Ibm Lotus Notes vulnerabilities

69 known vulnerabilities affecting ibm/lotus_notes.

Total CVEs
69
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL35HIGH12MEDIUM19LOW3

Vulnerabilities

Page 3 of 4
CVE-2007-6594MEDIUMCVSS 6.9≤ 8.0.12007-12-28
CVE-2007-6594 [MEDIUM] CWE-264 CVE-2007-6594: IBM Lotus Notes 8 for Linux before 8.0.1 uses (1) unspecified weak permissions for the installation IBM Lotus Notes 8 for Linux before 8.0.1 uses (1) unspecified weak permissions for the installation kit obtained through a Notes 8 download and (2) 0777 permissions for the installdata file that is created by setup.sh, which allows local users to gain privileges via a Trojan horse file.
nvd
CVE-2007-5909CRITICALCVSS 9.3≤ 7.0.22007-11-10
CVE-2007-5909 [CRITICAL] CWE-119 CVE-2007-5909: Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Expo Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, IBM Lotus Notes before 7.0.3, Symantec Mail Security, and other products, allow remote attackers to execute arbitrary code via a crafted (1) AG file to kpagrdr.dll, (2) AW file to awsr.dll, (3
nvd
CVE-2007-5910CRITICALCVSS 9.3≤ 7.0.22007-11-10
CVE-2007-5910 [CRITICAL] CWE-119 CVE-2007-5910: Stack-based buffer overflow in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK bef Stack-based buffer overflow in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, wp6sr.dll in IBM Lotus Notes 8.0 and before 7.0.3, Symantec Mail Security, and other products, allows remote attackers to execute arbitrary code via a crafted WordPerfect (WPD) file.
nvd
CVE-2007-4222CRITICALCVSS 9.3≤ 7.0.22007-10-29
CVE-2007-4222 [CRITICAL] CWE-119 CVE-2007-4222: Buffer overflow in the TagAttributeListCopy function in nnotes.dll in IBM Lotus Notes before 7.0.3 a Buffer overflow in the TagAttributeListCopy function in nnotes.dll in IBM Lotus Notes before 7.0.3 allows user-assisted remote attackers to execute arbitrary code via a crafted HTML email, related to duplicate RTF conversion when the recipient operates on this email.
nvd
CVE-2007-5544HIGHCVSS 7.8≤ 6.5.5≥ 7.0.0, < 7.0.32007-10-29
CVE-2007-5544 [HIGH] CWE-732 CVE-2007-5544: IBM Lotus Notes before 6.5.6, and 7.x before 7.0.3; and Domino before 6.5.5 FP3, and 7.x before 7.0. IBM Lotus Notes before 6.5.6, and 7.x before 7.0.3; and Domino before 6.5.5 FP3, and 7.x before 7.0.2 FP1; uses weak permissions (Everyone:Full Control) for memory mapped files (shared memory) in IPC, which allows local users to obtain sensitive information, or inject Lotus Script or other character sequences into a session.
nvd
CVE-2007-4309LOWCVSS 3.5v5.0v6.0+3 more2007-08-13
CVE-2007-4309 [LOW] CVE-2007-4309: IBM Lotus Notes 5.x through 7.0.2 allows user-assisted remote authenticated administrators to obtain IBM Lotus Notes 5.x through 7.0.2 allows user-assisted remote authenticated administrators to obtain a cleartext notes.id password by setting the notes.ini (1) KFM_ShowEntropy and (2) Debug_Outfile debug variables, a different vulnerability than CVE-2005-2696.
nvd
CVE-2007-1941MEDIUMCVSS 4.3v6.5.5v7.0+1 more2007-04-11
CVE-2007-1941 [MEDIUM] CVE-2007-1941: Cross-site scripting (XSS) vulnerability in the Active Content Filter feature in Domino Web Access ( Cross-site scripting (XSS) vulnerability in the Active Content Filter feature in Domino Web Access (DWA) in IBM Lotus Notes before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to inject arbitrary web script or HTML via a multipart/related e-mail message, a different issue than CVE-2006-4843.
nvd
CVE-2006-5835MEDIUMCVSS 5.0v5.0.3v5.0.12+14 more2006-11-10
CVE-2006-5835 [MEDIUM] CVE-2006-5835: The Notes Remote Procedure Call (NRPC) protocol in IBM Lotus Notes Domino before 6.5.5 FP2 and 7.x b The Notes Remote Procedure Call (NRPC) protocol in IBM Lotus Notes Domino before 6.5.5 FP2 and 7.x before 7.0.2 does not require authentication to perform user lookups, which allows remote attackers to obtain the user ID file.
nvd
CVE-2006-3778MEDIUMCVSS 5.0v6.0v6.5+1 more2006-07-24
CVE-2006-3778 [MEDIUM] CVE-2006-3778: IBM Lotus Notes 6.0, 6.5, and 7.0 does not properly handle replies to e-mail messages with alternate IBM Lotus Notes 6.0, 6.5, and 7.0 does not properly handle replies to e-mail messages with alternate name users when the (1) "Save As Draft" option is used or (2) a "," (comma) is inside the "phrase" portion of an address, which can cause the e-mail to be sent to users that were deleted from the To, CC, and BCC fields, which allows remote attackers to obtain
nvd
CVE-2006-1948MEDIUMCVSS 4.0v6.0v6.52006-04-20
