cbcvebase.

Ibm Lotus Notes vulnerabilities

69 known vulnerabilities affecting ibm/lotus_notes.

Total CVEs
69
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL35HIGH12MEDIUM19LOW3

Vulnerabilities

Page 4 of 4
CVE-2000-1117P4MEDIUMCVSS 5.0vr52001-01-09
CVE-2000-1117 [MEDIUM] CWE-203 CVE-2000-1117: The Extended Control List (ECL) feature of the Java Virtual Machine (JVM) in Lotus Notes Client R5 a The Extended Control List (ECL) feature of the Java Virtual Machine (JVM) in Lotus Notes Client R5 allows malicious web site operators to determine the existence of files on the client by measuring delays in the execution of the getSystemResource method.
nvd
CVE-2006-0120P4MEDIUMCVSS 5.0v6.5v6.5.1+3 more2006-01-09
CVE-2006-0120 [MEDIUM] CVE-2006-0120: Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 allow attacke Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (application crash) via multiple vectors, involving (1) a malformed message sent to an "Out Of Office" agent (SPR LPEE6DMQWJ), (2) the compact command (RTIN5U2SAJ), (3) malformed bitmap images (MYAA6FH5HW), (4) the "Delete Attach
nvd
CVE-2012-4846P4MEDIUMCVSS 4.3v8.5.0.0v8.5.0.1+14 more2012-12-19
CVE-2012-4846 [MEDIUM] CWE-200 CVE-2012-4846: IBM Lotus Notes 8.5.x before 8.5.3 FP3 does not include the HTTPOnly flag in a Set-Cookie header for IBM Lotus Notes 8.5.x before 8.5.3 FP3 does not include the HTTPOnly flag in a Set-Cookie header for a web-application cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie, aka SPRs JMAS7TRNLN and SRAO8U3Q68.
nvd
CVE-2005-2454P4MEDIUMCVSS 4.6v6.5.4v6.5.5+2 more2005-12-31
CVE-2005-2454 [MEDIUM] CWE-264 CVE-2005-2454: IBM Lotus Notes 6.5.4 and 6.5.5, and 7.0.0 and 7.0.1, uses insecure default permissions (Everyone/Fu IBM Lotus Notes 6.5.4 and 6.5.5, and 7.0.0 and 7.0.1, uses insecure default permissions (Everyone/Full Control) for the "Notes" folder and all children, which allows local users to gain privileges and modify, add, or delete files in that folder.
nvd
CVE-2007-1941P4MEDIUMCVSS 4.3v6.5.5v7.0+1 more2007-04-11
CVE-2007-1941 [MEDIUM] CVE-2007-1941: Cross-site scripting (XSS) vulnerability in the Active Content Filter feature in Domino Web Access ( Cross-site scripting (XSS) vulnerability in the Active Content Filter feature in Domino Web Access (DWA) in IBM Lotus Notes before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to inject arbitrary web script or HTML via a multipart/related e-mail message, a different issue than CVE-2006-4843.
nvd
CVE-2006-1948P4MEDIUMCVSS 4.0v6.0v6.52006-04-20
CVE-2006-1948 [MEDIUM] CVE-2006-1948: The "Add Sender to Address Book" operation (AddSenderToAddressBook.lss) and NameHelper.lss in IBM Lo The "Add Sender to Address Book" operation (AddSenderToAddressBook.lss) and NameHelper.lss in IBM Lotus Notes 6.0 and 6.5 before 20060331 do not properly store information in the Personal Address Book when multiple messages are checked and a message uses AltFrom, which might allow user-assisted remote attackers to trick a user into sending e-mail to an unauth
nvd
CVE-2007-4309P4LOWCVSS 3.5v5.0v6.0+3 more2007-08-13
CVE-2007-4309 [LOW] CVE-2007-4309: IBM Lotus Notes 5.x through 7.0.2 allows user-assisted remote authenticated administrators to obtain IBM Lotus Notes 5.x through 7.0.2 allows user-assisted remote authenticated administrators to obtain a cleartext notes.id password by setting the notes.ini (1) KFM_ShowEntropy and (2) Debug_Outfile debug variables, a different vulnerability than CVE-2005-2696.
nvd
CVE-2005-1405P4LOWCVSS 2.1v6.0v6.0.1+7 more2005-05-03
CVE-2005-1405 [LOW] CVE-2005-1405: HTTP response splitting vulnerability in the @SetHTTPHeader function in Lotus Domino 6.5.x before 6. HTTP response splitting vulnerability in the @SetHTTPHeader function in Lotus Domino 6.5.x before 6.5.4 and 6.0.x before 6.0.5 allows attackers to poison the web cache via malicious applications.
nvd
CVE-2010-1487P4LOWCVSS 2.1v7.0v8.0+1 more2010-04-20
CVE-2010-1487 [LOW] CWE-255 CVE-2010-1487: IBM Lotus Notes 7.0, 8.0, and 8.5 stores administrative credentials in cleartext in SURunAs.exe, whi IBM Lotus Notes 7.0, 8.0, and 8.5 stores administrative credentials in cleartext in SURunAs.exe, which allows local users to obtain sensitive information by examining this file, aka SPR JSTN837SEG.
nvd
Ibm Lotus Notes vulnerabilities | cvebase