Lotus Notes
IBM · 71 CVEs
The Notes Client Single Logon feature in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3, and 9.0 on Windows allo…
Jul 16, 2018
JDK: Privilege escalation issue
Aug 12, 2014
IBM Notes and Domino 8.5.x before 8.5.3 FP6 IF3 and 9.x before 9.0.1 FP1 on 32-bit Linux platforms use incorrect gcc op…
Apr 23, 2014
Buffer overflow in the .mdb parser in Autonomy KeyView IDOL, as used in IBM Notes 8.5.x before 8.5.3 FP4, allows remote…
Jul 18, 2013
ntmulti.exe in the Multi User Profile Cleanup service in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3 before F…
Jun 21, 2013
Integer overflow in IBM Notes 8.5.x before 8.5.3 FP4 Interim Fix 1 and 9.x before 9.0 Interim Fix 1 on Windows, and 8.5…
May 10, 2013
Cross-site scripting (XSS) vulnerability in IBM Lotus Notes 8.x before 8.5.3 FP4 Interim Fix 1 and 9.0 before Interim F…
May 1, 2013
IBM Lotus Notes 8.x before 8.5.3 FP4 Interim Fix 1 and 9.0 before Interim Fix 1 does not block APPLET elements in HTML…
May 1, 2013
JDK: java.lang.ClassLoder defineClass() code execution
Jan 11, 2013
JDK: java.lang.class code execution
Jan 11, 2013
JDK: getDeclaredMethods() and setAccessible() code execution
Jan 11, 2013
JDK: java.lang.reflect.Method invoke() code execution
Jan 11, 2013
IBM Lotus Notes 8.5.x before 8.5.3 FP3 does not include the HTTPOnly flag in a Set-Cookie header for a web-application…
Dec 19, 2012
Multiple untrusted search path vulnerabilities in IBM Lotus Notes 8.5 allow local users to gain privileges via a Trojan…
Sep 7, 2012
The URL handler in IBM Lotus Notes 8.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a crafted…
Jun 20, 2012
Heap-based buffer overflow in xlssr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote…
May 31, 2011
Buffer overflow in kvarcve.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attacker…
May 31, 2011
Buffer overflow in kpprzrdr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attacke…
May 31, 2011
Stack-based buffer overflow in assr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote…
May 31, 2011
Stack-based buffer overflow in mw8sr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remot…
May 31, 2011
Stack-based buffer overflow in rtfsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remot…
May 31, 2011
Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attacker…
May 31, 2011
Argument injection vulnerability in IBM Lotus Notes 8.0.x before 8.0.2 FP6 and 8.5.x before 8.5.1 FP5 allows remote att…
Feb 8, 2011
Stack-based buffer overflow in IBM Lotus Notes 8.5 and 8.5fp1, and possibly other versions, allows remote attackers to…
Apr 29, 2010
IBM Lotus Notes 7.0, 8.0, and 8.5 stores administrative credentials in cleartext in SURunAs.exe, which allows local use…
Apr 20, 2010
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2013-0522 | The Notes Client Single Logon feature in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3, and 9.0 on Windows allows local users to discover passwords via… | HIGH | 0.27% | Jul 16, 2018 |
| CVE-2014-3086 | JDK: Privilege escalation issue | HIGH | 5.05% | Aug 12, 2014 |
| CVE-2014-0892 | IBM Notes and Domino 8.5.x before 8.5.3 FP6 IF3 and 9.x before 9.0.1 FP1 on 32-bit Linux platforms use incorrect gcc options, which makes it easier for remote… | MEDIUM | 4.22% | Apr 23, 2014 |
| CVE-2012-6349 | Buffer overflow in the .mdb parser in Autonomy KeyView IDOL, as used in IBM Notes 8.5.x before 8.5.3 FP4, allows remote attackers to execute arbitrary code via… | HIGH | 3.19% | Jul 18, 2013 |
