Show filters
111 Total Results
Displaying 81-90 of 111
Sort by:
Attacker Value
Unknown
CVE-2005-2712
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
The LDAP server (nldap.exe) in IBM Lotus Domino before 7.0.1, 6.5.5, and 6.5.4 FP2 allows remote attackers to cause a denial of service (crash) via a long bind request, which triggers a null dereference.
0
Attacker Value
Unknown
CVE-2005-4819
Disclosure Date: December 31, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Lotus Domino versions before 6.5.4 fix pack 1 (FP1) and versions before 7.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
0
Attacker Value
Unknown
CVE-2005-3015
Disclosure Date: September 21, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 6.5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) BaseTarget or (2) Src parameters.
0
Attacker Value
Unknown
CVE-2005-2428
Disclosure Date: August 03, 2005 (last updated February 22, 2025)
Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the HTTPPasswordChangeDate field, (3) the client platform in the ClntPltfrm field, (4) the client machine name in the ClntMachine field, and (5) the client Lotus Domino release in the ClntBld field, a different vulnerability than CVE-2005-2696.
0
Attacker Value
Unknown
CVE-2005-1441
Disclosure Date: May 03, 2005 (last updated February 22, 2025)
Format string vulnerability in Lotus Domino 6.0.x before 6.0.5 and 6.5.x before 6.5.4 allows remote attackers to cause a denial of service via the Notes protocol (NRPC).
0
Attacker Value
Unknown
CVE-2005-1101
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Multiple buffer overflows in Lotus Domino Server 6.0.5 and 6.5.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via large amounts of data in certain (1) time or (2) date fields.
0
Attacker Value
Unknown
CVE-2005-0986
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
NLSCCSTR.DLL in the web service in IBM Lotus Domino Server 6.5.1, 6.0.3, and possibly other versions allows remote attackers to cause a denial of service (deep recursion and nHTTP.exe process crash) via a long GET request containing UNICODE decimal value 430 characters, which causes the stack to be exhausted. NOTE: IBM has reported that it is unable to replicate this issue.
0
Attacker Value
Unknown
CVE-2004-2311
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Directory traversal vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows local users to create folders or determine the existence of files via a .. (dot dot) in the new folder dialog.
0
Attacker Value
Unknown
CVE-2004-2369
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Directory traversal vulnerability in webadmin.nsf for Lotus Domino R6 6.5.1 allows attackers to create and detect directories via a .. (dot dot) in the directory creation command.
0
Attacker Value
Unknown
CVE-2004-2310
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows remote attackers to inject arbitrary web script or HTML via a Domino command in the Quick Console.
0