cbcvebase.

Ibm Lotus Notes vulnerabilities

69 known vulnerabilities affecting ibm/lotus_notes.

Total CVEs
69
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL35HIGH12MEDIUM19LOW3

Vulnerabilities

Page 3 of 4
CVE-2014-0892P4MEDIUMCVSS 5.0v8.5v8.5.0.0+21 more2014-04-23
CVE-2014-0892 [MEDIUM] CWE-200 CVE-2014-0892: IBM Notes and Domino 8.5.x before 8.5.3 FP6 IF3 and 9.x before 9.0.1 FP1 on 32-bit Linux platforms u IBM Notes and Domino 8.5.x before 8.5.3 FP6 IF3 and 9.x before 9.0.1 FP1 on 32-bit Linux platforms use incorrect gcc options, which makes it easier for remote attackers to execute arbitrary code by leveraging the absence of the NX protection mechanism and placing crafted x86 code on the stack, aka SPR KLYH9GGS9W.
nvd
CVE-2000-0891P4HIGHCVSS 7.5≤ 5.022001-07-21
CVE-2000-0891 [HIGH] CVE-2000-0891: A default ECL in Lotus Notes before 5.02 allows remote attackers to execute arbitrary commands by at A default ECL in Lotus Notes before 5.02 allows remote attackers to execute arbitrary commands by attaching a malicious program in an email message that is automatically executed when the user opens the email.
nvd
CVE-2013-0127P4MEDIUMCVSS 5.8v8.0v8.0.0+28 more2013-05-01
CVE-2013-0127 [MEDIUM] CWE-264 CVE-2013-0127: IBM Lotus Notes 8.x before 8.5.3 FP4 Interim Fix 1 and 9.0 before Interim Fix 1 does not block APPLE IBM Lotus Notes 8.x before 8.5.3 FP4 Interim Fix 1 and 9.0 before Interim Fix 1 does not block APPLET elements in HTML e-mail, which allows remote attackers to bypass intended restrictions on Java code execution and X-Confirm-Reading-To functionality via a crafted message, aka SPRs JMOY95BLM6 and JMOY95BN49.
nvd
CVE-2001-1504P4HIGHCVSS 7.5v4.6v5.02001-12-31
CVE-2001-1504 [HIGH] CVE-2001-1504: Lotus Notes R5 Client 4.6 allows remote attackers to execute arbitrary commands via a Lotus Notes ob Lotus Notes R5 Client 4.6 allows remote attackers to execute arbitrary commands via a Lotus Notes object with code in an event, which is automatically executed when the user processes the e-mail message.
nvd
CVE-2004-2281P4CRITICALCVSS 10.0v6.0v6.0.1+7 more2004-12-31
CVE-2004-2281 [CRITICAL] CVE-2004-2281: Multiple unknown vulnerabilities in IBM Lotus Notes 6.5.x before 6.5.4 and 6.0.x before 6.0.5 have u Multiple unknown vulnerabilities in IBM Lotus Notes 6.5.x before 6.5.4 and 6.0.x before 6.0.5 have unknown impact and attack vectors, related to Java applets, as identified by (1) KSPR5YS6GR and (2) KSPR62F4D3.
nvd
CVE-2006-5835P4MEDIUMCVSS 5.0v5.0.3v5.0.12+14 more2006-11-10
CVE-2006-5835 [MEDIUM] CVE-2006-5835: The Notes Remote Procedure Call (NRPC) protocol in IBM Lotus Notes Domino before 6.5.5 FP2 and 7.x b The Notes Remote Procedure Call (NRPC) protocol in IBM Lotus Notes Domino before 6.5.5 FP2 and 7.x before 7.0.2 does not require authentication to perform user lookups, which allows remote attackers to obtain the user ID file.
nvd
CVE-2013-0522P4HIGHCVSS 7.0v8.0v8.0.1+6 more2018-07-16
CVE-2013-0522 [HIGH] CWE-200 CVE-2013-0522: The Notes Client Single Logon feature in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3, and The Notes Client Single Logon feature in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3, and 9.0 on Windows allows local users to discover passwords via vectors involving an unspecified operating system communication mechanism for password transmission between Windows and Notes. IBM X-Force ID: 82531.
nvd
CVE-2013-0536P4HIGHCVSS 7.2v8.0v8.0.1+3 more2013-06-21
CVE-2013-0536 [HIGH] CWE-264 CVE-2013-0536: ntmulti.exe in the Multi User Profile Cleanup service in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8. ntmulti.exe in the Multi User Profile Cleanup service in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3 before FP5, and 9.0 before IF2 allows local users to gain privileges via vectors that arrange for code to be executed during the next login session of a different user, aka SPR PJOK959J24.
nvd
CVE-2006-0121P4HIGHCVSS 7.8v6.5v6.5.1+3 more2006-01-09
CVE-2006-0121 [HIGH] CVE-2006-0121: Multiple memory leaks in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a d Multiple memory leaks in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (memory consumption and crash) via unknown vectors related to (1) unspecified vectors during the SSL handshake (SPR# MKIN67MQVW), (2) the stash file during the SSL handshake (SPR# MKIN693QUT), and possibly other vectors. NOTE: due to insufficient
nvd
CVE-2007-5544P4HIGHCVSS 7.8≤ 6.5.5≥ 7.0.0, < 7.0.32007-10-29
CVE-2007-5544 [HIGH] CWE-732 CVE-2007-5544: IBM Lotus Notes before 6.5.6, and 7.x before 7.0.3; and Domino before 6.5.5 FP3, and 7.x before 7.0. IBM Lotus Notes before 6.5.6, and 7.x before 7.0.3; and Domino before 6.5.5 FP3, and 7.x before 7.0.2 FP1; uses weak permissions (Everyone:Full Control) for memory mapped files (shared memory) in IPC, which allows local users to obtain sensitive information, or inject Lotus Script or other character sequences into a session.
