7.8

CVE-2018-1771

IBM Domino 9.0 and 9.0.1 could allow an attacker to execute commands on the system by triggering a buffer overflow in the parsing of command line arguments passed to nsd.exe. IBM X-force ID: 148687.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Domino Version >= 9.0.1.0 <= 9.0.1.10
Ibm ≫ Domino Version 9.0.0.0 Update if1
Ibm ≫ Domino Version 9.0.0.0 Update if2
Ibm ≫ Domino Version 9.0.0.0 Update if3
Ibm ≫ Domino Version 9.0.0.0 Update if4
Ibm ≫ Domino Version 9.0.1.10 Update if1
Ibm ≫ Domino Version 9.0.1.10 Update if2
Ibm ≫ Domino Version 9.0.1.10 Update if3
Ibm ≫ Domino Version 9.0.1.10 Update if4
Ibm ≫ Notes Version >= 9.0.1.0 <= 9.0.1.10
Ibm ≫ Notes Version 9.0.0.0 Update if1
Ibm ≫ Notes Version 9.0.0.0 Update if2
Ibm ≫ Notes Version 9.0.0.0 Update if3
Ibm ≫ Notes Version 9.0.0.0 Update if4
Ibm ≫ Notes Version 9.0.1.10 Update if1
Ibm ≫ Notes Version 9.0.1.10 Update if2
Ibm ≫ Notes Version 9.0.1.10 Update if3
Ibm ≫ Notes Version 9.0.1.10 Update if4
Ibm ≫ Notes Version 9.0.1.10 Update if5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.48% 0.377
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
IBM 8.4 2.5 5.9
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

https://exchange.xforce.ibmcloud.com/vulnerabilities/148687
Vendor Advisory
VDB Entry
https://www.ibm.com/support/docview.wss?uid=ibm10743405
Patch
Vendor Advisory