Show filters
111 Total Results
Displaying 51-60 of 111
Sort by:
Attacker Value
Unknown
CVE-2008-7253
Disclosure Date: January 25, 2010 (last updated October 04, 2023)
The default configuration of the web server in IBM Lotus Domino Server, possibly 6.0 through 8.0, enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authentication credentials via a cross-site tracing (XST) attack, a related issue to CVE-2004-2763 and CVE-2005-3398.
0
Attacker Value
Unknown
CVE-2010-0358
Disclosure Date: January 20, 2010 (last updated October 04, 2023)
Heap-based buffer overflow in the server in IBM Lotus Domino 7 and 8.5 FP1 allows remote attackers to cause a denial of service (daemon exit) and possibly have unspecified other impact via a long string in a crafted LDAP message to a TCP port, a different vulnerability than CVE-2009-3087.
0
Attacker Value
Unknown
CVE-2010-0276
Disclosure Date: January 09, 2010 (last updated October 04, 2023)
IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 does not properly handle navigation of the "Try Lotus iNotes anyway" link from the page that reports use of an unsupported browser, which has unspecified impact and attack vectors, aka SPR LSHR7TBMQU.
0
Attacker Value
Unknown
CVE-2009-3087
Disclosure Date: September 08, 2009 (last updated October 04, 2023)
Unspecified vulnerability in nserver.exe in the server in IBM Lotus Domino 8.0 on Windows Server 2003 allows remote attackers to cause a denial of service (daemon crash) via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.11. NOTE: as of 20090903, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
0
Attacker Value
Unknown
CVE-2009-1286
Disclosure Date: April 13, 2009 (last updated October 04, 2023)
The IMAP task in the server in IBM Lotus Domino 8.0.2 before FP1 IF1 and 8.5 before IF3 allows remote attackers to cause a denial of service (daemon crash) via a MIME e-mail message with RFC822 attachments (aka blobs) containing malformed root entities.
0
Attacker Value
Unknown
CVE-2008-2410
Disclosure Date: May 22, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the servlet engine and Web container in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-2240
Disclosure Date: May 22, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in the Web Server service in IBM Lotus Domino before 7.0.3 FP1, and 8.x before 8.0.1, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long Accept-Language HTTP header.
0
Attacker Value
Unknown
CVE-2008-0243
Disclosure Date: January 12, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Lotus Domino 7.0.2 before Fix Pack 3 allows attackers to cause a denial of service via unknown vectors.
0
Attacker Value
Unknown
CVE-2007-4474
Disclosure Date: December 27, 2007 (last updated October 04, 2023)
Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, inotes6w.dll, dwa7.dll, and dwa7w.dll, in Domino 6.x and 7.x allow remote attackers to execute arbitrary code, as demonstrated by an overflow from a long General_ServerName property value when calling the InstallBrowserHelperDll function in the Upload Module in the dwa7.dwa7.1 control in dwa7w.dll 7.0.34.1.
0
Attacker Value
Unknown
CVE-2007-5924
Disclosure Date: November 10, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Web Server (HTTP) task in IBM Lotus Domino before 6.5.6 FP2, and 7.x before 7.0.2 FP2, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
0