Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
107 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.6% | — | IBM Lotus DominoIBM Lotus Domino Enterprise ServerIBM Lotus Notes | 9/1/2006 | 16/6/2026 | Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (application crash) via multiple vectors, involving (1) a malformed message sent to an "Out Of Office" agent (SPR LPEE6DMQWJ), (2) the compact command (RTIN5U2SAJ), (3) malformed bitmap… | |
| Modificada | Alta (7.8) | 3.0% | — | IBM Lotus Domino | 31/12/2005 | 16/6/2026 | The LDAP server (nldap.exe) in IBM Lotus Domino before 7.0.1, 6.5.5, and 6.5.4 FP2 allows remote attackers to cause a denial of service (crash) via a long bind request, which triggers a null dereference. | |
| Modificada | Media (6.8) | 1.4% | — | IBM Lotus Domino | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Lotus Domino versions before 6.5.4 fix pack 1 (FP1) and versions before 7.0 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Media (4.3) | 2.5% | — | IBM Lotus DominoIBM Lotus Domino Enterprise Server | 21/9/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Lotus Domino 6.5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) BaseTarget or (2) Src parameters. | |
| Modificada | Media (5) | 73% | 💥 Exploit | IBM Lotus Domino | 3/8/2005 | 16/6/2026 | Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hidden form fields, which allows remote attackers to read the HTML source to obtain sensitive information such as (1) the password hash in the HTTPPassword field, (2) the password change date in the… | |
| Modificada | Media (5) | 1.8% | — | IBM Lotus Domino | 3/5/2005 | 16/6/2026 | Format string vulnerability in Lotus Domino 6.0.x before 6.0.5 and 6.5.x before 6.5.4 allows remote attackers to cause a denial of service via the Notes protocol (NRPC). | |
| Modificada | Media (5) | 7.0% | 💥 Exploit | IBM Lotus Domino Server | 2/5/2005 | 16/6/2026 | NLSCCSTR.DLL in the web service in IBM Lotus Domino Server 6.5.1, 6.0.3, and possibly other versions allows remote attackers to cause a denial of service (deep recursion and nHTTP.exe process crash) via a long GET request containing UNICODE decimal value 430 characters, which causes the stack to be exhausted. NOTE:… | |
| Modificada | Alta (7.5) | 3.5% | — | IBM Lotus Domino Server | 2/5/2005 | 16/6/2026 | Multiple buffer overflows in Lotus Domino Server 6.0.5 and 6.5.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via large amounts of data in certain (1) time or (2) date fields. | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | IBM Lotus Domino | 31/12/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows remote attackers to inject arbitrary web script or HTML via a Domino command in the Quick Console. | |
| Modificada | Baja (3.6) | 1.1% | 💥 Exploit | IBM Lotus Domino | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows local users to create folders or determine the existence of files via a .. (dot dot) in the new folder dialog. | |
| Modificada | Media (6.4) | 1.6% | — | IBM Lotus Domino | 31/12/2004 | 16/6/2026 | Directory traversal vulnerability in webadmin.nsf for Lotus Domino R6 6.5.1 allows attackers to create and detect directories via a .. (dot dot) in the directory creation command. | |
| Modificada | Media (4.3) | 3.1% | 💥 Exploit | IBM Lotus Domino | 18/10/2004 | 16/6/2026 | NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Domino R6, and possibly earlier versions, allows remote attackers to execute arbitrary web script or HTML via square brackets at the beginning and end of (1) computed for display, (2) computed when… | |
| Modificada | Alta (7.5) | 1.5% | — | IBM Lotus Domino | 6/8/2004 | 16/6/2026 | Lotus Domino 6.5.0 and 6.5.1, with IMAP enabled, allows remote authenticated users to change their quota by using the IMAP setquota command. | |
| Modificada | Media (4.6) | 0.36% | — | IBM Lotus Domino | 20/1/2004 | 16/6/2026 | Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges. | |
| Modificada | Alta (10) | 15% | — | IBM Lotus Domino WEB Server | 2/4/2003 | 16/6/2026 | Multiple buffer overflows in Lotus Domino Web Server before 6.0.1 allow remote attackers to cause a denial of service or execute arbitrary code via (1) the s_ViewName option in the PresetFields parameter for iNotes, (2) the Foldername option in the PresetFields parameter for iNotes, or (3) a long Host header, which is… | |
| Modificada | Alta (7.5) | 7.7% | — | IBM Lotus Domino WEB ServerIBM Lotus Notes Client | 2/4/2003 | 16/6/2026 | Buffer overflow in the COM Object Control Handler for Lotus Domino 6.0.1 and earlier allows remote attackers to execute arbitrary code via multiple attack vectors, as demonstrated using the InitializeUsingNotesUserName method in the iNotes ActiveX control. | |
| Modificada | Media (5) | 3.0% | — | IBM Lotus Domino WEB Server | 2/4/2003 | 16/6/2026 | Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via an incomplete POST request, as demonstrated using the h_PageUI form. | |
| Modificada | Media (5) | 2.5% | — | IBM Lotus Domino WEB Server | 2/4/2003 | 16/6/2026 | Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via a "Fictionary Value Field POST request" as demonstrated using the s_Validation form with a long, unknown parameter name. | |
| Modificada | Media (5) | 10% | — | IBM Lotus DominoIBM Lotus Notes Client | 18/3/2003 | 16/6/2026 | Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote attackers to execute arbitrary code via a long distinguished name (DN) during NotesRPC authentication and an outer field length that is less than that of the DN field. | |
| Modificada | Media (5) | 3.4% | — | IBM Lotus DominoIBM Lotus Notes Client | 18/3/2003 | 16/6/2026 | Buffer overflow in Web Retriever client for Lotus Notes/Domino R4.5 through R6 allows remote malicious web servers to cause a denial of service (crash) via a long HTTP status line. | |
| Modificada | Media (5) | 1.8% | — | IBM Lotus Domino Server | 31/12/2002 | 16/6/2026 | Lotus Domino server 5.0.9a and earlier allows remote attackers to cause a denial of service by exhausting the number of working threads via a large number of HTTP requests for (1) an MS-DOS device name and (2) an MS-DOS device name with a large number of characters appended to the device name. | |
| Modificada | Media (5) | 2.3% | — | IBM Lotus Domino | 31/12/2002 | 16/6/2026 | Lotus Domino 5.0.8 web server returns different error messages when a valid or invalid user is provided in HTTP requests, which allows remote attackers to determine valid user names and makes it easier to conduct brute force attacks. | |
| Modificada | Media (5) | 4.1% | — | IBM Lotus Domino | 31/12/2002 | 16/6/2026 | Buffer overflow in Lotus Domino web server before R5.0.10, when logging to DOMLOG.NSF, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP Authenticate header containing certain non-ASCII characters. | |
| Modificada | Alta (7.5) | 2.6% | — | IBM Lotus Domino Server | 22/4/2002 | 16/6/2026 | Lotus Domino Servers 5.x, 4.6x, and 4.5x allows attackers to bypass the intended Reader and Author access list for a document's object via a Notes API call (NSFDbReadObject) that directly accesses the object. | |
| Modificada | Alta (7.2) | 0.43% | — | IBM Lotus Domino | 15/3/2002 | 16/6/2026 | Buffer overflow in bindsock in Lotus Domino 5.0.4 and 5.0.7 on Linux allows local users to gain root privileges via a long (1) Notes_ExecDirectory or (2) PATH environment variable. |