) in IBM Domino 8.5.x allows remote authenticated users to hijack the authentication of administrators.
nvd
CVE-2013-0488MEDIUMCVSS 4.3v8.5.0v8.5.0.1+14 more2013-03-27
CVE-2013-0488 [MEDIUM] CWE-79 CVE-2013-0488: Cross-site scripting (XSS) vulnerability in webadmin.nsf (aka the Web Administrator client) in IBM D
Cross-site scripting (XSS) vulnerability in webadmin.nsf (aka the Web Administrator client) in IBM Domino 8.5.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2013-0486MEDIUMCVSS 4.3v8.5.0v8.5.0.1+14 more2013-03-27
CVE-2013-0486 [MEDIUM] CWE-399 CVE-2013-0486: Memory leak in the HTTP server in IBM Domino 8.5.x allows remote attackers to cause a denial of serv
Memory leak in the HTTP server in IBM Domino 8.5.x allows remote attackers to cause a denial of service (memory consumption and daemon crash) via GET requests, aka SPR KLYH92NKZY.
nvd
CVE-2012-4842MEDIUMCVSS 5.8v8.5.0v8.5.0.1+12 more2013-02-27
CVE-2012-4842 [MEDIUM] CWE-399 CVE-2012-4842: Open redirect vulnerability in the web server in IBM Lotus Domino 8.5.x through 8.5.3 allows remote
Open redirect vulnerability in the web server in IBM Lotus Domino 8.5.x through 8.5.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
nvd
CVE-2012-4844MEDIUMCVSS 4.3v8.5.0v8.5.0.1+12 more2013-02-27
CVE-2012-4844 [MEDIUM] CWE-79 CVE-2012-4844: Cross-site scripting (XSS) vulnerability in the web server in IBM Lotus Domino 8.5.x through 8.5.3 a
Cross-site scripting (XSS) vulnerability in the web server in IBM Lotus Domino 8.5.x through 8.5.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2012-4820CRITICALCVSS 9.3v8.0v8.0.1+21 more2013-01-11
CVE-2012-4820 [CRITICAL] CVE-2012-4820: Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and ear
Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes
nvd
CVE-2012-4822CRITICALCVSS 9.3v8.0v8.0.1+21 more2013-01-11
CVE-2012-4822 [CRITICAL] CVE-2012-4822: Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1
Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lo
nvd
CVE-2012-4823CRITICALCVSS 9.3v8.0v8.0.1+21 more2013-01-11
CVE-2012-4823 [CRITICAL] CVE-2012-4823: Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and ear
Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes
nvd
CVE-2012-4821CRITICALCVSS 9.3v8.0v8.0.1+21 more2013-01-11
CVE-2012-4821 [CRITICAL] CVE-2012-4821: Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1
Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lo
nvd
CVE-2012-3301MEDIUMCVSS 4.3v8.5.0v8.5.0.1+13 more2012-08-21
CVE-2012-3301 [MEDIUM] CWE-20 CVE-2012-3301: Multiple CRLF injection vulnerabilities in the HTTP server in IBM Lotus Domino 8.5.x before 8.5.4 al
Multiple CRLF injection vulnerabilities in the HTTP server in IBM Lotus Domino 8.5.x before 8.5.4 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via crafted input involving (1) Mozilla Firefox 3.0.9 and earlier or (2) unspecified browsers.
nvd
CVE-2012-3302MEDIUMCVSS 4.3v7.0.1v7.0.1.1+22 more2012-08-21
CVE-2012-3302 [MEDIUM] CWE-79 CVE-2012-3302: Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Domino 7.x and 8.x before 8.5.4 all
Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Domino 7.x and 8.x before 8.5.4 allow remote attackers to inject arbitrary web script or HTML via (1) a URL accessed during use of the Mail template in the WebMail UI or (2) a URL accessed during use of Domino Help through the Domino HTTP server.
nvd
CVE-2011-1393HIGHCVSS 7.8≤ 8.5.2v8.0+16 more2011-12-27
CVE-2011-1393 [HIGH] CVE-2011-1393: Unspecified vulnerability in the authentication functionality in the server in IBM Lotus Domino 8.x
Unspecified vulnerability in the authentication functionality in the server in IBM Lotus Domino 8.x before 8.5.2 FP4 allows remote attackers to cause a denial of service (daemon crash) via a crafted Notes RPC packet.
