Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
367 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.9) | 0.34% | — | IBM Lotus Notes | 28/12/2007 | 16/6/2026 | IBM Lotus Notes 8 for Linux before 8.0.1 uses (1) unspecified weak permissions for the installation kit obtained through a Notes 8 download and (2) 0777 permissions for the installdata file that is created by setup.sh, which allows local users to gain privileges via a Trojan horse file. | |
| Modificada | Alta (9.3) | 21% | — | Activepdf DocconverterAutonomy Keyview Export SDKAutonomy Keyview Filter SDKAutonomy Keyview Viewer SDK+2 | 10/11/2007 | 16/6/2026 | Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, IBM Lotus Notes before 7.0.3, Symantec Mail Security, and other products, allow remote attackers to execute arbitrary code via a crafted (1) AG file to… | |
| Modificada | Alta (9.3) | 6.6% | — | Activepdf DocconverterAutonomy Keyview Export SDKAutonomy Keyview Filter SDKAutonomy Keyview Viewer SDK+2 | 10/11/2007 | 16/6/2026 | Stack-based buffer overflow in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, wp6sr.dll in IBM Lotus Notes 8.0 and before 7.0.3, Symantec Mail Security, and other products, allows remote attackers to execute arbitrary code via a crafted WordPerfect… | |
| Modificada | Alta (9.3) | 4.1% | — | IBM Lotus Notes | 29/10/2007 | 16/6/2026 | Buffer overflow in the TagAttributeListCopy function in nnotes.dll in IBM Lotus Notes before 7.0.3 allows user-assisted remote attackers to execute arbitrary code via a crafted HTML email, related to duplicate RTF conversion when the recipient operates on this email. | |
| Modificada | Alta (7.8) | 0.27% | — | IBM Lotus DominoIBM Lotus Notes | 29/10/2007 | 16/6/2026 | IBM Lotus Notes before 6.5.6, and 7.x before 7.0.3; and Domino before 6.5.5 FP3, and 7.x before 7.0.2 FP1; uses weak permissions (Everyone:Full Control) for memory mapped files (shared memory) in IPC, which allows local users to obtain sensitive information, or inject Lotus Script or other character sequences into a… | |
| Modificada | Baja (3.5) | 0.85% | — | IBM Lotus Notes | 13/8/2007 | 16/6/2026 | IBM Lotus Notes 5.x through 7.0.2 allows user-assisted remote authenticated administrators to obtain a cleartext notes.id password by setting the notes.ini (1) KFM_ShowEntropy and (2) Debug_Outfile debug variables, a different vulnerability than CVE-2005-2696. | |
| Modificada | Media (4.3) | 1.1% | — | IBM Lotus Notes | 11/4/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Active Content Filter feature in Domino Web Access (DWA) in IBM Lotus Notes before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to inject arbitrary web script or HTML via a multipart/related e-mail message, a different issue than CVE-2006-4843. | |
| Modificada | Alta (10) | 4.2% | 💥 Exploit | Lbstone Active PHP Bookmark Notes | 23/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in templates/head.php in Active PHP Bookmark Notes (APB) 0.2.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the APB_SETTINGS[template_path] parameter. NOTE: this issue might be related to CVE-2003-1254. | |
| Modificada | Media (5) | 13% | — | IBM Lotus Notes | 10/11/2006 | 16/6/2026 | The Notes Remote Procedure Call (NRPC) protocol in IBM Lotus Notes Domino before 6.5.5 FP2 and 7.x before 7.0.2 does not require authentication to perform user lookups, which allows remote attackers to obtain the user ID file. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Evandor Easy Notesmanager | 3/11/2006 | 16/6/2026 | SQL injection vulnerability in easy notesManager (eNM) 0.0.1 allows remote attackers to execute arbitrary SQL commands via (1) the username parameter in login.php and (2) a search on the "search page." | |
| Modificada | Media (5) | 1.5% | — | IBM Lotus Notes | 24/7/2006 | 16/6/2026 | IBM Lotus Notes 6.0, 6.5, and 7.0 does not properly handle replies to e-mail messages with alternate name users when the (1) "Save As Draft" option is used or (2) a "," (comma) is inside the "phrase" portion of an address, which can cause the e-mail to be sent to users that were deleted from the To, CC, and BCC… | |
| Modificada | Media (4) | 0.98% | — | IBM Lotus Notes | 20/4/2006 | 16/6/2026 | The "Add Sender to Address Book" operation (AddSenderToAddressBook.lss) and NameHelper.lss in IBM Lotus Notes 6.0 and 6.5 before 20060331 do not properly store information in the Personal Address Book when multiple messages are checked and a message uses AltFrom, which might allow user-assisted remote attackers to… | |
