Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
326 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 7.9% | — | Autonomy Keyview Export SDKAutonomy Keyview Filter SDKAutonomy Keyview Viewer SDKIBM Lotus Notes | 31/12/2005 | 16/6/2026 | Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allow remote attackers to execute arbitrary code via (1) a UUE file containing an encoded file with a long filename handled by uudrdr.dll, (2) a compressed ZIP file with a long filename… | |
| Modificada | Media (4.3) | 2.5% | — | IBM Lotus DominoIBM Lotus Domino Enterprise Server | 21/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 6.5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) BaseTarget or (2) Src parameters. | |
| Modificada | Media (5) | 2.2% | — | IBM Lotus Notes | 26/8/2005 | 16/6/2026 | IBM Lotus Notes does not properly restrict access to password hashes in the Notes Address Book (NAB), which allows remote attackers to obtain sensitive information via the (1) password digest field in the Administration tab of a Lotus Notes client, (2) "PasswordDigest" and "HTTPPassword" fields in the document… | |
| Modificada | Media (5) | 73% | 💥 Exploit | IBM Lotus Domino | 3/8/2005 | 16/6/2026 | Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the… | |
| Modificada | Media (5) | 5.2% | 💥 Exploit | IBM Lotus Notes | 9/7/2005 | 16/6/2026 | The web interface for Lotus Notes mail automatically processes HTML in an attachment without prompting the user to save or open it, which makes it easier for remote attackers to conduct web-based attacks and steal cookies. | |
| Modificada | Baja (2.1) | 0.36% | — | IBM Lotus Notes | 3/5/2005 | 16/6/2026 | HTTP response splitting vulnerability in the @SetHTTPHeader function in Lotus Domino 6.5.x before 6.5.4 and 6.0.x before 6.0.5 allows attackers to poison the web cache via malicious applications. | |
| Modificada | Media (5) | 1.8% | — | IBM Lotus Domino | 3/5/2005 | 16/6/2026 | Format string vulnerability in Lotus Domino 6.0.x before 6.0.5 and 6.5.x before 6.5.4 allows remote attackers to cause a denial of service via the Notes protocol (NRPC). | |
| Modificada | Media (4.6) | 0.44% | — | IBM Lotus Notes | 3/5/2005 | 16/6/2026 | Buffer overflow in the Lotus Notes client for Domino 6.5 before 6.5.4 and 6.0 before 6.0.5 allows local users to cause a denial of service (client crash) and possibly execute arbitrary code via the NOTES.INI file. | |
| Modificada | Media (5) | 7.0% | 💥 Exploit | IBM Lotus Domino Server | 2/5/2005 | 16/6/2026 | NLSCCSTR.DLL in the web service in IBM Lotus Domino Server 6.5.1, 6.0.3, and possibly other versions allows remote attackers to cause a denial of service (deep recursion and nHTTP.exe process crash) via a long GET request containing UNICODE decimal value 430 characters, which causes the stack to be exhausted. NOTE:… | |
| Modificada | Alta (7.5) | 3.5% | — | IBM Lotus Domino Server | 2/5/2005 | 16/6/2026 | Multiple buffer overflows in Lotus Domino Server 6.0.5 and 6.5.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via large amounts of data in certain (1) time or (2) date fields. | |
| Modificada | Media (5) | 8.7% | 💥 Exploit | IBM Lotus Notes | 31/12/2004 | 16/6/2026 | Buffer overflow in IBM Lotus Notes 6.5.x before 6.5.3 and 6.0.x before 6.0.5 allows remote attackers to cause a denial of service (crash) via unknown vectors related to Java applets, as identified by KSPR62F4KN. | |
| Modificada | Alta (10) | 2.2% | — | IBM Lotus Notes | 31/12/2004 | 16/6/2026 | Multiple unknown vulnerabilities in IBM Lotus Notes 6.5.x before 6.5.4 and 6.0.x before 6.0.5 have unknown impact and attack vectors, related to Java applets, as identified by (1) KSPR5YS6GR and (2) KSPR62F4D3. | |
| Modificada | Baja (3.6) | 1.1% | 💥 Exploit | IBM Lotus Domino | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows local users to create folders or determine the existence of files via a .. (dot dot) in the new folder dialog. | |
| Modificada | Media (6.4) | 1.6% | — | IBM Lotus Domino | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in webadmin.nsf for Lotus Domino R6 6.5.1 allows attackers to create and detect directories via a .. (dot dot) in the directory creation command. | |
| Modificada | Media (6.8) | 1.2% | — | Lotus DominoAI | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Lotus Domino 6.0.x before 6.0.4 and 6.5.x before 6.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | IBM Lotus Domino | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows remote attackers to inject arbitrary web script or HTML via a Domino command in the Quick Console. | |
| Modificada | Alta (10) | 8.6% | — | IBM Lotus Notes | 6/12/2004 | 16/6/2026 | Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute arbitrary code via a notes: URI that uses a UNC network share pathname to provide an alternate notes.ini configuration file to notes.exe. | |
| Modificada | Media (4.3) | 3.1% | 💥 Exploit | IBM Lotus Domino | 18/10/2004 | 16/6/2026 | NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Domino R6, and possibly earlier versions, allows remote attackers to execute arbitrary web script or HTML via square brackets at the beginning and end of (1) computed for display, (2) computed when… | |
| Modificada | Alta (7.5) | 1.5% | — | IBM Lotus Domino | 6/8/2004 | 16/6/2026 | Lotus Domino 6.5.0 and 6.5.1, with IMAP enabled, allows remote authenticated users to change their quota by using the IMAP setquota command. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Lotus DominoAI | 6/8/2004 | 16/6/2026 | Web Access in Lotus Domino 6.5.1 allows remote attackers to cause a denial of service (server crash) via a large e-mail message, as demonstrated using a large image attachment. | |
| Modificada | Media (4.6) | 0.36% | — | IBM Lotus Domino | 20/1/2004 | 16/6/2026 | Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges. | |
| Modificada | Media (5) | 1.3% | — | Lotus Domino Server | 31/12/2003 | 16/6/2026 | Lotus Domino Server 5.0 and 6.0 allows remote attackers to read the source code for files via an HTTP request with a filename with a trailing dot. | |
| Modificada | Alta (10) | 15% | — | IBM Lotus Domino WEB Server | 2/4/2003 | 16/6/2026 | Multiple buffer overflows in Lotus Domino Web Server before 6.0.1 allow remote attackers to cause a denial of service or execute arbitrary code via (1) the s_ViewName option in the PresetFields parameter for iNotes, (2) the Foldername option in the PresetFields parameter for iNotes, or (3) a long Host header, which is… | |
| Modificada | Media (5) | 3.0% | — | IBM Lotus Domino WEB Server | 2/4/2003 | 16/6/2026 | Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via an incomplete POST request, as demonstrated using the h_PageUI form. | |
| Modificada | Media (5) | 2.5% | — | IBM Lotus Domino WEB Server | 2/4/2003 | 16/6/2026 | Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via a "Fictionary Value Field POST request" as demonstrated using the s_Validation form with a long, unknown parameter name. |