Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
367 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 5.1% | — | Autonomy KeyviewIBM Lotus Notes | 31/5/2011 | 16/6/2026 | Buffer overflow in kvarcve.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted .zip attachment, aka SPR PRAD8E3NSP. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 5.1% | — | IBM Lotus Notes | 31/5/2011 | 16/6/2026 | Buffer overflow in kpprzrdr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted .prz attachment. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 5.5% | — | IBM Lotus Notes | 31/5/2011 | 16/6/2026 | Stack-based buffer overflow in assr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via crafted tag data in an Applix spreadsheet attachment, aka SPR PRAD8823A7. | |
| Modificada | Alta (9.3) | 5.5% | — | IBM Lotus Notes | 31/5/2011 | 16/6/2026 | Stack-based buffer overflow in mw8sr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted link in a Microsoft Office document attachment, aka SPR PRAD8823ND. | |
| Modificada | Alta (9.3) | 5.5% | — | IBM Lotus Notes | 31/5/2011 | 16/6/2026 | Stack-based buffer overflow in rtfsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted link in a .rtf attachment, aka SPR PRAD8823JQ. | |
| Modificada | Alta (9.3) | 33% | 💥 Exploit | IBM Lotus Notes | 31/5/2011 | 16/6/2026 | Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted header in a .lzh attachment that triggers a stack-based buffer overflow, aka SPR PRAD88MJ2W. | |
| Modificada | Alta (9.3) | 3.5% | — | IBM Lotus Notes | 8/2/2011 | 16/6/2026 | Argument injection vulnerability in IBM Lotus Notes 8.0.x before 8.0.2 FP6 and 8.5.x before 8.5.1 FP5 allows remote attackers to execute arbitrary code via a cai:// URL containing a --launcher.library option that specifies a UNC share pathname for a DLL file, aka SPR PRAD82YJW2. | |
| Modificada | Media (5) | 1.4% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | An unspecified Domino API in IBM Lotus Notes Traveler before 8.5.1.1 does not properly handle MIME types, which allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors. | |
| Modificada | Media (5) | 2.2% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | Memory leak in IBM Lotus Notes Traveler before 8.5.1.1 allows remote attackers to cause a denial of service (memory consumption and daemon outage) by sending many embedded objects in e-mail messages for iPhone clients. | |
| Modificada | Media (4) | 1.7% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | IBM Lotus Notes Traveler before 8.5.1.2 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by omitting the Internet ID field in the person document, and then using an Apple device to (1) accept or (2) decline an invitation. | |
| Modificada | Media (5) | 1.4% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | IBM Lotus Notes Traveler before 8.5.1.3 allows remote attackers to cause a denial of service (sync failure) via a malformed document. | |
| Modificada | Media (4) | 1.2% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | IBM Lotus Notes Traveler before 8.5.1.3 on the Nokia s60 device successfully performs a Replace Data operation for a prohibited application, which allows remote authenticated users to bypass intended access restrictions via this operation. | |
| Modificada | Baja (2.1) | 1.5% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | IBM Lotus Notes Traveler before 8.5.1.2 allows remote authenticated users to cause a denial of service (daemon crash) by accepting a meeting invitation with an iNotes client and then accepting this meeting invitation with an iPhone client. | |
| Modificada | Baja (3.5) | 0.90% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | IBM Lotus Notes Traveler before 8.5.1.3, when a multidomain environment is used, does not properly apply policy documents to mobile users from a different Domino domain than the Traveler server, which allows remote authenticated users to bypass intended access restrictions by using credentials from a different domain. | |
| Modificada | Media (4) | 1.2% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | IBM Lotus Notes Traveler before 8.5.1.2 does not reject an attachment download request for an e-mail message with a Prevent Copy attribute, which allows remote authenticated users to bypass intended access restrictions via this request. | |
| Modificada | Media (4) | 1.1% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | IBM Lotus Notes Traveler before 8.5.1.2 allows remote authenticated users to cause a denial of service (resource consumption and sync outage) by syncing a large volume of data. | |
| Modificada | Media (4.3) | 1.1% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the servlet in IBM Lotus Notes Traveler before 8.5.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4) | 1.1% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | traveler.exe in IBM Lotus Notes Traveler before 8.0.1.3 CF1 allows remote authenticated users to cause a denial of service (daemon crash) via a malformed invitation document in a sync operation. | |
| Modificada | Media (4.3) | 0.97% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | The Nokia client in IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle multiple outgoing e-mail messages between sync operations, which might allow remote attackers to read communications intended for other recipients by examining appended messages. | |
| Modificada | Media (4) | 1.1% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | IBM Lotus Notes Traveler before 8.5.0.2 allows remote authenticated users to cause a denial of service (memory consumption and daemon crash) by syncing a large volume of data, related to the launch of a new process to handle the data while the previous process is still operating on the data. | |
| Modificada | Media (4) | 0.99% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle a "* *" argument sequence for a certain tell command, which allows remote authenticated users to obtain access to other users' data via a sync operation, related to storage of the data of multiple users within the same thread. | |
| Modificada | Media (5.8) | 1.1% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | The encrypted e-mail feature in IBM Lotus Notes Traveler before 8.5.0.2 sends unencrypted messages when the feature is used without uploading a Notes ID file, which makes it easier for remote attackers to obtain sensitive information by sniffing the network. | |
| Modificada | Alta (10) | 5.8% | — | IBM Lotus Notes | 29/4/2010 | 16/6/2026 | Stack-based buffer overflow in IBM Lotus Notes 8.5 and 8.5fp1, and possibly other versions, allows remote attackers to execute arbitrary code via unknown attack vectors, as demonstrated by the vd_ln module in VulnDisco 9.0. NOTE: as of 20100222, this disclosure has no actionable information. However, because the… | |
| Modificada | Baja (2.1) | 0.35% | — | IBM Lotus Notes | 20/4/2010 | 16/6/2026 | IBM Lotus Notes 7.0, 8.0, and 8.5 stores administrative credentials in cleartext in SURunAs.exe, which allows local users to obtain sensitive information by examining this file, aka SPR JSTN837SEG. | |
| Modificada | Alta (10) | 3.7% | — | IBM Lotus NotesSymantec Brightmail GatewaySymantec Data Loss Prevention Detection ServersSymantec Data Loss Prevention Endpoint Agents+2 | 5/3/2010 | 16/6/2026 | Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security for Microsoft Exchange 5.0.10 through 5.0.13, and other products, allows context-dependent attackers to execute arbitrary code via a crafted OLE document that triggers a… |