Vulnerabilities > IBM > Lotus Domino Server

DATE CVE VULNERABILITY TITLE RISK
2010-01-25 CVE-2008-7253 Configuration vulnerability in IBM Lotus Domino Server
The default configuration of the web server in IBM Lotus Domino Server, possibly 6.0 through 8.0, enables the HTTP TRACE method, which makes it easier for remote attackers to steal cookies and authentication credentials via a cross-site tracing (XST) attack, a related issue to CVE-2004-2763 and CVE-2005-3398.
network
ibm CWE-16
4.3
2006-02-08 CVE-2006-0580 Denial of Service vulnerability in IBM Lotus Domino Server 7.0
IBM Lotus Domino Server 7.0 allows remote attackers to cause a denial of service (segmentation fault) via a crafted packet to the LDAP port (389/TCP).
network
low complexity
ibm
5.0
2005-05-02 CVE-2005-1101 Unspecified vulnerability in IBM Lotus Domino Server 6.0.5/6.5.4
Multiple buffer overflows in Lotus Domino Server 6.0.5 and 6.5.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via large amounts of data in certain (1) time or (2) date fields.
network
low complexity
ibm
7.5
2002-04-22 CVE-2002-0037 Security Bypass vulnerability in IBM Lotus Domino Server 4.5/4.6/5
Lotus Domino Servers 5.x, 4.6x, and 4.5x allows attackers to bypass the intended Reader and Author access list for a document's object via a Notes API call (NSFDbReadObject) that directly accesses the object.
network
low complexity
ibm
7.5
2001-12-31 CVE-2001-1567 Remote Authentication Bypass vulnerability in IBM Lotus Domino and Lotus Domino Server
Lotus Domino server 5.0.9a and earlier allows remote attackers to bypass security restrictions and view Notes database files and possibly sensitive Notes template files (.ntf) via an HTTP request with a large number of "+" characters before the .nsf file extension, which are converted to spaces by Domino.
network
low complexity
ibm
5.0
2001-03-12 CVE-1999-0729 Unspecified vulnerability in IBM Lotus Domino Server 4.6
Buffer overflow in Lotus Notes LDAP (NLDAP) allows an attacker to conduct a denial of service through the ldap_search request.
network
low complexity
ibm
5.0