Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
96 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 6.8% | — | Autonomy Keyview Export SDKAutonomy Keyview Filter SDKAutonomy Keyview Viewer SDKIBM Lotus Notes+6 | 18/3/2009 | 16/6/2026 | Stack-based buffer overflow in wp6sr.dll in the Autonomy KeyView SDK 10.4 and earlier, as used in IBM Lotus Notes, Symantec Mail Security (SMS) products, Symantec BrightMail Appliance products, and Symantec Data Loss Prevention (DLP) products, allows remote attackers to execute arbitrary code via a crafted Word… | |
| Modificada | Alta (9.3) | 5.7% | — | Activepdf DocconverterAutonomy KeyviewIBM Lotus NotesSymantec Mail Security+1 | 10/4/2008 | 16/6/2026 | Multiple buffer overflows in kpagrdr.dll 2.0.0.2 and 10.3.0.0 in the Applix Presents reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, allow remote attackers to execute arbitrary code via a .ag file with (1) a long ENCODING attribute in a… | |
| Modificada | Alta (9.3) | 5.5% | — | Autonomy KeyviewIBM Lotus Notes | 10/4/2008 | 16/6/2026 | Multiple buffer overflows in htmsr.dll in the HTML speed reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes 7.0.2 and 7.0.3, allow remote attackers to execute arbitrary code via an HTML document with (1) "large chunks of data," or a long URL in the (2) BACKGROUND attribute of a BODY element or… | |
| Modificada | Alta (9.3) | 3.3% | — | Autonomy KeyviewIBM Lotus Notes | 10/4/2008 | 16/6/2026 | Buffer overflow in mimesr.dll in Autonomy (formerly Verity) KeyView, as used in IBM Lotus Notes before 8.0, might allow user-assisted remote attackers to execute arbitrary code via an e-mail message with a crafted Text mail (MIME) attachment. | |
| Modificada | Alta (9.3) | 3.0% | — | IBM Lotus NotesSymantec Mail SecurityAutonomy Keyview | 10/4/2008 | 16/6/2026 | kpagrdr.dll 2.0.0.2 and 10.3.0.0 in the Applix Presents reader in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, does not properly parse long tokens, which allows remote attackers to cause a denial of service (CPU and memory consumption) via a… | |
| Modificada | Alta (9.3) | 5.5% | — | Autonomy KeyviewIBM Lotus Notes | 10/4/2008 | 16/6/2026 | Multiple heap-based buffer overflows in emlsr.dll in the EML reader in Autonomy (formerly Verity) KeyView 10.3.0.0, as used by IBM Lotus Notes, allow remote attackers to execute arbitrary code via a long (1) To, (2) Cc, (3) Bcc, (4) From, (5) Date, (6) Subject, (7) Priority, (8) Importance, or (9) X-MSMail-Priority… | |
| Modificada | Alta (9.3) | 5.5% | — | Autonomy KeyviewIBM Lotus Notes | 10/4/2008 | 16/6/2026 | Buffer overflow in kvdocve.dll in the KeyView document viewing engine in Autonomy (formerly Verity) KeyView, as used by IBM Lotus Notes 7.0.2 and 7.0.3, allows remote attackers to execute arbitrary code via a long pathname, as demonstrated by a long SRC attribute of an IMG element in an HTML document. | |
| Modificada | Alta (9.3) | 5.7% | — | Activepdf DocconverterAutonomy KeyviewIBM Lotus NotesSymantec Mail Security+1 | 10/4/2008 | 16/6/2026 | Multiple stack-based buffer overflows in foliosr.dll in the Folio Flat File speed reader in Autonomy (formerly Verity) KeyView 10.3.0.0, as used by IBM Lotus Notes, Symantec Mail Security, and activePDF DocConverter, allow remote attackers to execute arbitrary code via a long attribute value in a (1) DI, (2) FD, (3)… | |
| Modificada | Alta (9.3) | 3.5% | — | IBM Lotus Notes | 9/3/2008 | 16/6/2026 | Unspecified vulnerability in nlnotes.dll in the client in IBM Lotus Notes 6.5, 7.0.x before 7.0.2 CCH or 7.0.3, and possibly 8.0 allows remote attackers to execute arbitrary code via crafted text in an e-mail message sent over SMTP. | |
| Modificada | Alta (9.3) | 2.9% | — | IBM Lotus Notes | 9/3/2008 | 16/6/2026 | Unspecified vulnerability in nlnotes.dll in the client in IBM Lotus Notes 6.5, 7.0.x before 7.0.2 CCH, and 8.0.x before 8.0.1 allows remote attackers to execute arbitrary code via a crafted attachment in an e-mail message sent over SMTP, a variant of CVE-2007-6706. | |
| Modificada | Media (4.3) | 2.1% | — | IBM Lotus Notes | 21/2/2008 | 16/6/2026 | IBM Lotus Notes 6.0, 6.5, 7.0, and 8.0 signs an unsigned applet when a user forwards an email message to another user, which allows user-assisted remote attackers to bypass Execution Control List (ECL) protection. | |
| Modificada | Alta (8.8) | 6.3% | 💥 Exploit | IBM Lotus Notes | 28/12/2007 | 16/6/2026 | Multiple stack-based buffer overflows in l123sr.dll in Autonomy (formerly Verity) KeyView SDK, as used by IBM Lotus Notes 5.x through 8.x, allow user-assisted remote attackers to execute arbitrary code via the (1) Length and (2) Value fields for certain Types in a Lotus 1-2-3 (.123) file in the Worksheet File (WKS)… | |
