Skip to main content

Vendor/product archive

ibm / lotus_notes_traveler CVEs

Beta · best-effort

25 CVEs tagged to ibm / lotus_notes_traveler4 Critical, 1 High, 17 Medium, 3 Low, 0 Unrated.

CVE-2012-5309

Published Oct 8, 2012

servlet/traveler in IBM Lotus Notes Traveler through 8.5.3.3 Interim Fix 1 does not properly restrict invalid authentication attempts, which makes it easier for remote attackers t…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5308

Published Oct 8, 2012

Cross-site request forgery (CSRF) vulnerability in servlet/traveler in IBM Lotus Notes Traveler through 8.5.3.3 Interim Fix 1 allows remote attackers to hijack the authentication…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5307

Published Oct 8, 2012

Cross-site scripting (XSS) vulnerability in servlet/traveler in IBM Lotus Notes Traveler before 8.5.3.3 Interim Fix 1, when Firefox is used, allows remote attackers to inject arbi…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-4825

Published Oct 8, 2012

Multiple cross-site scripting (XSS) vulnerabilities in servlet/traveler/ILNT.mobileconfig in IBM Lotus Notes Traveler before 8.5.3.2 allow remote attackers to inject arbitrary web…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4824

Published Oct 8, 2012

Open redirect vulnerability in servlet/traveler in IBM Lotus Notes Traveler 8.5.3 before 8.5.3.3 Interim Fix 1 allows remote attackers to redirect users to arbitrary web sites and…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4553

Published Dec 16, 2010

An unspecified Domino API in IBM Lotus Notes Traveler before 8.5.1.1 does not properly handle MIME types, which allows remote attackers to cause a denial of service (daemon crash)…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4552

Published Dec 16, 2010

Memory leak in IBM Lotus Notes Traveler before 8.5.1.1 allows remote attackers to cause a denial of service (memory consumption and daemon outage) by sending many embedded objects…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4551

Published Dec 16, 2010

IBM Lotus Notes Traveler before 8.5.1.2 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by omitting the Internet ID fiel…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4550

Published Dec 16, 2010

IBM Lotus Notes Traveler before 8.5.1.3 allows remote attackers to cause a denial of service (sync failure) via a malformed document.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4549

Published Dec 16, 2010

IBM Lotus Notes Traveler before 8.5.1.3 on the Nokia s60 device successfully performs a Replace Data operation for a prohibited application, which allows remote authenticated user…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4548

Published Dec 16, 2010

IBM Lotus Notes Traveler before 8.5.1.2 allows remote authenticated users to cause a denial of service (daemon crash) by accepting a meeting invitation with an iNotes client and t…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-4547

Published Dec 16, 2010

IBM Lotus Notes Traveler before 8.5.1.3, when a multidomain environment is used, does not properly apply policy documents to mobile users from a different Domino domain than the T…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-4546

Published Dec 16, 2010

IBM Lotus Notes Traveler before 8.5.1.2 does not reject an attachment download request for an e-mail message with a Prevent Copy attribute, which allows remote authenticated users…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4545

Published Dec 16, 2010

IBM Lotus Notes Traveler before 8.5.1.2 allows remote authenticated users to cause a denial of service (resource consumption and sync outage) by syncing a large volume of data.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4544

Published Dec 16, 2010

Cross-site scripting (XSS) vulnerability in the servlet in IBM Lotus Notes Traveler before 8.5.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified v…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-5036

Published Dec 16, 2010

traveler.exe in IBM Lotus Notes Traveler before 8.0.1.3 CF1 allows remote authenticated users to cause a denial of service (daemon crash) via a malformed invitation document in a…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-5035

Published Dec 16, 2010

The Nokia client in IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle multiple outgoing e-mail messages between sync operations, which might allow remote attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-5034

Published Dec 16, 2010

IBM Lotus Notes Traveler before 8.5.0.2 allows remote authenticated users to cause a denial of service (memory consumption and daemon crash) by syncing a large volume of data, rel…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-5033

Published Dec 16, 2010

IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle a "* *" argument sequence for a certain tell command, which allows remote authenticated users to obtain access to…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-5032

Published Dec 16, 2010

The encrypted e-mail feature in IBM Lotus Notes Traveler before 8.5.0.2 sends unencrypted messages when the feature is used without uploading a Notes ID file, which makes it easie…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 25 CVEsPage 1 of 1