5.8

CVE-2013-0127

IBM Lotus Notes 8.x before 8.5.3 FP4 Interim Fix 1 and 9.0 before Interim Fix 1 does not block APPLET elements in HTML e-mail, which allows remote attackers to bypass intended restrictions on Java code execution and X-Confirm-Reading-To functionality via a crafted message, aka SPRs JMOY95BLM6 and JMOY95BN49.

Data is provided by the National Vulnerability Database (NVD)
IbmLotus Notes Version8.0
IbmLotus Notes Version8.0.0
IbmLotus Notes Version8.0.1
IbmLotus Notes Version8.0.2
IbmLotus Notes Version8.0.2.0
IbmLotus Notes Version8.0.2.1
IbmLotus Notes Version8.0.2.2
IbmLotus Notes Version8.0.2.3
IbmLotus Notes Version8.0.2.4
IbmLotus Notes Version8.0.2.5
IbmLotus Notes Version8.0.2.6
IbmLotus Notes Version8.5
IbmLotus Notes Version8.5.0.0
IbmLotus Notes Version8.5.0.1
IbmLotus Notes Version8.5.1
IbmLotus Notes Version8.5.1.0
IbmLotus Notes Version8.5.1.1
IbmLotus Notes Version8.5.1.2
IbmLotus Notes Version8.5.1.3
IbmLotus Notes Version8.5.1.4
IbmLotus Notes Version8.5.1.5
IbmLotus Notes Version8.5.2.0
IbmLotus Notes Version8.5.2.1
IbmLotus Notes Version8.5.2.2
IbmLotus Notes Version8.5.2.3
IbmLotus Notes Version8.5.3
IbmLotus Notes Version8.5.3.1
IbmLotus Notes Version8.5.3.2
IbmLotus Notes Version8.5.3.3
IbmLotus Notes Version9.0.0.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.07% 0.757
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N