| Modificada | Media (6.9) | 0.34% | — | IBM Lotus Notes | 28/12/2007 | 16/6/2026 | IBM Lotus Notes 8 for Linux before 8.0.1 uses (1) unspecified weak permissions for the installation kit obtained through a Notes 8 download and (2) 0777 permissions for the installdata file that is created by setup.sh, which allows local users to gain privileges via a Trojan horse file. | |
| Modificada | Alta (9.3) | 21% | — | Activepdf DocconverterAutonomy Keyview Export SDKAutonomy Keyview Filter SDKAutonomy Keyview Viewer SDK+2 | 10/11/2007 | 16/6/2026 | Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, IBM Lotus Notes before 7.0.3, Symantec Mail Security, and other products, allow remote attackers to execute arbitrary code via a crafted (1) AG file to… | |
| Modificada | Alta (9.3) | 6.6% | — | Activepdf DocconverterAutonomy Keyview Export SDKAutonomy Keyview Filter SDKAutonomy Keyview Viewer SDK+2 | 10/11/2007 | 16/6/2026 | Stack-based buffer overflow in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, wp6sr.dll in IBM Lotus Notes 8.0 and before 7.0.3, Symantec Mail Security, and other products, allows remote attackers to execute arbitrary code via a crafted WordPerfect… | |
| Modificada | Alta (9.3) | 4.1% | — | IBM Lotus Notes | 29/10/2007 | 16/6/2026 | Buffer overflow in the TagAttributeListCopy function in nnotes.dll in IBM Lotus Notes before 7.0.3 allows user-assisted remote attackers to execute arbitrary code via a crafted HTML email, related to duplicate RTF conversion when the recipient operates on this email. | |
| Modificada | Alta (7.8) | 0.27% | — | IBM Lotus DominoIBM Lotus Notes | 29/10/2007 | 16/6/2026 | IBM Lotus Notes before 6.5.6, and 7.x before 7.0.3; and Domino before 6.5.5 FP3, and 7.x before 7.0.2 FP1; uses weak permissions (Everyone:Full Control) for memory mapped files (shared memory) in IPC, which allows local users to obtain sensitive information, or inject Lotus Script or other character sequences into a… | |
| Modificada | Baja (3.5) | 0.85% | — | IBM Lotus Notes | 13/8/2007 | 16/6/2026 | IBM Lotus Notes 5.x through 7.0.2 allows user-assisted remote authenticated administrators to obtain a cleartext notes.id password by setting the notes.ini (1) KFM_ShowEntropy and (2) Debug_Outfile debug variables, a different vulnerability than CVE-2005-2696. | |
| Modificada | Media (4.3) | 1.1% | — | IBM Lotus Notes | 11/4/2007 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Active Content Filter feature in Domino Web Access (DWA) in IBM Lotus Notes before 6.5.6 and 7.x before 7.0.2 FP1 allows remote attackers to inject arbitrary web script or HTML via a multipart/related e-mail message, a different issue than CVE-2006-4843. | |
| Modificada | Media (5) | 13% | — | IBM Lotus Notes | 10/11/2006 | 16/6/2026 | The Notes Remote Procedure Call (NRPC) protocol in IBM Lotus Notes Domino before 6.5.5 FP2 and 7.x before 7.0.2 does not require authentication to perform user lookups, which allows remote attackers to obtain the user ID file. | |
| Modificada | Media (5) | 1.5% | — | IBM Lotus Notes | 24/7/2006 | 16/6/2026 | IBM Lotus Notes 6.0, 6.5, and 7.0 does not properly handle replies to e-mail messages with alternate name users when the (1) "Save As Draft" option is used or (2) a "," (comma) is inside the "phrase" portion of an address, which can cause the e-mail to be sent to users that were deleted from the To, CC, and BCC… | |
| Modificada | Media (4) | 0.98% | — | IBM Lotus Notes | 20/4/2006 | 16/6/2026 | The "Add Sender to Address Book" operation (AddSenderToAddressBook.lss) and NameHelper.lss in IBM Lotus Notes 6.0 and 6.5 before 20060331 do not properly store information in the Personal Address Book when multiple messages are checked and a message uses AltFrom, which might allow user-assisted remote attackers to… | |
| Modificada | Media (5) | 1.6% | — | IBM Lotus DominoIBM Lotus Domino Enterprise ServerIBM Lotus Notes | 9/1/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (application crash) via multiple vectors, involving (1) a malformed message sent to an "Out Of Office" agent (SPR LPEE6DMQWJ), (2) the compact command (RTIN5U2SAJ), (3) malformed bitmap… | |
| Modificada | Alta (10) | 3.8% | — | IBM Lotus DominoIBM Lotus Domino Enterprise ServerIBM Lotus Notes | 9/1/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 have unknown impact and attack vectors, due to "potential security issues" as identified by SPR numbers (1) GPKS6C9J67 in Agents, (2) JGAN6B6TZ3 and (3) KSPR699NBP in the Router, (4) GPKS5YQGPT in Security, or (5) HSAO6BNL6Y in the… | |
| Modificada | Media (5) | 1.7% | — | IBM Lotus DominoIBM Lotus Domino Enterprise ServerIBM Lotus Notes | 9/1/2006 | 16/6/2026 | Unspecified vulnerability in IBM Lotus Notes and Domino Server before 6.5.5, when running on AIX, allows attackers to cause a denial of service (deep recursion leading to stack overflow and crash) via long formulas. |