CVE-2003-0179
Estado: ModificadaAlta (7.5)—
Buffer overflow in the COM Object Control Handler for Lotus Domino 6.0.1 and earlier allows remote attackers to execute arbitrary code via multiple attack vectors, as demonstrated using the InitializeUsingNotesUserName method in the iNotes ActiveX control.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 7.74%
- Percentil entre todas las CVEs puntuadas: 94
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- NVD-CWE-Other
Referencias
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0082.html
- http://marc.info/?l=bugtraq&m=104550124032513&w=2
- http://marc.info/?l=bugtraq&m=104550335103136&w=2
- http://marc.info/?l=ntbugtraq&m=104558778131373&w=2
- http://marc.info/?l=ntbugtraq&m=104558778331387&w=2
- http://www-1.ibm.com/support/docview.wss?uid=swg21104543
- http://www.cert.org/advisories/CA-2003-11.html
- http://www.ciac.org/ciac/bulletins/n-065.shtml
- http://www.kb.cert.org/vuls/id/571297
- http://www.nextgenss.com/advisories/lotus-inotesclientaxbo.txt
- http://www.securityfocus.com/bid/6872
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11339
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0082.html
- http://marc.info/?l=bugtraq&m=104550124032513&w=2
- http://marc.info/?l=bugtraq&m=104550335103136&w=2
- http://marc.info/?l=ntbugtraq&m=104558778131373&w=2
- http://marc.info/?l=ntbugtraq&m=104558778331387&w=2
- http://www-1.ibm.com/support/docview.wss?uid=swg21104543
- http://www.cert.org/advisories/CA-2003-11.html
- http://www.ciac.org/ciac/bulletins/n-065.shtml
- http://www.kb.cert.org/vuls/id/571297
- http://www.nextgenss.com/advisories/lotus-inotesclientaxbo.txt
- http://www.securityfocus.com/bid/6872
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11339
JSON original (NVD)
Mostrar
{
"id": "CVE-2003-0179",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": true,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2003-04-02T05:00:00.000",
"references": [
{
"url": "http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0082.html",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=104550124032513&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=104550335103136&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=ntbugtraq&m=104558778131373&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=ntbugtraq&m=104558778331387&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://www-1.ibm.com/support/docview.wss?uid=swg21104543",
"source": "cve@mitre.org"
},
{
"url": "http://www.cert.org/advisories/CA-2003-11.html",
"tags": [
"US Government Resource"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.ciac.org/ciac/bulletins/n-065.shtml",
"source": "cve@mitre.org"
},
{
"url": "http://www.kb.cert.org/vuls/id/571297",
"tags": [
"Patch",
"Third Party Advisory",
"US Government Resource"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.nextgenss.com/advisories/lotus-inotesclientaxbo.txt",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/6872",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/11339",
"source": "cve@mitre.org"
},
{
"url": "http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0082.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=bugtraq&m=104550124032513&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=bugtraq&m=104550335103136&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=ntbugtraq&m=104558778131373&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=ntbugtraq&m=104558778331387&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www-1.ibm.com/support/docview.wss?uid=swg21104543",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.cert.org/advisories/CA-2003-11.html",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.ciac.org/ciac/bulletins/n-065.shtml",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/571297",
"tags": [
"Patch",
"Third Party Advisory",
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.nextgenss.com/advisories/lotus-inotesclientaxbo.txt",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/6872",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/11339",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Buffer overflow in the COM Object Control Handler for Lotus Domino 6.0.1 and earlier allows remote attackers to execute arbitrary code via multiple attack vectors, as demonstrated using the InitializeUsingNotesUserName method in the iNotes ActiveX control."
},
{
"lang": "es",
"value": "Desbordamiento de búfer en el manejador de control de objetos COM para Lotus Domino 6.0.1 y versiones anteriores, permite a atacantes remotos la ejecución de código arbitrario mediante vectores de ataque múltiple, como se demuestra utilizando el método InitializeUsingNotesUserName en el control ActiveX de iNotes."
}
],
"lastModified": "2026-06-16T22:01:42.513",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ibm:lotus_domino_web_server:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "33C637A6-CD7E-4E88-B994-5A5139EE91C1"
},
{
"criteria": "cpe:2.3:a:ibm:lotus_notes_client:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "65BA8CED-47B7-4F45-BFCD-0BB7968D3384"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}