cbcvebase.

Ibm Lotus Notes vulnerabilities

69 known vulnerabilities affecting ibm/lotus_notes.

Total CVEs
69
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL35HIGH12MEDIUM19LOW3

Vulnerabilities

Page 2 of 4
CVE-2011-1218P3CRITICALCVSS 9.3≤ 8.5.2.2v3.0+99 more2011-05-31
CVE-2011-1218 [CRITICAL] CWE-119 CVE-2011-1218: Buffer overflow in kvarcve.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, all Buffer overflow in kvarcve.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted .zip attachment, aka SPR PRAD8E3NSP. NOTE: some of these details are obtained from third party information.
nvd
CVE-2012-6349P3CRITICALCVSS 9.3v8.5v8.5.0.0+16 more2013-07-18
CVE-2012-6349 [CRITICAL] CWE-119 CVE-2012-6349: Buffer overflow in the .mdb parser in Autonomy KeyView IDOL, as used in IBM Notes 8.5.x before 8.5.3 Buffer overflow in the .mdb parser in Autonomy KeyView IDOL, as used in IBM Notes 8.5.x before 8.5.3 FP4, allows remote attackers to execute arbitrary code via a crafted file, aka SPR KLYH92XL3W.
nvd
CVE-2014-3086P3HIGHCVSS 7.5v8.5.3.0v9.0.1.02014-08-12
CVE-2014-3086 [HIGH] CVE-2014-3086: Unspecified vulnerability in the IBM Java Virtual Machine, as used in IBM WebSphere Real Time 3 befo Unspecified vulnerability in the IBM Java Virtual Machine, as used in IBM WebSphere Real Time 3 before Service Refresh 7 FP1 and other products, allows remote attackers to gain privileges by leveraging the ability to execute code in the context of a security manager.
nvd
CVE-2011-1217P3CRITICALCVSS 9.3≤ 8.5.2.2v3.0+99 more2011-05-31
CVE-2011-1217 [CRITICAL] CWE-119 CVE-2011-1217: Buffer overflow in kpprzrdr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, al Buffer overflow in kpprzrdr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted .prz attachment. NOTE: some of these details are obtained from third party information.
nvd
CVE-2007-6020P3CRITICALCVSS 9.3v6.0v6.5+3 more2008-04-10
CVE-2007-6020 [CRITICAL] CWE-119 CVE-2007-6020: Multiple stack-based buffer overflows in foliosr.dll in the Folio Flat File speed reader in Autonomy Multiple stack-based buffer overflows in foliosr.dll in the Folio Flat File speed reader in Autonomy (formerly Verity) KeyView 10.3.0.0, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, allow remote attackers to execute arbitrary code via a long attribute value in a (1) DI, (2) FD, (3) FT, (4) JD, (5) JL, (6) LE, (7) O
nvd
CVE-2007-5405P3CRITICALCVSS 9.3v6.0v6.5+3 more2008-04-10
CVE-2007-5405 [CRITICAL] CWE-119 CVE-2007-5405: Multiple buffer overflows in kpagrdr.dll 2.0.0.2 and 10.3.0.0 in the Applix Presents reader in Auton Multiple buffer overflows in kpagrdr.dll 2.0.0.2 and 10.3.0.0 in the Applix Presents reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, allow remote attackers to execute arbitrary code via a .ag file with (1) a long ENCODING attribute in a *BEGIN tag, (2) a long token, or (3)
nvd
CVE-2008-0066P3CRITICALCVSS 9.3v7.0.2v7.0.32008-04-10
CVE-2008-0066 [CRITICAL] CWE-119 CVE-2008-0066: Multiple buffer overflows in htmsr.dll in the HTML speed reader in Autonomy (formerly Verity) KeyVie Multiple buffer overflows in htmsr.dll in the HTML speed reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes 7.0.2 and 7.0.3, allow remote attackers to execute arbitrary code via an HTML document with (1) "large chunks of data," or a long URL in the (2) BACKGROUND attribute of a BODY element or (3) SRC attribute of an IMG elemen
nvd
CVE-2007-5399P3CRITICALCVSS 9.3v6.0v6.5+3 more2008-04-10
CVE-2007-5399 [CRITICAL] CWE-119 CVE-2007-5399: Multiple heap-based buffer overflows in emlsr.dll in the EML reader in Autonomy (formerly Verity) Ke Multiple heap-based buffer overflows in emlsr.dll in the EML reader in Autonomy (formerly Verity) KeyView 10.3.0.0, as used by IBM Lotus Notes, allow remote attackers to execute arbitrary code via a long (1) To, (2) Cc, (3) Bcc, (4) From, (5) Date, (6) Subject, (7) Priority, (8) Importance, or (9) X-MSMail-Priority header; (10) a long string at the
nvd
CVE-2004-0480P3CRITICALCVSS 10.0v6.0.3v6.52004-12-06
CVE-2004-0480 [CRITICAL] CWE-88 CVE-2004-0480: Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute arbitrary code via a notes: URI that uses a UNC network share pathname to provide an alternate notes.ini configuration file to notes.exe.
nvd
CVE-2008-1101P3CRITICALCVSS 9.3v6.0v6.5+3 more2008-04-10
CVE-2008-1101 [CRITICAL] CWE-119 CVE-2008-1101: Buffer overflow in kvdocve.dll in the KeyView document viewing engine in Autonomy (formerly Verity) Buffer overflow in kvdocve.dll in the KeyView document viewing engine in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes 7.0.2 and 7.0.3, allows remote attackers to execute arbitrary code via a long pathname, as demonstrated by a long SRC attribute of an IMG element in an HTML document.
