Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
326 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.0% | — | IBM Lotus Expeditor | 22/6/2012 | 16/6/2026 | The web container in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack does not properly perform access control for requests, which allows remote attackers to spoof a localhost request origin via crafted headers. | |
| Modificada | Alta (9.3) | 1.6% | — | IBM Lotus Expeditor | 22/6/2012 | 16/6/2026 | Untrusted search path vulnerability in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack allows local users to gain privileges via a Trojan horse DLL in the current working directory. | |
| Modificada | Media (4.3) | 1.6% | — | IBM Lotus Expeditor | 22/6/2012 | 16/6/2026 | Directory traversal vulnerability in the Eclipse Help component in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack allows remote attackers to discover the locations of files via a crafted URL. | |
| Modificada | Alta (9.3) | 29% | 💥 Exploit | IBM Lotus Inotes | 20/6/2012 | 16/6/2026 | Buffer overflow in the Attachment_Times method in a certain ActiveX control in dwa85W.dll in IBM Lotus iNotes 8.5.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a long argument. | |
| Modificada | Alta (9.3) | 38% | 💥 Exploit | IBM Lotus Notes | 20/6/2012 | 16/6/2026 | The URL handler in IBM Lotus Notes 8.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a crafted notes:// URL. | |
| Modificada | Alta (9.3) | 32% | 💥 Exploit | IBM Lotus Quickr | 25/5/2012 | 16/6/2026 | Multiple stack-based buffer overflows in a certain ActiveX control in qp2.cab in IBM Lotus Quickr 8.2 before 8.2.0.27-002a for Domino allow remote attackers to execute arbitrary code via a long argument to the (1) Attachment_Times or (2) Import_Times method. | |
| Modificada | Alta (9.3) | 5.1% | — | IBM Lotus Symphony | 23/1/2012 | 16/6/2026 | Multiple integer overflows in vclmi.dll in the visual class library module in IBM Lotus Symphony before 3.0.1 might allow remote attackers to execute arbitrary code via an embedded (1) JPEG or (2) PNG image object in a Symphony document that triggers a heap-based buffer overflow, as demonstrated by a .doc file. | |
| Modificada | Alta (7.8) | 1.8% | — | IBM Lotus Domino | 27/12/2011 | 16/6/2026 | Unspecified vulnerability in the authentication functionality in the server in IBM Lotus Domino 8.x before 8.5.2 FP4 allows remote attackers to cause a denial of service (daemon crash) via a crafted Notes RPC packet. | |
| Modificada | Media (4.3) | 1.0% | — | IBM Lotus Mobile Connect | 19/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Lotus Mobile Connect (LMC) 6.1.4 allows remote attackers to inject arbitrary web script or HTML via vectors related to a hidden redirect URL. | |
| Modificada | Media (5) | 1.1% | — | IBM Lotus Sametime | 29/10/2011 | 16/6/2026 | The default configuration of the Sametime configuration servlet (SCS) in the server in IBM Lotus Sametime 7.0 through 8.5.2 does not enable an authentication requirement, which allows remote attackers to read the configuration settings by examining a response message. | |
| Modificada | Media (4.3) | 0.87% | — | IBM Lotus Domino | 19/9/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 8.5.2 allows remote attackers to inject arbitrary web script or HTML via the PanelIcon parameter in an fmpgPanelHeader ReadForm action to WebAdmin.nsf. | |
| Modificada | Alta (9) | 11% | 💥 Exploit | IBM Lotus Domino | 19/9/2011 | 16/6/2026 | Stack-based buffer overflow in the NSFComputeEvaluateExt function in Nnotes.dll in IBM Lotus Domino 8.5.2 allows remote authenticated users to execute arbitrary code via a long tHPRAgentName parameter in an fmHttpPostRequest OpenForm action to WebAdmin.nsf. | |
| Modificada | Media (4.3) | 1.5% | — | IBM Lotus Symphony | 27/7/2011 | 16/6/2026 | The DataPilot feature in IBM Lotus Symphony 3 before FP3 allows user-assisted remote attackers to cause a denial of service (application crash) via a large .xls spreadsheet with an invalid Value reference. | |
| Modificada | Media (4.3) | 2.2% | — | IBM Lotus Symphony | 27/7/2011 | 16/6/2026 | IBM Lotus Symphony 3 before FP3 allows remote attackers to cause a denial of service (application hang) via complex graphics in a presentation. | |
| Modificada | Media (4.3) | 2.2% | — | IBM Lotus Symphony | 27/7/2011 | 16/6/2026 | IBM Lotus Symphony 3 before FP3 on Linux allows remote attackers to cause a denial of service (application crash) via a certain sample document. | |
| Modificada | Media (4.3) | 1.5% | — | IBM Lotus Symphony | 27/7/2011 | 16/6/2026 | IBM Lotus Symphony 3 before FP3 allows remote attackers to cause a denial of service (application crash) via a .docx document with empty bullet styles for parent bullets. | |
| Modificada | Media (4.3) | 2.2% | — | IBM Lotus Symphony | 27/7/2011 | 16/6/2026 | IBM Lotus Symphony 3 before FP3 allows remote attackers to cause a denial of service (application crash) via the sample .doc document that incorporates a user-defined toolbar. | |
| Modificada | Alta (10) | 2.3% | — | IBM Lotus Symphony | 27/7/2011 | 16/6/2026 | Multiple unspecified vulnerabilities in IBM Lotus Symphony 3 before FP3 have unknown impact and attack vectors, related to "critical security vulnerability issues." | |
| Modificada | Alta (9.3) | 6.9% | — | Autonomy KeyviewIBM Lotus Notes | 31/5/2011 | 16/6/2026 | Heap-based buffer overflow in xlssr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a malformed BIFF record in a .xls Excel spreadsheet attachment, aka SPR PRAD8E3HKR. | |
| Modificada | Alta (9.3) | 5.1% | — | Autonomy KeyviewIBM Lotus Notes | 31/5/2011 | 16/6/2026 | Buffer overflow in kvarcve.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted .zip attachment, aka SPR PRAD8E3NSP. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 5.1% | — | IBM Lotus Notes | 31/5/2011 | 16/6/2026 | Buffer overflow in kpprzrdr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted .prz attachment. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 5.5% | — | IBM Lotus Notes | 31/5/2011 | 16/6/2026 | Stack-based buffer overflow in assr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via crafted tag data in an Applix spreadsheet attachment, aka SPR PRAD8823A7. | |
| Modificada | Alta (9.3) | 5.5% | — | IBM Lotus Notes | 31/5/2011 | 16/6/2026 | Stack-based buffer overflow in mw8sr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted link in a Microsoft Office document attachment, aka SPR PRAD8823ND. | |
| Modificada | Alta (9.3) | 5.5% | — | IBM Lotus Notes | 31/5/2011 | 16/6/2026 | Stack-based buffer overflow in rtfsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted link in a .rtf attachment, aka SPR PRAD8823JQ. | |
| Modificada | Alta (9.3) | 33% | 💥 Exploit | IBM Lotus Notes | 31/5/2011 | 16/6/2026 | Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted header in a .lzh attachment that triggers a stack-based buffer overflow, aka SPR PRAD88MJ2W. |