Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2847▼ 151 respecto a la semana anterior
Críticas / altas1373▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 257 respecto a la semana anterior
–

13 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)2.1%—IBM Lotus Domino Server25/1/201016/6/2026
The default configuration of the web server in IBM Lotus Domino Server, possibly 6.0 through 8.0, enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authentication credentials via a cross-site tracing (XST) attack, a related issue to CVE-2004-2763 and CVE-2005-3398.
ModificadaMedia (5)3.2%—IBM Lotus Domino Server8/2/200616/6/2026
IBM Lotus Domino Server 7.0 allows remote attackers to cause a denial of service (segmentation fault) via a crafted packet to the LDAP port (389/TCP).
ModificadaMedia (5)7.0%—IBM Lotus Domino Server2/5/200516/6/2026
NLSCCSTR.DLL in the web service in IBM Lotus Domino Server 6.5.1, 6.0.3, and possibly other versions allows remote attackers to cause a denial of service (deep recursion and nHTTP.exe process crash) via a long GET request containing UNICODE decimal value 430 characters, which causes the stack to be exhausted. NOTE:…
ModificadaAlta (7.5)3.5%—IBM Lotus Domino Server2/5/200516/6/2026
Multiple buffer overflows in Lotus Domino Server 6.0.5 and 6.5.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via large amounts of data in certain (1) time or (2) date fields.
ModificadaMedia (5)1.3%—Lotus Domino Server31/12/200316/6/2026
Lotus Domino Server 5.0 and 6.0 allows remote attackers to read the source code for files via an HTTP request with a filename with a trailing dot.
ModificadaMedia (5)1.8%—IBM Lotus Domino Server31/12/200216/6/2026
Lotus Domino server 5.0.9a and earlier allows remote attackers to cause a denial of service by exhausting the number of working threads via a large number of HTTP requests for (1) an MS-DOS device name and (2) an MS-DOS device name with a large number of characters appended to the device name.
ModificadaAlta (7.5)2.6%—IBM Lotus Domino Server22/4/200216/6/2026
Lotus Domino Servers 5.x, 4.6x, and 4.5x allows attackers to bypass the intended Reader and Author access list for a document's object via a Notes API call (NSFDbReadObject) that directly accesses the object.
ModificadaMedia (5)1.6%—IBM Lotus DominoIBM Lotus Domino Server31/12/200116/6/2026
Lotus Domino server 5.0.9a and earlier allows remote attackers to bypass security restrictions and view Notes database files and possibly sensitive Notes template files (.ntf) via an HTTP request with a large number of "+" characters before the .nsf file extension, which are converted to spaces by Domino.
ModificadaMedia (5)1.7%—IBM Lotus Domino Server12/3/200116/6/2026
Buffer overflow in Lotus Notes LDAP (NLDAP) allows an attacker to conduct a denial of service through the ldap_search request.
ModificadaMedia (5)9.3%—Lotus Domino Server12/2/200116/6/2026
Directory traversal vulnerability in Lotus Domino 5.0.5 web server allows remote attackers to read arbitrary files via a .. attack.
ModificadaMedia (5)1.4%—Lotus Domino Server21/12/199916/6/2026
Buffer overflow in Lotus Domino HTTP server allows remote attackers to cause a denial of service via a long URL.
ModificadaMedia (5)1.1%—Lotus Domino Server21/12/199916/6/2026
Lotus Domino HTTP server does not properly disable anonymous access for the cgi-bin directory.
ModificadaMedia (5)1.4%—Lotus Domino Server1/12/199916/6/2026
Lotus Domino HTTP server allows remote attackers to determine the real path of the server via a request to a non-existent script in /cgi-bin.