Ibm Lotus Notes vulnerabilities

69 known vulnerabilities affecting ibm/lotus_notes.

Total CVEs
69
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL35HIGH12MEDIUM19LOW3

Vulnerabilities

Page 2 of 4
CVE-2011-1218CRITICALCVSS 9.3≤ 8.5.2.2v3.0+99 more2011-05-31
CVE-2011-1218 [CRITICAL] CWE-119 CVE-2011-1218: Buffer overflow in kvarcve.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, all Buffer overflow in kvarcve.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted .zip attachment, aka SPR PRAD8E3NSP. NOTE: some of these details are obtained from third party information.
nvd
CVE-2011-1213CRITICALCVSS 9.3PoC≤ 8.5.2.2v3.0+99 more2011-05-31
CVE-2011-1213 [CRITICAL] CWE-189 CVE-2011-1213: Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, all Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted header in a .lzh attachment that triggers a stack-based buffer overflow, aka SPR PRAD88MJ2W.
nvd
CVE-2011-0912CRITICALCVSS 9.3v8.0v8.0.1+14 more2011-02-08
CVE-2011-0912 [CRITICAL] CWE-20 CVE-2011-0912: Argument injection vulnerability in IBM Lotus Notes 8.0.x before 8.0.2 FP6 and 8.5.x before 8.5.1 FP Argument injection vulnerability in IBM Lotus Notes 8.0.x before 8.0.2 FP6 and 8.5.x before 8.5.1 FP5 allows remote attackers to execute arbitrary code via a cai:// URL containing a --launcher.library option that specifies a UNC share pathname for a DLL file, aka SPR PRAD82YJW2.
nvd
CVE-2010-1608CRITICALCVSS 10.0v8.5v8.5.1+1 more2010-04-29
CVE-2010-1608 [CRITICAL] CWE-119 CVE-2010-1608: Stack-based buffer overflow in IBM Lotus Notes 8.5 and 8.5fp1, and possibly other versions, allows r Stack-based buffer overflow in IBM Lotus Notes 8.5 and 8.5fp1, and possibly other versions, allows remote attackers to execute arbitrary code via unknown attack vectors, as demonstrated by the vd_ln module in VulnDisco 9.0. NOTE: as of 20100222, this disclosure has no actionable information. However, because the VulnDisco author is a reliable resear
nvd
CVE-2010-1487LOWCVSS 2.1v7.0v8.0+1 more2010-04-20
CVE-2010-1487 [LOW] CWE-255 CVE-2010-1487: IBM Lotus Notes 7.0, 8.0, and 8.5 stores administrative credentials in cleartext in SURunAs.exe, whi IBM Lotus Notes 7.0, 8.0, and 8.5 stores administrative credentials in cleartext in SURunAs.exe, which allows local users to obtain sensitive information by examining this file, aka SPR JSTN837SEG.
nvd
CVE-2009-3032CRITICALCVSS 10.0v8.52010-03-05
CVE-2009-3032 [CRITICAL] CWE-189 CVE-2009-3032: Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security for Microsoft Exchange 5.0.10 through 5.0.13, and other products, allows context-dependent attackers to execute arbitrary code via a crafted OLE document that triggers a heap-based buffer overflow.
nvd
CVE-2009-3114HIGHCVSS 7.5v8.52009-09-09
CVE-2009-3114 [HIGH] CWE-94 CVE-2009-3114: The RSS reader widget in IBM Lotus Notes 8.0 and 8.5 saves items from an RSS feed as local HTML docu The RSS reader widget in IBM Lotus Notes 8.0 and 8.5 saves items from an RSS feed as local HTML documents, which allows remote attackers to execute arbitrary script in Internet Explorer's Local Machine Zone via a crafted feed, aka SPR RGAU7RDJ9K.
