Skip to main content

Vendor/product archive

ibm / lotus_domino CVEs

Beta · best-effort

106 CVEs tagged to ibm / lotus_domino28 Critical, 16 High, 46 Medium, 16 Low, 0 Unrated.

CVE-2007-0068

Published Jun 6, 2007

IBM Lotus Domino 7.0.x before 7.0.3 does not revalidate the signature on a signed scheduled agent after the agent is modified, which allows remote authenticated users to gain priv…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-4843

Published Mar 29, 2007

Cross-site scripting (XSS) vulnerability in the Active Content Filter feature in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to inject arbitrary…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-1739

Published Mar 28, 2007

Heap-based buffer overflow in the LDAP server in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to cause a denial of service (crash) via a long, ma…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2007-1675

Published Mar 28, 2007

Buffer overflow in the CRAM-MD5 authentication mechanism in the IMAP server (nimap.exe) in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to cause…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-0977

Published Feb 16, 2007

IBM Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores HTTPPassword hashes from names.nsf in a manner accessible through Readviewentries and OpenD…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2006-5818

Published Nov 8, 2006

Multiple buffer overflows in tunekrnl in IBM Lotus Domino 6.x before 6.5.5 FP2 and 7.x before 7.0.2 allow local users to gain privileges and execute arbitrary code via unspecified…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2005-2712

Published Dec 31, 2005

The LDAP server (nldap.exe) in IBM Lotus Domino before 7.0.1, 6.5.5, and 6.5.4 FP2 allows remote attackers to cause a denial of service (crash) via a long bind request, which trig…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4819

Published Dec 31, 2005

Cross-site scripting (XSS) vulnerability in Lotus Domino versions before 6.5.4 fix pack 1 (FP1) and versions before 7.0 allows remote attackers to inject arbitrary web script or H…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-2428

Published Aug 3, 2005

Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1441

Published May 3, 2005

Format string vulnerability in Lotus Domino 6.0.x before 6.0.5 and 6.5.x before 6.5.4 allows remote attackers to cause a denial of service via the Notes protocol (NRPC).

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2310

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows remote attackers to inject arbitrary web script or HTML via a Domino command in the Quick…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2311

Published Dec 31, 2004

Directory traversal vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows local users to create folders or determine the existence of files via a .. (dot dot) in the new f…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-2369

Published Dec 31, 2004

Directory traversal vulnerability in webadmin.nsf for Lotus Domino R6 6.5.1 allows attackers to create and detect directories via a .. (dot dot) in the directory creation command.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2667

Published Dec 31, 2004

Cross-site scripting (XSS) vulnerability in Lotus Domino 6.0.x before 6.0.4 and 6.5.x before 6.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attac…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1621

Published Oct 18, 2004

NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Domino R6, and possibly earlier versions, allows remote attac…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0668

Published Aug 6, 2004

Web Access in Lotus Domino 6.5.1 allows remote attackers to cause a denial of service (server crash) via a large e-mail message, as demonstrated using a large image attachment.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0669

Published Aug 6, 2004

Lotus Domino 6.5.0 and 6.5.1, with IMAP enabled, allows remote authenticated users to change their quota by using the IMAP setquota command.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0029

Published Jan 20, 2004

Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain pr…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-0122

Published Mar 18, 2003

Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote attackers to execute arbitrary code via a long distinguished name (DN) during N…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 76-100 of 106 CVEsPage 4 of 5