nvd
CVE-2011-3575CRITICALCVSS 9.0PoCv8.5.22011-09-19
CVE-2011-3575 [CRITICAL] CWE-119 CVE-2011-3575: Stack-based buffer overflow in the NSFComputeEvaluateExt function in Nnotes.dll in IBM Lotus Domino
Stack-based buffer overflow in the NSFComputeEvaluateExt function in Nnotes.dll in IBM Lotus Domino 8.5.2 allows remote authenticated users to execute arbitrary code via a long tHPRAgentName parameter in an fmHttpPostRequest OpenForm action to WebAdmin.nsf.
nvd
CVE-2011-3576MEDIUMCVSS 4.3v8.5.22011-09-19
CVE-2011-3576 [MEDIUM] CWE-79 CVE-2011-3576: Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 8.5.2 allows remote attackers to inject
Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 8.5.2 allows remote attackers to inject arbitrary web script or HTML via the PanelIcon parameter in an fmpgPanelHeader ReadForm action to WebAdmin.nsf.
nvd
CVE-2011-1519CRITICALCVSS 10.0PoCv7.0v7.0.1+31 more2011-03-25
CVE-2011-1519 [CRITICAL] CVE-2011-1519: The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials aga
The remote console in the Server Controller in IBM Lotus Domino 7.x and 8.x verifies credentials against a file located at a UNC share pathname specified by the client, which allows remote attackers to bypass authentication, and consequently execute arbitrary code, by placing this pathname in the COOKIEFILE field. NOTE: this might overlap CVE-2011-0920.
nvd
CVE-2011-0913CRITICALCVSS 10.0≤ 8.5.2.2v4.6.1+72 more2011-02-08
CVE-2011-0913 [CRITICAL] CWE-119 CVE-2011-0913: Stack-based buffer overflow in ndiiop.exe in the DIIOP implementation in the server in IBM Lotus Dom
Stack-based buffer overflow in ndiiop.exe in the DIIOP implementation in the server in IBM Lotus Domino before 8.5.3 allows remote attackers to execute arbitrary code via a GIOP getEnvironmentString request, related to the local variable cache.
nvd
CVE-2011-0914CRITICALCVSS 10.0≤ 8.5.2.2v4.6.1+72 more2011-02-08
CVE-2011-0914 [CRITICAL] CWE-189 CVE-2011-0914: Integer signedness error in ndiiop.exe in the DIIOP implementation in the server in IBM Lotus Domino
Integer signedness error in ndiiop.exe in the DIIOP implementation in the server in IBM Lotus Domino before 8.5.3 allows remote attackers to execute arbitrary code via a GIOP client request, leading to a heap-based buffer overflow.
nvd
CVE-2011-0915CRITICALCVSS 10.0≤ 8.5.2.2v4.6.1+72 more2011-02-08
CVE-2011-0915 [CRITICAL] CWE-119 CVE-2011-0915: Stack-based buffer overflow in nrouter.exe in IBM Lotus Domino before 8.5.3 allows remote attackers
Stack-based buffer overflow in nrouter.exe in IBM Lotus Domino before 8.5.3 allows remote attackers to execute arbitrary code via a long name parameter in a Content-Type header in a malformed Notes calendar (aka iCalendar or iCal) meeting request, aka SPR KLYH87LL23.
nvd
CVE-2010-3407CRITICALCVSS 9.3PoCv8.0v8.0.1+9 more2010-09-16
CVE-2010-3407 [CRITICAL] CWE-119 CVE-2010-3407: Stack-based buffer overflow in the MailCheck821Address function in nnotes.dll in the nrouter.exe ser
Stack-based buffer overflow in the MailCheck821Address function in nnotes.dll in the nrouter.exe service in the server in IBM Lotus Domino 8.0.x before 8.0.2 FP5 and 8.5.x before 8.5.1 FP2 allows remote attackers to execute arbitrary code via a long e-mail address in an ORGANIZER:mailto header in an iCalendar calendar-invitation e-mail message, aka
nvd
CVE-2010-0927MEDIUMCVSS 4.3v7.0v7.0.1+9 more2010-03-05
CVE-2010-0927 [MEDIUM] CVE-2010-0927: Cross-site scripting (XSS) vulnerability in help/readme.nsf/Header in the Help component in IBM Lotu
Cross-site scripting (XSS) vulnerability in help/readme.nsf/Header in the Help component in IBM Lotus Domino 7.x before 7.0.4 and 8.x before 8.0.2 allows remote attackers to inject arbitrary web script or HTML via the BaseTarget parameter in an OpenPage action. NOTE: this may overlap CVE-2010-0920.
nvd