nvd
CVE-2007-6706P3CRITICALCVSS 9.3≤ 7.0.2v6.5+1 more2008-03-09
CVE-2007-6706 [CRITICAL] CWE-94 CVE-2007-6706: Unspecified vulnerability in nlnotes.dll in the client in IBM Lotus Notes 6.5, 7.0.x before 7.0.2 CC Unspecified vulnerability in nlnotes.dll in the client in IBM Lotus Notes 6.5, 7.0.x before 7.0.2 CCH or 7.0.3, and possibly 8.0 allows remote attackers to execute arbitrary code via crafted text in an e-mail message sent over SMTP.
nvd
CVE-2013-2977P3MEDIUMCVSS 6.8v8.5v8.5.0.0+18 more2013-05-10
CVE-2013-2977 [MEDIUM] CWE-189 CVE-2013-2977: Integer overflow in IBM Notes 8.5.x before 8.5.3 FP4 Interim Fix 1 and 9.x before 9.0 Interim Fix 1 Integer overflow in IBM Notes 8.5.x before 8.5.3 FP4 Interim Fix 1 and 9.x before 9.0 Interim Fix 1 on Windows, and 8.5.x before 8.5.3 FP5 and 9.x before 9.0.1 on Linux, allows remote attackers to execute arbitrary code via a malformed PNG image in a previewed e-mail message, aka SPR NPEI96K82Q.
nvd
CVE-2008-1217P3CRITICALCVSS 9.3v6.5v7.0.2+1 more2008-03-09
CVE-2008-1217 [CRITICAL] CVE-2008-1217: Unspecified vulnerability in nlnotes.dll in the client in IBM Lotus Notes 6.5, 7.0.x before 7.0.2 CC Unspecified vulnerability in nlnotes.dll in the client in IBM Lotus Notes 6.5, 7.0.x before 7.0.2 CCH, and 8.0.x before 8.0.1 allows remote attackers to execute arbitrary code via a crafted attachment in an e-mail message sent over SMTP, a variant of CVE-2007-6706.
nvd
CVE-2005-2618P3CRITICALCVSS 9.3v6.0.1v6.0.2+9 more2005-12-31
CVE-2005-2618 [CRITICAL] CWE-119 CVE-2005-2618: Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as use Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allow remote attackers to execute arbitrary code via (1) a UUE file containing an encoded file with a long filename handled by uudrdr.dll, (2) a compressed ZIP file with a long filename handled by kvarcve.dll, (3) a TAR
nvd
CVE-2007-4222P3CRITICALCVSS 9.3≤ 7.0.22007-10-29
CVE-2007-4222 [CRITICAL] CWE-119 CVE-2007-4222: Buffer overflow in the TagAttributeListCopy function in nnotes.dll in IBM Lotus Notes before 7.0.3 a Buffer overflow in the TagAttributeListCopy function in nnotes.dll in IBM Lotus Notes before 7.0.3 allows user-assisted remote attackers to execute arbitrary code via a crafted HTML email, related to duplicate RTF conversion when the recipient operates on this email.
nvd
CVE-2008-1718P3CRITICALCVSS 9.3v6.0v6.5+3 more2008-04-10
CVE-2008-1718 [CRITICAL] CWE-119 CVE-2008-1718: Buffer overflow in mimesr.dll in Autonomy (formerly Verity) KeyView, as used in IBM Lotus Notes befo Buffer overflow in mimesr.dll in Autonomy (formerly Verity) KeyView, as used in IBM Lotus Notes before 8.0, might allow user-assisted remote attackers to execute arbitrary code via an e-mail message with a crafted Text mail (MIME) attachment.
nvd
CVE-2005-2619P4CRITICALCVSS 9.3v6.0.1v6.0.2+9 more2005-12-31
CVE-2005-2619 [CRITICAL] CWE-22 CVE-2005-2619: Directory traversal vulnerability in kvarcve.dll in Autonomy (formerly Verity) KeyView SDK before 9. Directory traversal vulnerability in kvarcve.dll in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allows remote attackers to delete arbitrary files via a (1) ZIP, (2) UUE or (3) TAR archive that contains a .. (dot dot) in the filename, which is not properly handled when generating a preview.
nvd
CVE-2009-3114P4HIGHCVSS 7.5v8.52009-09-09
CVE-2009-3114 [HIGH] CWE-94 CVE-2009-3114: The RSS reader widget in IBM Lotus Notes 8.0 and 8.5 saves items from an RSS feed as local HTML docu The RSS reader widget in IBM Lotus Notes 8.0 and 8.5 saves items from an RSS feed as local HTML documents, which allows remote attackers to execute arbitrary script in Internet Explorer's Local Machine Zone via a crafted feed, aka SPR RGAU7RDJ9K.
nvd
CVE-2007-5406P4CRITICALCVSS 9.3v6.0v6.5+3 more2008-04-10
CVE-2007-5406 [CRITICAL] CVE-2007-5406: kpagrdr.dll 2.0.0.2 and 10.3.0.0 in the Applix Presents reader in Autonomy (formerly Verity) KeyView kpagrdr.dll 2.0.0.2 and 10.3.0.0 in the Applix Presents reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, does not properly parse long tokens, which allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted .ag file.
nvd
CVE-2006-0119P4CRITICALCVSS 10.0v6.5v6.5.1+3 more2006-01-09
CVE-2006-0119 [CRITICAL] CVE-2006-0119: Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 have unknown Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 have unknown impact and attack vectors, due to "potential security issues" as identified by SPR numbers (1) GPKS6C9J67 in Agents, (2) JGAN6B6TZ3 and (3) KSPR699NBP in the Router, (4) GPKS5YQGPT in Security, or (5) HSAO6BNL6Y in the Web Server. NOTE: vector 3 is related to
nvd
Ibm Lotus Notes vulnerabilities | cvebase