Show filters
111 Total Results
Displaying 81-90 of 111
Sort by:
Attacker Value
Unknown

CVE-2005-2712

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
The LDAP server (nldap.exe) in IBM Lotus Domino before 7.0.1, 6.5.5, and 6.5.4 FP2 allows remote attackers to cause a denial of service (crash) via a long bind request, which triggers a null dereference.
0
Attacker Value
Unknown

CVE-2005-4819

Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Lotus Domino versions before 6.5.4 fix pack 1 (FP1) and versions before 7.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
0
Attacker Value
Unknown

CVE-2005-3015

Disclosure Date: September 21, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 6.5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) BaseTarget or (2) Src parameters.
0
Attacker Value
Unknown

CVE-2005-2428

Disclosure Date: August 03, 2005 (last updated February 22, 2025)
Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the HTTPPasswordChangeDate field, (3) the client platform in the ClntPltfrm field, (4) the client machine name in the ClntMachine field, and (5) the client Lotus Domino release in the ClntBld field, a different vulnerability than CVE-2005-2696.
0
Attacker Value
Unknown

CVE-2005-1441

Disclosure Date: May 03, 2005 (last updated February 22, 2025)
Format string vulnerability in Lotus Domino 6.0.x before 6.0.5 and 6.5.x before 6.5.4 allows remote attackers to cause a denial of service via the Notes protocol (NRPC).
0
Attacker Value
Unknown

CVE-2005-1101

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Multiple buffer overflows in Lotus Domino Server 6.0.5 and 6.5.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via large amounts of data in certain (1) time or (2) date fields.
0
Attacker Value
Unknown

CVE-2005-0986

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
NLSCCSTR.DLL in the web service in IBM Lotus Domino Server 6.5.1, 6.0.3, and possibly other versions allows remote attackers to cause a denial of service (deep recursion and nHTTP.exe process crash) via a long GET request containing UNICODE decimal value 430 characters, which causes the stack to be exhausted. NOTE: IBM has reported that it is unable to replicate this issue.
0
Attacker Value
Unknown

CVE-2004-2311

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Directory traversal vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows local users to create folders or determine the existence of files via a .. (dot dot) in the new folder dialog.
0
Attacker Value
Unknown

CVE-2004-2369

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Directory traversal vulnerability in webadmin.nsf for Lotus Domino R6 6.5.1 allows attackers to create and detect directories via a .. (dot dot) in the directory creation command.
0
Attacker Value
Unknown

CVE-2004-2310

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows remote attackers to inject arbitrary web script or HTML via a Domino command in the Quick Console.
0