| CVE-2013-0536 | ntmulti.exe in the Multi User Profile Cleanup service in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3 before FP5, and 9.0 before IF2 allows local user… | HIGH | 0.37% | Jun 21, 2013 |
| CVE-2013-2977 | Integer overflow in IBM Notes 8.5.x before 8.5.3 FP4 Interim Fix 1 and 9.x before 9.0 Interim Fix 1 on Windows, and 8.5.x before 8.5.3 FP5 and 9.x before 9.0.1… | MEDIUM | 4.69% | May 10, 2013 |
| CVE-2013-0538 | Cross-site scripting (XSS) vulnerability in IBM Lotus Notes 8.x before 8.5.3 FP4 Interim Fix 1 and 9.0 before Interim Fix 1 allows remote attackers to inject a… | MEDIUM | 2.12% | May 1, 2013 |
| CVE-2013-0127 | IBM Lotus Notes 8.x before 8.5.3 FP4 Interim Fix 1 and 9.0 before Interim Fix 1 does not block APPLET elements in HTML e-mail, which allows remote attackers to… | MEDIUM | 3.79% | May 1, 2013 |
| CVE-2012-4823 | JDK: java.lang.ClassLoder defineClass() code execution | HIGH | 6.86% | Jan 11, 2013 |
| CVE-2012-4822 | JDK: java.lang.class code execution | HIGH | 6.90% | Jan 11, 2013 |
| CVE-2012-4821 | JDK: getDeclaredMethods() and setAccessible() code execution | HIGH | 6.90% | Jan 11, 2013 |
| CVE-2012-4820 | JDK: java.lang.reflect.Method invoke() code execution | HIGH | 5.09% | Jan 11, 2013 |
| CVE-2012-4846 | IBM Lotus Notes 8.5.x before 8.5.3 FP3 does not include the HTTPOnly flag in a Set-Cookie header for a web-application cookie, which makes it easier for remote… | MEDIUM | 1.19% | Dec 19, 2012 |
| CVE-2010-5251 | Multiple untrusted search path vulnerabilities in IBM Lotus Notes 8.5 allow local users to gain privileges via a Trojan horse (1) nnoteswc.dll or (2) nlsxbe.dl… | MEDIUM | 0.42% | Sep 7, 2012 |
| CVE-2012-2174 | The URL handler in IBM Lotus Notes 8.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a crafted notes:// URL. | HIGH | 38.29% | Jun 20, 2012 |
| CVE-2011-1512 | Heap-based buffer overflow in xlssr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via… | HIGH | 6.87% | May 31, 2011 |
| CVE-2011-1218 | Buffer overflow in kvarcve.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafte… | HIGH | 5.09% | May 31, 2011 |
| CVE-2011-1217 | Buffer overflow in kpprzrdr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a craft… | HIGH | 5.09% | May 31, 2011 |
| CVE-2011-1216 | Stack-based buffer overflow in assr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via… | HIGH | 5.54% | May 31, 2011 |
| CVE-2011-1215 | Stack-based buffer overflow in mw8sr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code vi… | HIGH | 5.54% | May 31, 2011 |
| CVE-2011-1214 | Stack-based buffer overflow in rtfsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code vi… | HIGH | 5.54% | May 31, 2011 |
| CVE-2011-1213 | Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafte… | HIGH | 32.96% | May 31, 2011 |
| CVE-2011-0912 | Argument injection vulnerability in IBM Lotus Notes 8.0.x before 8.0.2 FP6 and 8.5.x before 8.5.1 FP5 allows remote attackers to execute arbitrary code via a c… | HIGH | 3.54% | Feb 8, 2011 |
| CVE-2010-1608 | Stack-based buffer overflow in IBM Lotus Notes 8.5 and 8.5fp1, and possibly other versions, allows remote attackers to execute arbitrary code via unknown attac… | HIGH | 5.81% | Apr 29, 2010 |
| CVE-2010-1487 | IBM Lotus Notes 7.0, 8.0, and 8.5 stores administrative credentials in cleartext in SURunAs.exe, which allows local users to obtain sensitive information by ex… | LOW | 0.35% | Apr 20, 2010 |
Showing 1 to 25 of 71 CVEs