10

CVE-2020-14268

A vulnerability in the MIME message handling of the Notes client (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer overflow. This could allow a remote attacker to crash the client or inject code into the system which would execute with the privileges of the client.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
HcltechNotes Version >= 9.0 < 9.0.1
HcltechNotes Version >= 10.0 < 10.0.1
HcltechNotes Version9.0.1 Update-
HcltechNotes Version9.0.1 Updatefp10
HcltechNotes Version9.0.1 Updatefp10if1
HcltechNotes Version9.0.1 Updatefp10if2
HcltechNotes Version9.0.1 Updatefp10if3
HcltechNotes Version9.0.1 Updatefp10if4
HcltechNotes Version9.0.1 Updatefp10if5
HcltechNotes Version9.0.1 Updatefp10if6
HcltechNotes Version9.0.1 Updatefp10if7
HcltechNotes Version9.0.1 Updatefp1if1
HcltechNotes Version9.0.1 Updatefp1if2
HcltechNotes Version9.0.1 Updatefp2if1
HcltechNotes Version9.0.1 Updatefp2if2
HcltechNotes Version9.0.1 Updatefp2if3
HcltechNotes Version9.0.1 Updatefp2if4
HcltechNotes Version9.0.1 Updatefp3if1
HcltechNotes Version9.0.1 Updatefp3if2
HcltechNotes Version9.0.1 Updatefp3if3
HcltechNotes Version9.0.1 Updatefp3if4
HcltechNotes Version9.0.1 Updatefp4if1
HcltechNotes Version9.0.1 Updatefp4if2
HcltechNotes Version9.0.1 Updatefp5if1
HcltechNotes Version9.0.1 Updatefp5if2
HcltechNotes Version9.0.1 Updatefp5if3
HcltechNotes Version9.0.1 Updatefp7if1
HcltechNotes Version9.0.1 Updatefp7if2
HcltechNotes Version9.0.1 Updatefp8if1
HcltechNotes Version9.0.1 Updatefp9if1
HcltechNotes Version9.0.1 Updatefp9if2
HcltechNotes Version10.0.1 Update-
HcltechNotes Version10.0.1 Updatefp1
HcltechNotes Version10.0.1 Updatefp2
HcltechNotes Version10.0.1 Updatefp3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.67% 0.804
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.