cbcvebase.

Ibm Lotus Notes vulnerabilities

69 known vulnerabilities affecting ibm/lotus_notes.

Total CVEs
69
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL35HIGH12MEDIUM19LOW3

Vulnerabilities

Page 1 of 4
CVE-2012-2174P2CRITICALCVSS 9.3PoCv8.0v8.0.0+25 more2012-06-20
CVE-2012-2174 [CRITICAL] CWE-94 CVE-2012-2174: The URL handler in IBM Lotus Notes 8.x before 8.5.3 FP2 allows remote attackers to execute arbitrary The URL handler in IBM Lotus Notes 8.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a crafted notes:// URL.
nvd
CVE-2011-1213P2CRITICALCVSS 9.3PoC≤ 8.5.2.2v3.0+99 more2011-05-31
CVE-2011-1213 [CRITICAL] CWE-189 CVE-2011-1213: Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, all Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted header in a .lzh attachment that triggers a stack-based buffer overflow, aka SPR PRAD88MJ2W.
nvd
CVE-2007-6593P3HIGHCVSS 8.8PoCv5.0v6.0+3 more2007-12-28
CVE-2007-6593 [HIGH] CVE-2007-6593: Multiple stack-based buffer overflows in l123sr.dll in Autonomy (formerly Verity) KeyView SDK, as us Multiple stack-based buffer overflows in l123sr.dll in Autonomy (formerly Verity) KeyView SDK, as used by IBM Lotus Notes 5.x through 8.x, allow user-assisted remote attackers to execute arbitrary code via the (1) Length and (2) Value fields for certain Types in a Lotus 1-2-3 (.123) file in the Worksheet File (WKS) format, as demonstrated by a file with a craft
nvd
CVE-2012-4821P3CRITICALCVSS 9.3v8.0v8.0.0+27 more2013-01-11
CVE-2012-4821 [CRITICAL] CVE-2012-4821: Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lo
nvd
CVE-2012-4822P3CRITICALCVSS 9.3v8.0v8.0.0+27 more2013-01-11
CVE-2012-4822 [CRITICAL] CVE-2012-4822: Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 Multiple unspecified vulnerabilities in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lo
nvd
CVE-2012-4823P3CRITICALCVSS 9.3v8.0v8.0.0+27 more2013-01-11
CVE-2012-4823 [CRITICAL] CVE-2012-4823: Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and ear Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes
nvd
CVE-2012-4820P3CRITICALCVSS 9.3v8.0v8.0.0+27 more2013-01-11
CVE-2012-4820 [CRITICAL] CVE-2012-4820: Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and ear Unspecified vulnerability in the JRE component in IBM Java 7 SR2 and earlier, Java 6.0.1 SR3 and earlier, Java 6 SR11 and earlier, Java 5 SR14 and earlier, and Java 142 SR13 FP13 and earlier; as used in IBM Rational Host On-Demand, Rational Change, Tivoli Monitoring, Smart Analytics System 5600, Tivoli Remote Control 5.1.2, WebSphere Real Time, Lotus Notes
nvd
CVE-2007-5909P3CRITICALCVSS 9.3≤ 7.0.22007-11-10
CVE-2007-5909 [CRITICAL] CWE-119 CVE-2007-5909: Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Expo Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, IBM Lotus Notes before 7.0.3, Symantec Mail Security, and other products, allow remote attackers to execute arbitrary code via a crafted (1) AG file to kpagrdr.dll, (2) AW file to awsr.dll, (3
nvd
CVE-2011-1512P3CRITICALCVSS 9.3≤ 8.5.2.2v3.0+99 more2011-05-31
CVE-2011-1512 [CRITICAL] CWE-119 CVE-2011-1512: Heap-based buffer overflow in xlssr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 Heap-based buffer overflow in xlssr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a malformed BIFF record in a .xls Excel spreadsheet attachment, aka SPR PRAD8E3HKR.
nvd
CVE-2011-1215P3CRITICALCVSS 9.3≤ 8.5.2.2v7.0+35 more2011-05-31
CVE-2011-1215 [CRITICAL] CWE-119 CVE-2011-1215: Stack-based buffer overflow in mw8sr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5. Stack-based buffer overflow in mw8sr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted link in a Microsoft Office document attachment, aka SPR PRAD8823ND.
nvd
CVE-2008-4564P3CRITICALCVSS 9.3v5.0.3v5.0.12+18 more2009-03-18
CVE-2008-4564 [CRITICAL] CWE-119 CVE-2008-4564: Stack-based buffer overflow in wp6sr.dll in the Autonomy KeyView SDK 10.4 and earlier, as used in IB Stack-based buffer overflow in wp6sr.dll in the Autonomy KeyView SDK 10.4 and earlier, as used in IBM Lotus Notes, Symantec Mail Security (SMS) products, Symantec BrightMail Appliance products, and Symantec Data Loss Prevention (DLP) products, allows remote attackers to execute arbitrary code via a crafted Word Perfect Document (WPD) file.
