Show filters
111 Total Results
Displaying 91-100 of 111
Sort by:
Attacker Value
Unknown

CVE-2004-1621

Disclosure Date: October 18, 2004 (last updated February 22, 2025)
NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Domino R6, and possibly earlier versions, allows remote attackers to execute arbitrary web script or HTML via square brackets at the beginning and end of (1) computed for display, (2) computed when composed, or (3) computed text element fields. NOTE: the vendor has disputed this issue, saying that it is not a problem with Notes/Domino itself, but with the applications that do not properly handle this feature
0
Attacker Value
Unknown

CVE-2004-0669

Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Lotus Domino 6.5.0 and 6.5.1, with IMAP enabled, allows remote authenticated users to change their quota by using the IMAP setquota command.
0
Attacker Value
Unknown

CVE-2004-0029

Disclosure Date: January 20, 2004 (last updated February 22, 2025)
Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges.
0
Attacker Value
Unknown

CVE-2003-0180

Disclosure Date: April 02, 2003 (last updated February 22, 2025)
Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via an incomplete POST request, as demonstrated using the h_PageUI form.
0
Attacker Value
Unknown

CVE-2003-0178

Disclosure Date: April 02, 2003 (last updated February 22, 2025)
Multiple buffer overflows in Lotus Domino Web Server before 6.0.1 allow remote attackers to cause a denial of service or execute arbitrary code via (1) the s_ViewName option in the PresetFields parameter for iNotes, (2) the Foldername option in the PresetFields parameter for iNotes, or (3) a long Host header, which is inserted into a long Location header and used during a redirect operation.
0
Attacker Value
Unknown

CVE-2003-0181

Disclosure Date: April 02, 2003 (last updated February 22, 2025)
Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via a "Fictionary Value Field POST request" as demonstrated using the s_Validation form with a long, unknown parameter name.
0
Attacker Value
Unknown

CVE-2003-0179

Disclosure Date: April 02, 2003 (last updated February 22, 2025)
Buffer overflow in the COM Object Control Handler for Lotus Domino 6.0.1 and earlier allows remote attackers to execute arbitrary code via multiple attack vectors, as demonstrated using the InitializeUsingNotesUserName method in the iNotes ActiveX control.
0
Attacker Value
Unknown

CVE-2003-0122

Disclosure Date: March 18, 2003 (last updated February 22, 2025)
Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote attackers to execute arbitrary code via a long distinguished name (DN) during NotesRPC authentication and an outer field length that is less than that of the DN field.
0
Attacker Value
Unknown

CVE-2003-0123

Disclosure Date: March 18, 2003 (last updated February 22, 2025)
Buffer overflow in Web Retriever client for Lotus Notes/Domino R4.5 through R6 allows remote malicious web servers to cause a denial of service (crash) via a long HTTP status line.
0
Attacker Value
Unknown

CVE-2002-1624

Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Buffer overflow in Lotus Domino web server before R5.0.10, when logging to DOMLOG.NSF, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP Authenticate header containing certain non-ASCII characters.
0