nvd
CVE-2009-3037CRITICALCVSS 9.3v5.0v5.0.1+32 more2009-09-01
CVE-2009-3037 [CRITICAL] CWE-119 CVE-2009-3037: Buffer overflow in xlssr.dll in the Autonomy KeyView XLS viewer (aka File Viewer for Excel), as used Buffer overflow in xlssr.dll in the Autonomy KeyView XLS viewer (aka File Viewer for Excel), as used in IBM Lotus Notes 5.x through 8.5.x, Symantec Mail Security, Symantec BrightMail Appliance, Symantec Data Loss Prevention (DLP), and other products, allows remote attackers to execute arbitrary code via a crafted .xls spreadsheet attachment.
nvd
CVE-2008-4564CRITICALCVSS 9.3v5.0.3v5.0.12+18 more2009-03-18
CVE-2008-4564 [CRITICAL] CWE-119 CVE-2008-4564: Stack-based buffer overflow in wp6sr.dll in the Autonomy KeyView SDK 10.4 and earlier, as used in IB Stack-based buffer overflow in wp6sr.dll in the Autonomy KeyView SDK 10.4 and earlier, as used in IBM Lotus Notes, Symantec Mail Security (SMS) products, Symantec BrightMail Appliance products, and Symantec Data Loss Prevention (DLP) products, allows remote attackers to execute arbitrary code via a crafted Word Perfect Document (WPD) file.
nvd
CVE-2008-1718CRITICALCVSS 9.3v6.0v6.5+3 more2008-04-10
CVE-2008-1718 [CRITICAL] CWE-119 CVE-2008-1718: Buffer overflow in mimesr.dll in Autonomy (formerly Verity) KeyView, as used in IBM Lotus Notes befo Buffer overflow in mimesr.dll in Autonomy (formerly Verity) KeyView, as used in IBM Lotus Notes before 8.0, might allow user-assisted remote attackers to execute arbitrary code via an e-mail message with a crafted Text mail (MIME) attachment.
nvd
CVE-2007-5406CRITICALCVSS 9.3v6.0v6.5+3 more2008-04-10
CVE-2007-5406 [CRITICAL] CVE-2007-5406: kpagrdr.dll 2.0.0.2 and 10.3.0.0 in the Applix Presents reader in Autonomy (formerly Verity) KeyView kpagrdr.dll 2.0.0.2 and 10.3.0.0 in the Applix Presents reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, does not properly parse long tokens, which allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted .ag file.
nvd
CVE-2008-0066CRITICALCVSS 9.3v7.0.2v7.0.32008-04-10
CVE-2008-0066 [CRITICAL] CWE-119 CVE-2008-0066: Multiple buffer overflows in htmsr.dll in the HTML speed reader in Autonomy (formerly Verity) KeyVie Multiple buffer overflows in htmsr.dll in the HTML speed reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes 7.0.2 and 7.0.3, allow remote attackers to execute arbitrary code via an HTML document with (1) "large chunks of data," or a long URL in the (2) BACKGROUND attribute of a BODY element or (3) SRC attribute of an IMG elemen
nvd
CVE-2007-5399CRITICALCVSS 9.3v6.0v6.5+3 more2008-04-10
CVE-2007-5399 [CRITICAL] CWE-119 CVE-2007-5399: Multiple heap-based buffer overflows in emlsr.dll in the EML reader in Autonomy (formerly Verity) Ke Multiple heap-based buffer overflows in emlsr.dll in the EML reader in Autonomy (formerly Verity) KeyView 10.3.0.0, as used by IBM Lotus Notes, allow remote attackers to execute arbitrary code via a long (1) To, (2) Cc, (3) Bcc, (4) From, (5) Date, (6) Subject, (7) Priority, (8) Importance, or (9) X-MSMail-Priority header; (10) a long string at the
nvd
CVE-2007-6020CRITICALCVSS 9.3v6.0v6.5+3 more2008-04-10
