Ibm

Lotus Domino

86 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 83.95%
  • Veröffentlicht 22.05.2008 13:09:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Stack-based buffer overflow in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long Accept-Language HTTP h...

  • EPSS 0.56%
  • Veröffentlicht 12.01.2008 02:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Unspecified vulnerability in Lotus Domino 7.0.2 before Fix Pack 3 allows attackers to cause a denial of service via unknown vectors.

  • EPSS 0.43%
  • Veröffentlicht 10.11.2007 02:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in the Web Server (HTTP) task in IBM Lotus Domino before 6.5.6 FP2, and 7.x before 7.0.2 FP2, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

  • EPSS 0.05%
  • Veröffentlicht 29.10.2007 21:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Incomplete blacklist vulnerability in the Certificate Authority (CA) in IBM Lotus Domino before 7.0.3 allows local users, or attackers with physical access, to obtain sensitive information (passwords) when an administrator enters a "ca activate" or "...

  • EPSS 8.74%
  • Veröffentlicht 29.10.2007 21:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Buffer overflow in the IMAP service in IBM Lotus Domino before 6.5.6 FP2, and 7.x before 7.0.3, allows remote authenticated users to execute arbitrary code via a long mailbox name.

  • EPSS 0.09%
  • Veröffentlicht 29.10.2007 21:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

IBM Lotus Notes before 6.5.6, and 7.x before 7.0.3; and Domino before 6.5.5 FP3, and 7.x before 7.0.2 FP1; uses weak permissions (Everyone:Full Control) for memory mapped files (shared memory) in IPC, which allows local users to obtain sensitive info...

  • EPSS 0.33%
  • Veröffentlicht 29.10.2007 21:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The Evaluate LotusScript method in IBM Lotus Domino before 7.0.3 uses an incorrect security context for @ formula commands in some circumstances, which might allow remote authenticated users to gain privileges and obtain sensitive information.

  • EPSS 1.77%
  • Veröffentlicht 06.06.2007 21:30:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

IBM Lotus Domino 7.0.x before 7.0.3 does not revalidate the signature on a signed scheduled agent after the agent is modified, which allows remote authenticated users to gain privileges via a modified agent in a server database.

Exploit
  • EPSS 0.76%
  • Veröffentlicht 29.03.2007 21:19:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in the Active Content Filter feature in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to inject arbitrary web script or HTML via unspecified "code sequences" that bypass the pr...

Exploit
  • EPSS 15.2%
  • Veröffentlicht 28.03.2007 22:19:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Heap-based buffer overflow in the LDAP server in IBM Lotus Domino before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to cause a denial of service (crash) via a long, malformed DN request, which causes only the lower 16 bits of the string l...