Ibm Lotus Domino vulnerabilities

80 known vulnerabilities affecting ibm/lotus_domino.

Total CVEs
80
CISA KEV
0
Public exploits
10
Exploited in wild
0
Severity breakdown
CRITICAL18HIGH14MEDIUM40LOW8

Vulnerabilities

Page 4 of 4
CVE-2006-0118MEDIUMCVSS 5.0v6.5.0v6.5.1+3 more2006-01-09
CVE-2006-0118 [MEDIUM] CVE-2006-0118: Unspecified vulnerability in IBM Lotus Notes and Domino Server before 6.5.5, when running on AIX, al Unspecified vulnerability in IBM Lotus Notes and Domino Server before 6.5.5, when running on AIX, allows attackers to cause a denial of service (deep recursion leading to stack overflow and crash) via long formulas.
nvd
CVE-2006-0120MEDIUMCVSS 5.0v6.5.0v6.5.1+3 more2006-01-09
CVE-2006-0120 [MEDIUM] CVE-2006-0120: Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 allow attacke Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (application crash) via multiple vectors, involving (1) a malformed message sent to an "Out Of Office" agent (SPR LPEE6DMQWJ), (2) the compact command (RTIN5U2SAJ), (3) malformed bitmap images (MYAA6FH5HW), (4) the "Delete Attach
nvd
CVE-2005-2712HIGHCVSS 7.8v6.0v6.0.1+16 more2005-12-31
CVE-2005-2712 [HIGH] CVE-2005-2712: The LDAP server (nldap.exe) in IBM Lotus Domino before 7.0.1, 6.5.5, and 6.5.4 FP2 allows remote att The LDAP server (nldap.exe) in IBM Lotus Domino before 7.0.1, 6.5.5, and 6.5.4 FP2 allows remote attackers to cause a denial of service (crash) via a long bind request, which triggers a null dereference.
nvd
CVE-2005-4819MEDIUMCVSS 6.8v6.0.5v6.5.4+3 more2005-12-31
CVE-2005-4819 [MEDIUM] CVE-2005-4819: Cross-site scripting (XSS) vulnerability in Lotus Domino versions before 6.5.4 fix pack 1 (FP1) and Cross-site scripting (XSS) vulnerability in Lotus Domino versions before 6.5.4 fix pack 1 (FP1) and versions before 7.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
nvd
CVE-2005-3015MEDIUMCVSS 4.3v6.5.22005-09-21
CVE-2005-3015 [MEDIUM] CVE-2005-3015: Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 6.5.2 allows remote attackers to inject Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 6.5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) BaseTarget or (2) Src parameters.
nvd
CVE-2005-2428MEDIUMCVSS 5.0PoCv5.0v6.0+1 more2005-08-03
CVE-2005-2428 [MEDIUM] CVE-2005-2428: Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data f Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the HTTPPasswordChangeDate field, (3) the client
nvd
CVE-2005-1441MEDIUMCVSS 5.0v6.0v6.0.1+7 more2005-05-03
CVE-2005-1441 [MEDIUM] CVE-2005-1441: Format string vulnerability in Lotus Domino 6.0.x before 6.0.5 and 6.5.x before 6.5.4 allows remote Format string vulnerability in Lotus Domino 6.0.x before 6.0.5 and 6.5.x before 6.5.4 allows remote attackers to cause a denial of service via the Notes protocol (NRPC).
nvd
CVE-2004-2310MEDIUMCVSS 4.3PoCv6.5.12004-12-31
CVE-2004-2310 [MEDIUM] CVE-2004-2310: Cross-site scripting (XSS) vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows remote atta Cross-site scripting (XSS) vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows remote attackers to inject arbitrary web script or HTML via a Domino command in the Quick Console.
nvd
CVE-2004-2369MEDIUMCVSS 6.4v6.5.12004-12-31
CVE-2004-2369 [MEDIUM] CVE-2004-2369: Directory traversal vulnerability in webadmin.nsf for Lotus Domino R6 6.5.1 allows attackers to crea Directory traversal vulnerability in webadmin.nsf for Lotus Domino R6 6.5.1 allows attackers to create and detect directories via a .. (dot dot) in the directory creation command.
nvd
CVE-2004-2311LOWCVSS 3.6PoCv6.5.12004-12-31
CVE-2004-2311 [LOW] CVE-2004-2311: Directory traversal vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows local users to cre Directory traversal vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows local users to create folders or determine the existence of files via a .. (dot dot) in the new folder dialog.