nvd
CVE-2011-1214P3CRITICALCVSS 9.3≤ 8.5.2.2v3.0+99 more2011-05-31
CVE-2011-1214 [CRITICAL] CWE-119 CVE-2011-1214: Stack-based buffer overflow in rtfsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5. Stack-based buffer overflow in rtfsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted link in a .rtf attachment, aka SPR PRAD8823JQ.
nvd
CVE-2011-1216P3CRITICALCVSS 9.3≤ 8.5.2.2v3.0+99 more2011-05-31
CVE-2011-1216 [CRITICAL] CWE-119 CVE-2011-1216: Stack-based buffer overflow in assr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 Stack-based buffer overflow in assr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via crafted tag data in an Applix spreadsheet attachment, aka SPR PRAD8823A7.
nvd
CVE-2010-1608P3CRITICALCVSS 10.0v8.5v8.5.1+1 more2010-04-29
CVE-2010-1608 [CRITICAL] CWE-119 CVE-2010-1608: Stack-based buffer overflow in IBM Lotus Notes 8.5 and 8.5fp1, and possibly other versions, allows r Stack-based buffer overflow in IBM Lotus Notes 8.5 and 8.5fp1, and possibly other versions, allows remote attackers to execute arbitrary code via unknown attack vectors, as demonstrated by the vd_ln module in VulnDisco 9.0. NOTE: as of 20100222, this disclosure has no actionable information. However, because the VulnDisco author is a reliable resear
nvd
CVE-2004-2280P4MEDIUMCVSS 5.0PoCv6.0v6.0.1+8 more2004-12-31
CVE-2004-2280 [MEDIUM] CVE-2004-2280: Buffer overflow in IBM Lotus Notes 6.5.x before 6.5.3 and 6.0.x before 6.0.5 allows remote attackers Buffer overflow in IBM Lotus Notes 6.5.x before 6.5.3 and 6.0.x before 6.0.5 allows remote attackers to cause a denial of service (crash) via unknown vectors related to Java applets, as identified by KSPR62F4KN.
nvd
CVE-2007-5910P3CRITICALCVSS 9.3≤ 7.0.22007-11-10
CVE-2007-5910 [CRITICAL] CWE-119 CVE-2007-5910: Stack-based buffer overflow in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK bef Stack-based buffer overflow in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, wp6sr.dll in IBM Lotus Notes 8.0 and before 7.0.3, Symantec Mail Security, and other products, allows remote attackers to execute arbitrary code via a crafted WordPerfect (WPD) file.
nvd
CVE-2011-0912P3CRITICALCVSS 9.3v8.0v8.0.1+14 more2011-02-08
CVE-2011-0912 [CRITICAL] CWE-20 CVE-2011-0912: Argument injection vulnerability in IBM Lotus Notes 8.0.x before 8.0.2 FP6 and 8.5.x before 8.5.1 FP Argument injection vulnerability in IBM Lotus Notes 8.0.x before 8.0.2 FP6 and 8.5.x before 8.5.1 FP5 allows remote attackers to execute arbitrary code via a cai:// URL containing a --launcher.library option that specifies a UNC share pathname for a DLL file, aka SPR PRAD82YJW2.
nvd
CVE-2002-0370P3HIGHCVSS 7.5≤ 4.5v5.0+10 more2002-10-10
CVE-2002-0370 [HIGH] CVE-2002-0370: Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denia Buffer overflow in the ZIP capability for multiple products allows remote attackers to cause a denial of service or execute arbitrary code via ZIP files containing entries with long filenames, including (1) Microsoft Windows 98 with Plus! Pack, (2) Windows XP, (3) Windows ME, (4) Lotus Notes R4 through R6 (pre-gold), (5) Verity KeyView, and (6) Stuffit Expander
nvd
CVE-2009-3037P3CRITICALCVSS 9.3v5.0v5.0.1+32 more2009-09-01
CVE-2009-3037 [CRITICAL] CWE-119 CVE-2009-3037: Buffer overflow in xlssr.dll in the Autonomy KeyView XLS viewer (aka File Viewer for Excel), as used Buffer overflow in xlssr.dll in the Autonomy KeyView XLS viewer (aka File Viewer for Excel), as used in IBM Lotus Notes 5.x through 8.5.x, Symantec Mail Security, Symantec BrightMail Appliance, Symantec Data Loss Prevention (DLP), and other products, allows remote attackers to execute arbitrary code via a crafted .xls spreadsheet attachment.
nvd
CVE-2009-3032P3CRITICALCVSS 10.0v8.52010-03-05
CVE-2009-3032 [CRITICAL] CWE-189 CVE-2009-3032: Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security for Microsoft Exchange 5.0.10 through 5.0.13, and other products, allows context-dependent attackers to execute arbitrary code via a crafted OLE document that triggers a heap-based buffer overflow.
nvd
Ibm Lotus Notes vulnerabilities | cvebase