CVE-2007-6020 [CRITICAL] CWE-119 CVE-2007-6020: Multiple stack-based buffer overflows in foliosr.dll in the Folio Flat File speed reader in Autonomy Multiple stack-based buffer overflows in foliosr.dll in the Folio Flat File speed reader in Autonomy (formerly Verity) KeyView 10.3.0.0, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, allow remote attackers to execute arbitrary code via a long attribute value in a (1) DI, (2) FD, (3) FT, (4) JD, (5) JL, (6) LE, (7) O
nvd
CVE-2007-5405CRITICALCVSS 9.3v6.0v6.5+3 more2008-04-10
CVE-2007-5405 [CRITICAL] CWE-119 CVE-2007-5405: Multiple buffer overflows in kpagrdr.dll 2.0.0.2 and 10.3.0.0 in the Applix Presents reader in Auton Multiple buffer overflows in kpagrdr.dll 2.0.0.2 and 10.3.0.0 in the Applix Presents reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, allow remote attackers to execute arbitrary code via a .ag file with (1) a long ENCODING attribute in a *BEGIN tag, (2) a long token, or (3)
nvd
CVE-2008-1101CRITICALCVSS 9.3v6.0v6.5+3 more2008-04-10
CVE-2008-1101 [CRITICAL] CWE-119 CVE-2008-1101: Buffer overflow in kvdocve.dll in the KeyView document viewing engine in Autonomy (formerly Verity) Buffer overflow in kvdocve.dll in the KeyView document viewing engine in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes 7.0.2 and 7.0.3, allows remote attackers to execute arbitrary code via a long pathname, as demonstrated by a long SRC attribute of an IMG element in an HTML document.
nvd
CVE-2007-6706CRITICALCVSS 9.3≤ 7.0.2v6.5+1 more2008-03-09
CVE-2007-6706 [CRITICAL] CWE-94 CVE-2007-6706: Unspecified vulnerability in nlnotes.dll in the client in IBM Lotus Notes 6.5, 7.0.x before 7.0.2 CC Unspecified vulnerability in nlnotes.dll in the client in IBM Lotus Notes 6.5, 7.0.x before 7.0.2 CCH or 7.0.3, and possibly 8.0 allows remote attackers to execute arbitrary code via crafted text in an e-mail message sent over SMTP.
nvd
CVE-2008-1217CRITICALCVSS 9.3v6.5v7.0.2+1 more2008-03-09
CVE-2008-1217 [CRITICAL] CVE-2008-1217: Unspecified vulnerability in nlnotes.dll in the client in IBM Lotus Notes 6.5, 7.0.x before 7.0.2 CC Unspecified vulnerability in nlnotes.dll in the client in IBM Lotus Notes 6.5, 7.0.x before 7.0.2 CCH, and 8.0.x before 8.0.1 allows remote attackers to execute arbitrary code via a crafted attachment in an e-mail message sent over SMTP, a variant of CVE-2007-6706.
nvd
CVE-2008-0862MEDIUMCVSS 4.3v6.0v6.5+2 more2008-02-21
CVE-2008-0862 [MEDIUM] CWE-264 CVE-2008-0862: IBM Lotus Notes 6.0, 6.5, 7.0, and 8.0 signs an unsigned applet when a user forwards an email messag IBM Lotus Notes 6.0, 6.5, 7.0, and 8.0 signs an unsigned applet when a user forwards an email message to another user, which allows user-assisted remote attackers to bypass Execution Control List (ECL) protection.
nvd
CVE-2007-6593HIGHCVSS 8.8PoCv5.0v6.0+3 more2007-12-28
CVE-2007-6593 [HIGH] CVE-2007-6593: Multiple stack-based buffer overflows in l123sr.dll in Autonomy (formerly Verity) KeyView SDK, as us Multiple stack-based buffer overflows in l123sr.dll in Autonomy (formerly Verity) KeyView SDK, as used by IBM Lotus Notes 5.x through 8.x, allow user-assisted remote attackers to execute arbitrary code via the (1) Length and (2) Value fields for certain Types in a Lotus 1-2-3 (.123) file in the Worksheet File (WKS) format, as demonstrated by a file with a craft
nvd