Skip to main content

Vendor/product archive

ibm / lotus_domino CVEs

Beta · best-effort

106 CVEs tagged to ibm / lotus_domino28 Critical, 16 High, 46 Medium, 16 Low, 0 Unrated.

CVE-2011-0916

Published Feb 8, 2011

Stack-based buffer overflow in the SMTP service in IBM Lotus Domino allows remote attackers to execute arbitrary code via long arguments in a filename parameter in a malformed MIM…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0915

Published Feb 8, 2011

Stack-based buffer overflow in nrouter.exe in IBM Lotus Domino before 8.5.3 allows remote attackers to execute arbitrary code via a long name parameter in a Content-Type header in…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0914

Published Feb 8, 2011

Integer signedness error in ndiiop.exe in the DIIOP implementation in the server in IBM Lotus Domino before 8.5.3 allows remote attackers to execute arbitrary code via a GIOP clie…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-0913

Published Feb 8, 2011

Stack-based buffer overflow in ndiiop.exe in the DIIOP implementation in the server in IBM Lotus Domino before 8.5.3 allows remote attackers to execute arbitrary code via a GIOP g…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-3407

Published Sep 16, 2010

Stack-based buffer overflow in the MailCheck821Address function in nnotes.dll in the nrouter.exe service in the server in IBM Lotus Domino 8.0.x before 8.0.2 FP5 and 8.5.x before…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-0927

Published Mar 5, 2010

Cross-site scripting (XSS) vulnerability in help/readme.nsf/Header in the Help component in IBM Lotus Domino 7.x before 7.0.4 and 8.x before 8.0.2 allows remote attackers to injec…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0921

Published Mar 3, 2010

Cross-site request forgery (CSRF) vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 allows remote attackers to hijack the authen…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0920

Published Mar 3, 2010

Cross-site scripting (XSS) vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 allows remote attackers to inject arbitrary web scr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0918

Published Mar 3, 2010

Multiple unspecified vulnerabilities in the UltraLite functionality in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 have unknown impact and…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-0358

Published Jan 20, 2010

Heap-based buffer overflow in the server in IBM Lotus Domino 7 and 8.5 FP1 allows remote attackers to cause a denial of service (daemon exit) and possibly have unspecified other i…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-0275

Published Jan 9, 2010

Ultra-light Mode in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 does not properly handle script commands in the status-alerts URL, which ha…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-0274

Published Jan 9, 2010

Unspecified vulnerability in the Edit Contact scene in Ultra-light Mode in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 has unknown impact a…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-4594

Published Jan 9, 2010

Unspecified vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.131 for Domino 8.0.x has unknown impact and attack vectors, aka SPR SDOY7RHBNH.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-3087

Published Sep 8, 2009

Unspecified vulnerability in nserver.exe in the server in IBM Lotus Domino 8.0 on Windows Server 2003 allows remote attackers to cause a denial of service (daemon crash) via unkno…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-1286

Published Apr 13, 2009

The IMAP task in the server in IBM Lotus Domino 8.0.2 before FP1 IF1 and 8.5 before IF3 allows remote attackers to cause a denial of service (daemon crash) via a MIME e-mail messa…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5011

Published Nov 10, 2008

Multiple cross-site scripting (XSS) vulnerabilities in IBM Lotus Quickr 8.1 before 8.1.0.2 services for Lotus Domino allow remote attackers to inject arbitrary web script or HTML…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-2240

Published May 22, 2008

Stack-based buffer overflow in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote attackers to cause a denial of service (daemon cras…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-0243

Published Jan 12, 2008

Unspecified vulnerability in Lotus Domino 7.0.2 before Fix Pack 3 allows attackers to cause a denial of service via unknown vectors.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5924

Published Nov 10, 2007

Cross-site scripting (XSS) vulnerability in the Web Server (HTTP) task in IBM Lotus Domino before 6.5.6 FP2, and 7.x before 7.0.2 FP2, allows remote authenticated users to inject…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-3510

Published Oct 29, 2007

Buffer overflow in the IMAP service in IBM Lotus Domino before 6.5.6 FP2, and 7.x before 7.0.3, allows remote authenticated users to execute arbitrary code via a long mailbox name.

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-5544

Published Oct 29, 2007

IBM Lotus Notes before 6.5.6, and 7.x before 7.0.3; and Domino before 6.5.5 FP3, and 7.x before 7.0.2 FP1; uses weak permissions (Everyone:Full Control) for memory mapped files (s…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-5700

Published Oct 29, 2007

The Evaluate LotusScript method in IBM Lotus Domino before 7.0.3 uses an incorrect security context for @ formula commands in some circumstances, which might allow remote authenti…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-5701

Published Oct 29, 2007

Incomplete blacklist vulnerability in the Certificate Authority (CA) in IBM Lotus Domino before 7.0.3 allows local users, or attackers with physical access, to obtain sensitive in…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 51-75 of 106 CVEsPage 3 of 5