nvd
CVE-2000-1138P4HIGHCVSS 7.5≤ 5.0.5v5.0+4 more2001-01-09
CVE-2000-1138 [HIGH] CVE-2000-1138: Lotus Notes R5 client R5.0.5 and earlier does not properly warn users when an S/MIME email message h Lotus Notes R5 client R5.0.5 and earlier does not properly warn users when an S/MIME email message has been modified, which could allow an attacker to modify the email in transit without being detected.
nvd
CVE-2006-3778P4MEDIUMCVSS 5.0v6.0v6.5+1 more2006-07-24
CVE-2006-3778 [MEDIUM] CVE-2006-3778: IBM Lotus Notes 6.0, 6.5, and 7.0 does not properly handle replies to e-mail messages with alternate IBM Lotus Notes 6.0, 6.5, and 7.0 does not properly handle replies to e-mail messages with alternate name users when the (1) "Save As Draft" option is used or (2) a "," (comma) is inside the "phrase" portion of an address, which can cause the e-mail to be sent to users that were deleted from the To, CC, and BCC fields, which allows remote attackers to obtain
nvd
CVE-1999-0429P4HIGHCVSS 7.5v4.51999-03-01
CVE-1999-0429 [HIGH] CVE-1999-0429: The Lotus Notes 4.5 client may send a copy of encrypted mail in the clear across the network if the The Lotus Notes 4.5 client may send a copy of encrypted mail in the clear across the network if the user does not set the "Encrypt Saved Mail" preference.
nvd
CVE-2013-0538P4MEDIUMCVSS 4.3v8.0v8.0.0+28 more2013-05-01
CVE-2013-0538 [MEDIUM] CWE-79 CVE-2013-0538: Cross-site scripting (XSS) vulnerability in IBM Lotus Notes 8.x before 8.5.3 FP4 Interim Fix 1 and 9 Cross-site scripting (XSS) vulnerability in IBM Lotus Notes 8.x before 8.5.3 FP4 Interim Fix 1 and 9.0 before Interim Fix 1 allows remote attackers to inject arbitrary web script or HTML via a SCRIPT element in an HTML e-mail message, aka SPRs JMOY95BLM6 and JMOY95BN49.
nvd
CVE-2006-0117P4MEDIUMCVSS 5.0v6.5v6.5.1+3 more2006-01-09
CVE-2006-0117 [MEDIUM] CVE-2006-0117: Buffer overflow in IBM Lotus Notes and Domino Server before 6.5.5 allows attackers to cause a denial Buffer overflow in IBM Lotus Notes and Domino Server before 6.5.5 allows attackers to cause a denial of service (router crash or hang) via unspecified vectors involving "CD to MIME Conversion".
nvd
CVE-2006-0118P4MEDIUMCVSS 5.0v6.5v6.5.1+3 more2006-01-09
CVE-2006-0118 [MEDIUM] CVE-2006-0118: Unspecified vulnerability in IBM Lotus Notes and Domino Server before 6.5.5, when running on AIX, al Unspecified vulnerability in IBM Lotus Notes and Domino Server before 6.5.5, when running on AIX, allows attackers to cause a denial of service (deep recursion leading to stack overflow and crash) via long formulas.
nvd
CVE-2010-5251P4MEDIUMCVSS 6.9v8.52012-09-07
CVE-2010-5251 [MEDIUM] CVE-2010-5251: Multiple untrusted search path vulnerabilities in IBM Lotus Notes 8.5 allow local users to gain priv Multiple untrusted search path vulnerabilities in IBM Lotus Notes 8.5 allow local users to gain privileges via a Trojan horse (1) nnoteswc.dll or (2) nlsxbe.dll file in the current working directory, as demonstrated by a directory that contains a .vcf, .vcs, or .ics file. NOTE: the provenance of this information is unknown; the details are obtained solely fro
nvd
CVE-2008-0862P4MEDIUMCVSS 4.3v6.0v6.5+2 more2008-02-21
CVE-2008-0862 [MEDIUM] CWE-264 CVE-2008-0862: IBM Lotus Notes 6.0, 6.5, 7.0, and 8.0 signs an unsigned applet when a user forwards an email messag IBM Lotus Notes 6.0, 6.5, 7.0, and 8.0 signs an unsigned applet when a user forwards an email message to another user, which allows user-assisted remote attackers to bypass Execution Control List (ECL) protection.
nvd
CVE-2005-1442P4MEDIUMCVSS 4.6v6.0v6.0.1+7 more2005-05-03
CVE-2005-1442 [MEDIUM] CVE-2005-1442: Buffer overflow in the Lotus Notes client for Domino 6.5 before 6.5.4 and 6.0 before 6.0.5 allows lo Buffer overflow in the Lotus Notes client for Domino 6.5 before 6.5.4 and 6.0 before 6.0.5 allows local users to cause a denial of service (client crash) and possibly execute arbitrary code via the NOTES.INI file.
nvd
CVE-2007-6594P4MEDIUMCVSS 6.9≤ 8.0.12007-12-28
CVE-2007-6594 [MEDIUM] CWE-264 CVE-2007-6594: IBM Lotus Notes 8 for Linux before 8.0.1 uses (1) unspecified weak permissions for the installation IBM Lotus Notes 8 for Linux before 8.0.1 uses (1) unspecified weak permissions for the installation kit obtained through a Notes 8 download and (2) 0777 permissions for the installdata file that is created by setup.sh, which allows local users to gain privileges via a Trojan horse file.
nvd
Ibm Lotus Notes vulnerabilities | cvebase