CVE-2006-1948 [MEDIUM] CVE-2006-1948: The "Add Sender to Address Book" operation (AddSenderToAddressBook.lss) and NameHelper.lss in IBM Lo The "Add Sender to Address Book" operation (AddSenderToAddressBook.lss) and NameHelper.lss in IBM Lotus Notes 6.0 and 6.5 before 20060331 do not properly store information in the Personal Address Book when multiple messages are checked and a message uses AltFrom, which might allow user-assisted remote attackers to trick a user into sending e-mail to an unauth
nvd
CVE-2006-0119CRITICALCVSS 10.0v6.5v6.5.1+3 more2006-01-09
CVE-2006-0119 [CRITICAL] CVE-2006-0119: Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 have unknown Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 have unknown impact and attack vectors, due to "potential security issues" as identified by SPR numbers (1) GPKS6C9J67 in Agents, (2) JGAN6B6TZ3 and (3) KSPR699NBP in the Router, (4) GPKS5YQGPT in Security, or (5) HSAO6BNL6Y in the Web Server. NOTE: vector 3 is related to
nvd
CVE-2006-0121HIGHCVSS 7.8v6.5v6.5.1+3 more2006-01-09
CVE-2006-0121 [HIGH] CVE-2006-0121: Multiple memory leaks in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a d Multiple memory leaks in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (memory consumption and crash) via unknown vectors related to (1) unspecified vectors during the SSL handshake (SPR# MKIN67MQVW), (2) the stash file during the SSL handshake (SPR# MKIN693QUT), and possibly other vectors. NOTE: due to insufficient
nvd
CVE-2006-0117MEDIUMCVSS 5.0v6.5v6.5.1+3 more2006-01-09
CVE-2006-0117 [MEDIUM] CVE-2006-0117: Buffer overflow in IBM Lotus Notes and Domino Server before 6.5.5 allows attackers to cause a denial Buffer overflow in IBM Lotus Notes and Domino Server before 6.5.5 allows attackers to cause a denial of service (router crash or hang) via unspecified vectors involving "CD to MIME Conversion".
nvd
CVE-2006-0118MEDIUMCVSS 5.0v6.5v6.5.1+3 more2006-01-09
CVE-2006-0118 [MEDIUM] CVE-2006-0118: Unspecified vulnerability in IBM Lotus Notes and Domino Server before 6.5.5, when running on AIX, al Unspecified vulnerability in IBM Lotus Notes and Domino Server before 6.5.5, when running on AIX, allows attackers to cause a denial of service (deep recursion leading to stack overflow and crash) via long formulas.
nvd
CVE-2006-0120MEDIUMCVSS 5.0v6.5v6.5.1+3 more2006-01-09
CVE-2006-0120 [MEDIUM] CVE-2006-0120: Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 allow attacke Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (application crash) via multiple vectors, involving (1) a malformed message sent to an "Out Of Office" agent (SPR LPEE6DMQWJ), (2) the compact command (RTIN5U2SAJ), (3) malformed bitmap images (MYAA6FH5HW), (4) the "Delete Attach
nvd
CVE-2005-2618CRITICALCVSS 9.3v6.0.1v6.0.2+9 more2005-12-31
CVE-2005-2618 [CRITICAL] CWE-119 CVE-2005-2618: Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as use Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allow remote attackers to execute arbitrary code via (1) a UUE file containing an encoded file with a long filename handled by uudrdr.dll, (2) a compressed ZIP file with a long filename handled by kvarcve.dll, (3) a TAR
nvd
CVE-2005-2619CRITICALCVSS 9.3v6.0.1v6.0.2+9 more2005-12-31
CVE-2005-2619 [CRITICAL] CWE-22 CVE-2005-2619: Directory traversal vulnerability in kvarcve.dll in Autonomy (formerly Verity) KeyView SDK before 9. Directory traversal vulnerability in kvarcve.dll in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allows remote attackers to delete arbitrary files via a (1) ZIP, (2) UUE or (3) TAR archive that contains a .. (dot dot) in the filename, which is not properly handled when generating a preview.
nvd
CVE-2005-2454MEDIUMCVSS 4.6v6.5.4v6.5.5+2 more2005-12-31
CVE-2005-2454 [MEDIUM] CWE-264 CVE-2005-2454: IBM Lotus Notes 6.5.4 and 6.5.5, and 7.0.0 and 7.0.1, uses insecure default permissions (Everyone/Fu IBM Lotus Notes 6.5.4 and 6.5.5, and 7.0.0 and 7.0.1, uses insecure default permissions (Everyone/Full Control) for the "Notes" folder and all children, which allows local users to gain privileges and modify, add, or delete files in that folder.
nvd
CVE-2005-1442MEDIUMCVSS 4.6v6.0v6.0.1+7 more2005-05-03
CVE-2005-1442 [MEDIUM] CVE-2005-1442: Buffer overflow in the Lotus Notes client for Domino 6.5 before 6.5.4 and 6.0 before 6.0.5 allows lo Buffer overflow in the Lotus Notes client for Domino 6.5 before 6.5.4 and 6.0 before 6.0.5 allows local users to cause a denial of service (client crash) and possibly execute arbitrary code via the NOTES.INI file.
nvd
CVE-2005-1405LOWCVSS 2.1v6.0v6.0.1+7 more2005-05-03
CVE-2005-1405 [LOW] CVE-2005-1405: HTTP response splitting vulnerability in the @SetHTTPHeader function in Lotus Domino 6.5.x before 6. HTTP response splitting vulnerability in the @SetHTTPHeader function in Lotus Domino 6.5.x before 6.5.4 and 6.0.x before 6.0.5 allows attackers to poison the web cache via malicious applications.
nvd