nvd
CVE-2004-1621MEDIUMCVSS 4.3PoCv6.0v6.0.1+6 more2004-10-18
CVE-2004-1621 [MEDIUM] CVE-2004-1621: NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM L NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Domino R6, and possibly earlier versions, allows remote attackers to execute arbitrary web script or HTML via square brackets at the beginning and end of (1) computed for display, (2) computed when composed, or (3) computed text element fields.
nvd
CVE-2004-0669HIGHCVSS 7.5v6.5.0v6.5.12004-08-06
CVE-2004-0669 [HIGH] CVE-2004-0669: Lotus Domino 6.5.0 and 6.5.1, with IMAP enabled, allows remote authenticated users to change their q Lotus Domino 6.5.0 and 6.5.1, with IMAP enabled, allows remote authenticated users to change their quota by using the IMAP setquota command.
nvd
CVE-2004-0029MEDIUMCVSS 4.6v6.0.22004-01-20
CVE-2004-0029 [MEDIUM] CVE-2004-0029: Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable perm Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges.
nvd
CVE-2003-0122MEDIUMCVSS 5.0v4.6.1v4.6.3+17 more2003-03-18
CVE-2003-0122 [MEDIUM] CVE-2003-0122: Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote attackers to execute arbitrary code via a long distinguished name (DN) during NotesRPC authentication and an outer field length that is less than that of the DN field.
nvd
CVE-2003-0123MEDIUMCVSS 5.0v4.6.1v4.6.3+18 more2003-03-18
CVE-2003-0123 [MEDIUM] CVE-2003-0123: Buffer overflow in Web Retriever client for Lotus Notes/Domino R4.5 through R6 allows remote malicio Buffer overflow in Web Retriever client for Lotus Notes/Domino R4.5 through R6 allows remote malicious web servers to cause a denial of service (crash) via a long HTTP status line.
nvd
CVE-2002-1624MEDIUMCVSS 5.0v5.0v5.0.1+12 more2002-12-31
CVE-2002-1624 [MEDIUM] CVE-2002-1624: Buffer overflow in Lotus Domino web server before R5.0.10, when logging to DOMLOG.NSF, allows remote Buffer overflow in Lotus Domino web server before R5.0.10, when logging to DOMLOG.NSF, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP Authenticate header containing certain non-ASCII characters.
nvd
CVE-2002-2014MEDIUMCVSS 5.0v5.0.82002-12-31
CVE-2002-2014 [MEDIUM] CVE-2002-2014: Lotus Domino 5.0.8 web server returns different error messages when a valid or invalid user is provi Lotus Domino 5.0.8 web server returns different error messages when a valid or invalid user is provided in HTTP requests, which allows remote attackers to determine valid user names and makes it easier to conduct brute force attacks.
nvd
CVE-2002-0086HIGHCVSS 7.2v5.0.4v5.0.72002-03-15
CVE-2002-0086 [HIGH] CVE-2002-0086: Buffer overflow in bindsock in Lotus Domino 5.0.4 and 5.0.7 on Linux allows local users to gain root Buffer overflow in bindsock in Lotus Domino 5.0.4 and 5.0.7 on Linux allows local users to gain root privileges via a long (1) Notes_ExecDirectory or (2) PATH environment variable.
nvd
CVE-2001-1567MEDIUMCVSS 5.0v5.0v5.0.1+9 more2001-12-31
CVE-2001-1567 [MEDIUM] CVE-2001-1567: Lotus Domino server 5.0.9a and earlier allows remote attackers to bypass security restrictions and v Lotus Domino server 5.0.9a and earlier allows remote attackers to bypass security restrictions and view Notes database files and possibly sensitive Notes template files (.ntf) via an HTTP request with a large number of "+" characters before the .nsf file extension, which are converted to spaces by Domino.
nvd
CVE-2000-1215MEDIUMCVSS 5.0v5.0.82001-09-19
CVE-2000-1215 [MEDIUM] CVE-2000-1215: The default configuration of Lotus Domino server 5.0.8 includes system information (version, operati The default configuration of Lotus Domino server 5.0.8 includes system information (version, operating system, and build date) in the HTTP headers of replies, which allows remote attackers to obtain sensitive information.
nvd