Ibm

Lotus Notes

71 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 16.3%
  • Veröffentlicht 28.12.2007 21:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple stack-based buffer overflows in l123sr.dll in Autonomy (formerly Verity) KeyView SDK, as used by IBM Lotus Notes 5.x through 8.x, allow user-assisted remote attackers to execute arbitrary code via the (1) Length and (2) Value fields for cert...

  • EPSS 30.96%
  • Veröffentlicht 10.11.2007 02:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Stack-based buffer overflow in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, wp6sr.dll in IBM Lotus Notes 8.0 and before 7.0.3, Symantec Mail Security, and other products, allows...

  • EPSS 25.87%
  • Veröffentlicht 10.11.2007 02:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, IBM Lotus Notes before 7.0.3, Symantec Mail Security, and other products, allow remote atta...

  • EPSS 18.78%
  • Veröffentlicht 29.10.2007 22:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Buffer overflow in the TagAttributeListCopy function in nnotes.dll in IBM Lotus Notes before 7.0.3 allows user-assisted remote attackers to execute arbitrary code via a crafted HTML email, related to duplicate RTF conversion when the recipient operat...

  • EPSS 0.09%
  • Veröffentlicht 29.10.2007 21:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

IBM Lotus Notes before 6.5.6, and 7.x before 7.0.3; and Domino before 6.5.5 FP3, and 7.x before 7.0.2 FP1; uses weak permissions (Everyone:Full Control) for memory mapped files (shared memory) in IPC, which allows local users to obtain sensitive info...

  • EPSS 0.2%
  • Veröffentlicht 13.08.2007 21:17:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

IBM Lotus Notes 5.x through 7.0.2 allows user-assisted remote authenticated administrators to obtain a cleartext notes.id password by setting the notes.ini (1) KFM_ShowEntropy and (2) Debug_Outfile debug variables, a different vulnerability than CVE-...

  • EPSS 0.29%
  • Veröffentlicht 11.04.2007 01:19:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in the Active Content Filter feature in Domino Web Access (DWA) in IBM Lotus Notes before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to inject arbitrary web script or HTML via a multipart/related e...

Exploit
  • EPSS 2.02%
  • Veröffentlicht 10.11.2006 01:07:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The Notes Remote Procedure Call (NRPC) protocol in IBM Lotus Notes Domino before 6.5.5 FP2 and 7.x before 7.0.2 does not require authentication to perform user lookups, which allows remote attackers to obtain the user ID file.

Exploit
  • EPSS 0.51%
  • Veröffentlicht 24.07.2006 12:19:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

IBM Lotus Notes 6.0, 6.5, and 7.0 does not properly handle replies to e-mail messages with alternate name users when the (1) "Save As Draft" option is used or (2) a "," (comma) is inside the "phrase" portion of an address, which can cause the e-mail ...

  • EPSS 0.3%
  • Veröffentlicht 20.04.2006 22:02:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

The "Add Sender to Address Book" operation (AddSenderToAddressBook.lss) and NameHelper.lss in IBM Lotus Notes 6.0 and 6.5 before 20060331 do not properly store information in the Personal Address Book when multiple messages are checked and a message ...