9.8

CVE-2022-44751

HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView.  This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44755.  This vulnerability applies to software previously licensed by IBM.

Data is provided by the National Vulnerability Database (NVD)
HcltechNotes Version9.0.1 Update-
HcltechNotes Version9.0.1 Updatefp10
HcltechNotes Version9.0.1 Updatefp10if1
HcltechNotes Version9.0.1 Updatefp10if10
HcltechNotes Version9.0.1 Updatefp10if2
HcltechNotes Version9.0.1 Updatefp10if3
HcltechNotes Version9.0.1 Updatefp10if4
HcltechNotes Version9.0.1 Updatefp10if5
HcltechNotes Version9.0.1 Updatefp10if6
HcltechNotes Version9.0.1 Updatefp10if7
HcltechNotes Version9.0.1 Updatefp10if8
HcltechNotes Version9.0.1 Updatefp1if1
HcltechNotes Version9.0.1 Updatefp1if2
HcltechNotes Version9.0.1 Updatefp2if1
HcltechNotes Version9.0.1 Updatefp2if2
HcltechNotes Version9.0.1 Updatefp2if3
HcltechNotes Version9.0.1 Updatefp2if4
HcltechNotes Version9.0.1 Updatefp3if1
HcltechNotes Version9.0.1 Updatefp3if2
HcltechNotes Version9.0.1 Updatefp3if3
HcltechNotes Version9.0.1 Updatefp3if4
HcltechNotes Version9.0.1 Updatefp4if1
HcltechNotes Version9.0.1 Updatefp4if2
HcltechNotes Version9.0.1 Updatefp5if1
HcltechNotes Version9.0.1 Updatefp5if2
HcltechNotes Version9.0.1 Updatefp5if3
HcltechNotes Version9.0.1 Updatefp7if1
HcltechNotes Version9.0.1 Updatefp7if2
HcltechNotes Version9.0.1 Updatefp8if1
HcltechNotes Version9.0.1 Updatefp9if1
HcltechNotes Version9.0.1 Updatefp9if2
HcltechNotes Version10.0.1 Update-
HcltechNotes Version10.0.1 Updatefp1
HcltechNotes Version10.0.1 Updatefp2
HcltechNotes Version10.0.1 Updatefp3
HcltechNotes Version10.0.1 Updatefp4
HcltechNotes Version10.0.1 Updatefp5
HcltechNotes Version10.0.1 Updatefp6
HcltechNotes Version10.0.1 Updatefp7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 3.14% 0.864
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
psirt@hcl.com 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.