Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

234 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)7.0%💥 ExploitIBM Lotus Domino Server2/5/200516/6/2026
NLSCCSTR.DLL in the web service in IBM Lotus Domino Server 6.5.1, 6.0.3, and possibly other versions allows remote attackers to cause a denial of service (deep recursion and nHTTP.exe process crash) via a long GET request containing UNICODE decimal value 430 characters, which causes the stack to be exhausted. NOTE:…
ModificadaMedia (5)5.2%💥 ExploitTrend Micro Scanmail Domino1/3/200516/6/2026
Trend ScanMail allows remote attackers to obtain potentially sensitive information or disable the anti-virus capability via the smency.nsf file.
ModificadaAlta (7.5)19%—Symantec Antivirus Scan EngineSymantec Brightmail AntispamSymantec Client SecuritySymantec Gateway Security+78/2/200516/6/2026
Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative virtual offset to a crafted PE header.
ModificadaMedia (4.3)3.6%💥 ExploitIBM Lotus Domino31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows remote attackers to inject arbitrary web script or HTML via a Domino command in the Quick Console.
ModificadaBaja (3.6)1.1%💥 ExploitIBM Lotus Domino31/12/200416/6/2026
Directory traversal vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows local users to create folders or determine the existence of files via a .. (dot dot) in the new folder dialog.
ModificadaMedia (6.4)1.6%—IBM Lotus Domino31/12/200416/6/2026
Directory traversal vulnerability in webadmin.nsf for Lotus Domino R6 6.5.1 allows attackers to create and detect directories via a .. (dot dot) in the directory creation command.
ModificadaMedia (6.8)1.2%—Lotus DominoAI31/12/200416/6/2026
Cross-site scripting (XSS) vulnerability in Lotus Domino 6.0.x before 6.0.4 and 6.5.x before 6.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
ModificadaMedia (4.3)3.1%💥 ExploitIBM Lotus Domino18/10/200416/6/2026
NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Domino R6, and possibly earlier versions, allows remote attackers to execute arbitrary web script or HTML via square brackets at the beginning and end of (1) computed for display, (2) computed when…
ModificadaMedia (5)3.1%💥 ExploitLotus DominoAI6/8/200416/6/2026
Web Access in Lotus Domino 6.5.1 allows remote attackers to cause a denial of service (server crash) via a large e-mail message, as demonstrated using a large image attachment.
ModificadaAlta (7.5)1.5%—IBM Lotus Domino6/8/200416/6/2026
Lotus Domino 6.5.0 and 6.5.1, with IMAP enabled, allows remote authenticated users to change their quota by using the IMAP setquota command.
ModificadaMedia (4.6)0.36%—IBM Lotus Domino20/1/200416/6/2026
Lotus Notes Domino 6.0.2 on Linux installs the notes.ini configuration file with world-writable permissions, which allows local users to modify the Notes configuration and gain privileges.
ModificadaMedia (5)1.3%—Lotus Domino Server31/12/200316/6/2026
Lotus Domino Server 5.0 and 6.0 allows remote attackers to read the source code for files via an HTTP request with a filename with a trailing dot.
ModificadaMedia (5)3.0%—IBM Lotus Domino WEB Server2/4/200316/6/2026
Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via an incomplete POST request, as demonstrated using the h_PageUI form.
ModificadaAlta (7.5)7.7%—IBM Lotus Domino WEB ServerIBM Lotus Notes Client2/4/200316/6/2026
Buffer overflow in the COM Object Control Handler for Lotus Domino 6.0.1 and earlier allows remote attackers to execute arbitrary code via multiple attack vectors, as demonstrated using the InitializeUsingNotesUserName method in the iNotes ActiveX control.
ModificadaMedia (5)2.5%—IBM Lotus Domino WEB Server2/4/200316/6/2026
Lotus Domino Web Server (nhttp.exe) before 6.0.1 allows remote attackers to cause a denial of service via a "Fictionary Value Field POST request" as demonstrated using the s_Validation form with a long, unknown parameter name.
ModificadaAlta (10)15%—IBM Lotus Domino WEB Server2/4/200316/6/2026
Multiple buffer overflows in Lotus Domino Web Server before 6.0.1 allow remote attackers to cause a denial of service or execute arbitrary code via (1) the s_ViewName option in the PresetFields parameter for iNotes, (2) the Foldername option in the PresetFields parameter for iNotes, or (3) a long Host header, which is…
ModificadaMedia (5)3.4%—IBM Lotus DominoIBM Lotus Notes Client18/3/200316/6/2026
Buffer overflow in Web Retriever client for Lotus Notes/Domino R4.5 through R6 allows remote malicious web servers to cause a denial of service (crash) via a long HTTP status line.
ModificadaMedia (5)10%—IBM Lotus DominoIBM Lotus Notes Client18/3/200316/6/2026
Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote attackers to execute arbitrary code via a long distinguished name (DN) during NotesRPC authentication and an outer field length that is less than that of the DN field.
ModificadaMedia (5)4.1%—IBM Lotus Domino31/12/200216/6/2026
Buffer overflow in Lotus Domino web server before R5.0.10, when logging to DOMLOG.NSF, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP Authenticate header containing certain non-ASCII characters.
ModificadaMedia (5)2.3%—IBM Lotus Domino31/12/200216/6/2026
Lotus Domino 5.0.8 web server returns different error messages when a valid or invalid user is provided in HTTP requests, which allows remote attackers to determine valid user names and makes it easier to conduct brute force attacks.
ModificadaMedia (5)1.8%—IBM Lotus Domino Server31/12/200216/6/2026
Lotus Domino server 5.0.9a and earlier allows remote attackers to cause a denial of service by exhausting the number of working threads via a large number of HTTP requests for (1) an MS-DOS device name and (2) an MS-DOS device name with a large number of characters appended to the device name.
ModificadaMedia (5)2.9%💥 ExploitLotus Domino31/12/200216/6/2026
Lotus Domino 5.0.9a and earlier, even when configured with the 'DominoNoBanner=1' option, allows remote attackers to obtain potential sensitive information such as the version via a request for a non-existent .nsf database, which leaks the version in the HTTP banner.
ModificadaAlta (7.5)1.4%—Lotus Domino R44/10/200216/6/2026
Lotus Domino R4 allows remote attackers to bypass access restrictions for files in the web root via an HTTP request appended with a "?" character, which is treated as a wildcard character and bypasses the web handlers.
ModificadaMedia (5)1.7%—Lotus Domino26/7/200216/6/2026
htcgibin.exe in Lotus Domino server 5.0.9a and earlier, when configured with the NoBanner setting, allows remote attackers to determine the version number of the server via a request that generates an HTTP 500 error code, which leaks the version in a hard-coded error message.
ModificadaMedia (5)2.8%—Lotus Domino26/7/200216/6/2026
htcgibin.exe in Lotus Domino server 5.0.9a and earlier allows remote attackers to determine the physical pathname for the server via requests that contain certain MS-DOS device names such as com5, such as (1) a request with a .pl or .java extension, or (2) a request containing a large number of periods, which causes…
Orbitaley — Vulnerabilidades