Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

234 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.5%—Lotus Domino29/5/200216/6/2026
Lotus Domino server 5.0.8 with NoBanner enabled allows remote attackers to (1) determine the physical path of the server via a request for a nonexistent file with a .pl (Perl) extension, which leaks the pathname in the error message, or (2) make any request that causes an HTTP 500 error, which leaks the server's…
ModificadaAlta (7.5)2.6%—IBM Lotus Domino Server22/4/200216/6/2026
Lotus Domino Servers 5.x, 4.6x, and 4.5x allows attackers to bypass the intended Reader and Author access list for a document's object via a Notes API call (NSFDbReadObject) that directly accesses the object.
ModificadaBaja (2.1)0.34%—Lotus Domino15/3/200216/6/2026
bindsock in Lotus Domino 5.07 on Solaris allows local users to create arbitrary files via a symlink attack on temporary files.
ModificadaAlta (7.2)0.43%—IBM Lotus Domino15/3/200216/6/2026
Buffer overflow in bindsock in Lotus Domino 5.0.4 and 5.0.7 on Linux allows local users to gain root privileges via a long (1) Notes_ExecDirectory or (2) PATH environment variable.
ModificadaMedia (5)1.6%—IBM Lotus DominoIBM Lotus Domino Server31/12/200116/6/2026
Lotus Domino server 5.0.9a and earlier allows remote attackers to bypass security restrictions and view Notes database files and possibly sensitive Notes template files (.ntf) via an HTTP request with a large number of "+" characters before the .nsf file extension, which are converted to spaces by Domino.
ModificadaMedia (5)1.6%—Lotus Domino7/12/200116/6/2026
Lotus Domino 5.0.5 and 5.0.8, and possibly other versions, allows remote attackers to cause a denial of service (block access to databases that have not been previously accessed) via a URL that includes the . (dot) directory.
ModificadaAlta (7.5)2.4%—Lotus Domino WEB Server6/12/200116/6/2026
Lotus Domino Web Server 5.x allows remote attackers to gain sensitive information by accessing the default navigator $defaultNav via (1) URL encoding the request, or (2) directly requesting the ReplicaID.
ModificadaAlta (10)41%—Lotus Domino6/12/200116/6/2026
Lotus Domino 5.x allows remote attackers to read files or execute arbitrary code by requesting the ReplicaID of the Web Administrator template file (webadmin.ntf).
ModificadaMedia (5)1.6%—Lotus Domino30/11/200116/6/2026
Lotus Domino 5.08 and earlier allows remote attackers to cause a denial of service (crash) via a SunRPC NULL command to port 443.
ModificadaMedia (5)2.3%—Lotus Domino20/9/200116/6/2026
Lotus Domino web server 5.08 allows remote attackers to determine the internal IP address of the server when NAT is enabled via a GET request that contains a long sequence of / (slash) characters.
ModificadaMedia (5)1.8%—IBM Lotus Domino19/9/200116/6/2026
The default configuration of Lotus Domino server 5.0.8 includes system information (version, operating system, and build date) in the HTTP headers of replies, which allows remote attackers to obtain sensitive information.
ModificadaMedia (5)2.5%—Lotus Domino20/8/200116/6/2026
Lotus Domino SMTP server 4.63 through 5.08 allows remote attackers to cause a denial of service (CPU consumption) by forging an email message with the sender as bounce@[127.0.0.1] (localhost), which causes Domino to enter a mail loop.
ModificadaMedia (5)1.3%—Lotus Domino R5 Server2/8/200116/6/2026
Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via URL requests (>8Kb) containing a large number of '/' characters.
ModificadaMedia (5)1.9%—Lotus Domino R5 Server2/8/200116/6/2026
Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via repeated (>400) URL requests for DOS devices.
ModificadaMedia (5)1.3%—Lotus Domino R5 Server2/8/200116/6/2026
Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via repeated URL requests with the same HTTP headers, such as (1) Accept, (2) Accept-Charset, (3) Accept-Encoding, (4) Accept-Language, and (5) Content-Type.
ModificadaMedia (5)1.3%—Lotus Domino R5 Server2/8/200116/6/2026
Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via repeatedly sending large (> 10Kb) amounts of data to the DIIOP - CORBA service on TCP port 63148.
ModificadaMedia (5)1.9%—Lotus Domino R5 Server2/8/200116/6/2026
Lotus Domino R5 prior to 5.0.7 allows a remote attacker to create a denial of service via HTTP requests containing certain combinations of UNICODE characters.
ModificadaAlta (7.5)7.0%—IBM Lotus Domino R516/7/200116/6/2026
Buffer overflows in Lotus Domino R5 before R5.0.7a allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
ModificadaAlta (7.5)4.5%—IBM Lotus Domino R516/7/200116/6/2026
Format string vulnerabilities in Lotus Domino R5 before R5.0.7a allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, as demonstrated by the PROTOS LDAPv3 test suite.
ModificadaAlta (7.5)3.9%—IBM Lotus Domino R516/7/200116/6/2026
Lotus Domino R5 before R5.0.7a allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via miscellaneous packets with semi-valid BER encodings, as demonstrated by the PROTOS LDAPv3 test suite.
ModificadaAlta (7.5)3.6%—Lotus Domino R5 Server2/7/200116/6/2026
Cross-site scripting (CSS) vulnerability in Lotus Domino 5.0.6 allows remote attackers to execute script on other web clients via a URL that ends in Javascript, which generates an error message that does not quote the resulting script.
ModificadaAlta (7.5)3.9%—Lotus Domino Mail Server2/6/200116/6/2026
Buffer overflow in Lotus Domino Mail Server 5.0.5 and earlier allows a remote attacker to crash the server or execute arbitrary code via a long "RCPT TO" command.
ModificadaMedia (5)1.7%—IBM Lotus Domino Server12/3/200116/6/2026
Buffer overflow in Lotus Notes LDAP (NLDAP) allows an attacker to conduct a denial of service through the ldap_search request.
ModificadaAlta (10)3.1%—Lotus Domino R5 ClientLotus Domino R5 Server12/3/200116/6/2026
Buffer overflow in HTML parser of the Lotus R5 Domino Server before 5.06, and Domino Client before 5.05, allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a malformed font size specifier.
ModificadaAlta (7.5)1.9%—Lotus Domino Mail Server1/3/200116/6/2026
Unknown vulnerability in the SMTP server in Lotus Domino 5.0 through 5.7 allows remote attackers to bypass mail relaying restrictions via crafted e-mail addresses in "RCPT TO" commands.
Orbitaley — Vulnerabilidades