| Modificada | Media (4.3) | 1.4% | — | IBM Lotus Domino Inotes Client | 13/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Lotus Domino iNotes Client 6.5.4 allows remote attackers to inject arbitrary web script or HTML via email with attached html files, which are directly rendered in the browser. | |
| Modificada | Media (4.3) | 5.7% | 💥 Exploit | IBM Lotus Domino Inotes Client | 13/2/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) an email subject; (2) an encoded javascript URI, as demonstrated using "java script:"; or (3) when the Domino Web Access ActiveX control is not… | |
| Modificada | Media (5) | 1.6% | — | IBM Lotus DominoIBM Lotus Domino Enterprise ServerIBM Lotus Notes | 9/1/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (application crash) via multiple vectors, involving (1) a malformed message sent to an "Out Of Office" agent (SPR LPEE6DMQWJ), (2) the compact command (RTIN5U2SAJ), (3) malformed bitmap… | |
| Modificada | Media (5) | 1.7% | — | IBM Lotus DominoIBM Lotus Domino Enterprise ServerIBM Lotus Notes | 9/1/2006 | 16/6/2026 | Buffer overflow in IBM Lotus Notes and Domino Server before 6.5.5 allows attackers to cause a denial of service (router crash or hang) via unspecified vectors involving "CD to MIME Conversion". | |
| Modificada | Alta (7.8) | 1.7% | — | IBM Lotus DominoIBM Lotus Domino Enterprise ServerIBM Lotus Notes | 9/1/2006 | 16/6/2026 | Multiple memory leaks in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (memory consumption and crash) via unknown vectors related to (1) unspecified vectors during the SSL handshake (SPR# MKIN67MQVW), (2) the stash file during the SSL handshake (SPR# MKIN693QUT), and… | |
| Modificada | Alta (10) | 3.8% | — | IBM Lotus DominoIBM Lotus Domino Enterprise ServerIBM Lotus Notes | 9/1/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 have unknown impact and attack vectors, due to "potential security issues" as identified by SPR numbers (1) GPKS6C9J67 in Agents, (2) JGAN6B6TZ3 and (3) KSPR699NBP in the Router, (4) GPKS5YQGPT in Security, or (5) HSAO6BNL6Y in the… | |
| Modificada | Media (5) | 1.7% | — | IBM Lotus DominoIBM Lotus Domino Enterprise ServerIBM Lotus Notes | 9/1/2006 | 16/6/2026 | Unspecified vulnerability in IBM Lotus Notes and Domino Server before 6.5.5, when running on AIX, allows attackers to cause a denial of service (deep recursion leading to stack overflow and crash) via long formulas. | |
| Modificada | Media (4.6) | 0.45% | — | IBM Lotus Notes | 31/12/2005 | 16/6/2026 | IBM Lotus Notes 6.5.4 and 6.5.5, and 7.0.0 and 7.0.1, uses insecure default permissions (Everyone/Full Control) for the "Notes" folder and all children, which allows local users to gain privileges and modify, add, or delete files in that folder. | |
| Modificada | Alta (9.3) | 3.3% | — | Autonomy Keyview Export SDKAutonomy Keyview Filter SDKAutonomy Keyview Viewer SDKIBM Lotus Notes | 31/12/2005 | 16/6/2026 | Directory traversal vulnerability in kvarcve.dll in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allows remote attackers to delete arbitrary files via a (1) ZIP, (2) UUE or (3) TAR archive that contains a .. (dot dot) in the filename, which is not properly handled when… | |
| Modificada | Alta (9.3) | 7.9% | — | Autonomy Keyview Export SDKAutonomy Keyview Filter SDKAutonomy Keyview Viewer SDKIBM Lotus Notes | 31/12/2005 | 16/6/2026 | Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allow remote attackers to execute arbitrary code via (1) a UUE file containing an encoded file with a long filename handled by uudrdr.dll, (2) a compressed ZIP file with a long filename… | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Phpwebnotes | 2/9/2005 | 16/6/2026 | php_api.php in phpWebNotes 2.0.0 uses the extract function to modify key variables such as $t_path_core, which leads to a PHP file inclusion vulnerability that allows remote attackers to execute arbitrary PHP code via the t_path_core parameter. | |
| Modificada | Media (5) | 2.2% | — | IBM Lotus Notes | 26/8/2005 | 16/6/2026 | IBM Lotus Notes does not properly restrict access to password hashes in the Notes Address Book (NAB), which allows remote attackers to obtain sensitive information via the (1) password digest field in the Administration tab of a Lotus Notes client, (2) "PasswordDigest" and "HTTPPassword" fields in the document… | |
| Modificada | Media (5) | 6.2% | — | Sophos Anti-virusSophos MailmonitorSophos Mailmonitor FOR Notes DominoSophos Puremessage Anti-virus+1 | 19/7/2005 | 16/6/2026 | Sophos Anti-Virus 5.0.1, with "Scan inside archive files" enabled, allows remote attackers to cause a denial of service (CPU consumption by infinite loop) via a Bzip2 archive with a large 'Extra field length' value. |