Ibm

Lotus Notes

71 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 16.3%
  • Published 28.12.2007 21:46:00
  • Last modified 09.04.2025 00:30:58

Multiple stack-based buffer overflows in l123sr.dll in Autonomy (formerly Verity) KeyView SDK, as used by IBM Lotus Notes 5.x through 8.x, allow user-assisted remote attackers to execute arbitrary code via the (1) Length and (2) Value fields for cert...

  • EPSS 30.96%
  • Published 10.11.2007 02:46:00
  • Last modified 09.04.2025 00:30:58

Stack-based buffer overflow in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, wp6sr.dll in IBM Lotus Notes 8.0 and before 7.0.3, Symantec Mail Security, and other products, allows...

  • EPSS 25.87%
  • Published 10.11.2007 02:46:00
  • Last modified 09.04.2025 00:30:58

Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, IBM Lotus Notes before 7.0.3, Symantec Mail Security, and other products, allow remote atta...

  • EPSS 18.78%
  • Published 29.10.2007 22:46:00
  • Last modified 09.04.2025 00:30:58

Buffer overflow in the TagAttributeListCopy function in nnotes.dll in IBM Lotus Notes before 7.0.3 allows user-assisted remote attackers to execute arbitrary code via a crafted HTML email, related to duplicate RTF conversion when the recipient operat...

  • EPSS 0.09%
  • Published 29.10.2007 21:46:00
  • Last modified 09.04.2025 00:30:58

IBM Lotus Notes before 6.5.6, and 7.x before 7.0.3; and Domino before 6.5.5 FP3, and 7.x before 7.0.2 FP1; uses weak permissions (Everyone:Full Control) for memory mapped files (shared memory) in IPC, which allows local users to obtain sensitive info...

  • EPSS 0.2%
  • Published 13.08.2007 21:17:00
  • Last modified 09.04.2025 00:30:58

IBM Lotus Notes 5.x through 7.0.2 allows user-assisted remote authenticated administrators to obtain a cleartext notes.id password by setting the notes.ini (1) KFM_ShowEntropy and (2) Debug_Outfile debug variables, a different vulnerability than CVE-...

  • EPSS 0.29%
  • Published 11.04.2007 01:19:00
  • Last modified 09.04.2025 00:30:58

Cross-site scripting (XSS) vulnerability in the Active Content Filter feature in Domino Web Access (DWA) in IBM Lotus Notes before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to inject arbitrary web script or HTML via a multipart/related e...

Exploit
  • EPSS 2.02%
  • Published 10.11.2006 01:07:00
  • Last modified 09.04.2025 00:30:58

The Notes Remote Procedure Call (NRPC) protocol in IBM Lotus Notes Domino before 6.5.5 FP2 and 7.x before 7.0.2 does not require authentication to perform user lookups, which allows remote attackers to obtain the user ID file.

Exploit
  • EPSS 0.51%
  • Published 24.07.2006 12:19:00
  • Last modified 03.04.2025 01:03:51

IBM Lotus Notes 6.0, 6.5, and 7.0 does not properly handle replies to e-mail messages with alternate name users when the (1) "Save As Draft" option is used or (2) a "," (comma) is inside the "phrase" portion of an address, which can cause the e-mail ...

  • EPSS 0.3%
  • Published 20.04.2006 22:02:00
  • Last modified 03.04.2025 01:03:51

The "Add Sender to Address Book" operation (AddSenderToAddressBook.lss) and NameHelper.lss in IBM Lotus Notes 6.0 and 6.5 before 20060331 do not properly store information in the Personal Address Book when multiple messages are checked and a message ...