Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
326 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.3% | — | IBM Lotus Mobile Connect | 22/12/2010 | 16/6/2026 | The Connection Manager in IBM Lotus Mobile Connect before 6.1.4 disables the http.device.stanza blacklisting functionality for HTTP Access Services (HTTP-AS), which allows remote attackers to bypass intended access restrictions via an HTTP request that contains a disallowed User-Agent header. | |
| Modificada | Media (4.3) | 0.97% | — | IBM Lotus Mobile Connect | 22/12/2010 | 16/6/2026 | The Connection Manager in IBM Lotus Mobile Connect before 6.1.4, when HTTP Access Services (HTTP-AS) is enabled, does not properly process TCP connection requests, which allows remote attackers to cause a denial of service (memory consumption and HTTP-AS hang) by making many connection requests that trigger "queue… | |
| Modificada | Media (4) | 1.1% | — | IBM Lotus Mobile Connect | 22/12/2010 | 16/6/2026 | The Connection Manager in IBM Lotus Mobile Connect before 6.1.4 does not properly maintain a certain reference count, which allows remote authenticated users to cause a denial of service (IP address exhaustion) by making invalid attempts to establish sessions with the same VPN ID from multiple devices. | |
| Modificada | Media (4.3) | 1.2% | — | IBM Lotus Mobile Connect | 22/12/2010 | 16/6/2026 | The Mobile Network Connections functionality in the Connection Manager in IBM Lotus Mobile Connect before 6.1.4, when HTTP Access Services (HTTP-AS) is enabled, does not properly handle failed attempts at establishing HTTP-TCP sessions, which allows remote attackers to cause a denial of service (memory consumption and… | |
| Modificada | Media (4.4) | 0.28% | — | IBM Lotus Mobile Connect | 22/12/2010 | 16/6/2026 | The Connection Manager in IBM Lotus Mobile Connect (LMC) before 6.1.4, when HTTP Access Services (HTTP-AS) is enabled, does not delete LTPA tokens in response to use of the iNotes Logoff button, which might allow physically proximate attackers to obtain access via an unattended client, related to a cookie domain… | |
| Modificada | Media (4.3) | 1.1% | — | IBM Lotus Mobile Connect | 22/12/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HTTP Access Services (HTTP-AS) in the Connection Manager in IBM Lotus Mobile Connect (LMC) before 6.1.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 1.4% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | An unspecified Domino API in IBM Lotus Notes Traveler before 8.5.1.1 does not properly handle MIME types, which allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors. | |
| Modificada | Media (5) | 2.2% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | Memory leak in IBM Lotus Notes Traveler before 8.5.1.1 allows remote attackers to cause a denial of service (memory consumption and daemon outage) by sending many embedded objects in e-mail messages for iPhone clients. | |
| Modificada | Media (4) | 1.7% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | IBM Lotus Notes Traveler before 8.5.1.2 allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) by omitting the Internet ID field in the person document, and then using an Apple device to (1) accept or (2) decline an invitation. | |
| Modificada | Media (5) | 1.4% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | IBM Lotus Notes Traveler before 8.5.1.3 allows remote attackers to cause a denial of service (sync failure) via a malformed document. | |
| Modificada | Media (4) | 1.2% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | IBM Lotus Notes Traveler before 8.5.1.3 on the Nokia s60 device successfully performs a Replace Data operation for a prohibited application, which allows remote authenticated users to bypass intended access restrictions via this operation. | |
| Modificada | Baja (2.1) | 1.5% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | IBM Lotus Notes Traveler before 8.5.1.2 allows remote authenticated users to cause a denial of service (daemon crash) by accepting a meeting invitation with an iNotes client and then accepting this meeting invitation with an iPhone client. | |
| Modificada | Baja (3.5) | 0.90% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | IBM Lotus Notes Traveler before 8.5.1.3, when a multidomain environment is used, does not properly apply policy documents to mobile users from a different Domino domain than the Traveler server, which allows remote authenticated users to bypass intended access restrictions by using credentials from a different domain. | |
| Modificada | Media (4) | 1.2% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | IBM Lotus Notes Traveler before 8.5.1.2 does not reject an attachment download request for an e-mail message with a Prevent Copy attribute, which allows remote authenticated users to bypass intended access restrictions via this request. | |
| Modificada | Media (4) | 1.1% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | IBM Lotus Notes Traveler before 8.5.1.2 allows remote authenticated users to cause a denial of service (resource consumption and sync outage) by syncing a large volume of data. | |
| Modificada | Media (4.3) | 1.1% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the servlet in IBM Lotus Notes Traveler before 8.5.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4) | 1.1% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | traveler.exe in IBM Lotus Notes Traveler before 8.0.1.3 CF1 allows remote authenticated users to cause a denial of service (daemon crash) via a malformed invitation document in a sync operation. | |
| Modificada | Media (4.3) | 0.97% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | The Nokia client in IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle multiple outgoing e-mail messages between sync operations, which might allow remote attackers to read communications intended for other recipients by examining appended messages. | |
| Modificada | Media (4) | 1.1% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | IBM Lotus Notes Traveler before 8.5.0.2 allows remote authenticated users to cause a denial of service (memory consumption and daemon crash) by syncing a large volume of data, related to the launch of a new process to handle the data while the previous process is still operating on the data. | |
| Modificada | Media (4) | 0.99% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | IBM Lotus Notes Traveler before 8.5.0.2 does not properly handle a "* *" argument sequence for a certain tell command, which allows remote authenticated users to obtain access to other users' data via a sync operation, related to storage of the data of multiple users within the same thread. | |
| Modificada | Media (5.8) | 1.1% | — | IBM Lotus Notes Traveler | 16/12/2010 | 16/6/2026 | The encrypted e-mail feature in IBM Lotus Notes Traveler before 8.5.0.2 sends unencrypted messages when the feature is used without uploading a Notes ID file, which makes it easier for remote attackers to obtain sensitive information by sniffing the network. | |
| Modificada | Alta (9.3) | 41% | 💥 Exploit | IBM Lotus Domino | 16/9/2010 | 16/6/2026 | Stack-based buffer overflow in the MailCheck821Address function in nnotes.dll in the nrouter.exe service in the server in IBM Lotus Domino 8.0.x before 8.0.2 FP5 and 8.5.x before 8.5.1 FP2 allows remote attackers to execute arbitrary code via a long e-mail address in an ORGANIZER:mailto header in an iCalendar… | |
| Modificada | Alta (10) | 1.4% | — | IBM Lotus Sametime | 15/9/2010 | 16/6/2026 | Unspecified vulnerability in the webcontainer implementation in IBM Lotus Sametime Connect 8.5.1 before CF1 has unknown impact and attack vectors, aka SPRs LXUU87S57H and LXUU87S93W. | |
| Modificada | Media (4.3) | 1.0% | — | IBM Lotus Connections | 15/6/2010 | 16/6/2026 | Open redirect vulnerability in the Mobile component in IBM Lotus Connections 2.5.x before 2.5.0.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, related to "mobile edit actions," aka SPR ASRE83PPVH. | |
| Modificada | Alta (7.6) | 1.3% | — | IBM Lotus Connections | 15/6/2010 | 16/6/2026 | The Top Updates implementation in the Homepage component in IBM Lotus Connections 2.5.x before 2.5.0.2, when "forced SSL" is enabled, uses http for links, which has unspecified impact and remote attack vectors. |