Vulnerabilities > IBM > Notes

DATE CVE VULNERABILITY TITLE RISK
2020-02-21 CVE-2012-6277 Multiple unspecified vulnerabilities in Autonomy KeyView IDOL before 10.16, as used in Symantec Mail Security for Microsoft Exchange before 6.5.8, Symantec Mail Security for Domino before 8.1.1, Symantec Messaging Gateway before 10.0.1, Symantec Data Loss Prevention (DLP) before 11.6.1, IBM Notes 8.5.x, IBM Lotus Domino 8.5.x before 8.5.3 FP4, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, related to "a number of underlying issues" in which "some of these cases demonstrated memory corruption with attacker-controlled input and could be exploited to run arbitrary code."
network
ibm symantec hp
critical
9.3
2018-12-20 CVE-2018-1771 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in IBM Domino and Notes
IBM Domino 9.0 and 9.0.1 could allow an attacker to execute commands on the system by triggering a buffer overflow in the parsing of command line arguments passed to nsd.exe.
local
low complexity
ibm CWE-119
7.2
2018-05-16 CVE-2017-17689 The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. 4.3
2018-03-14 CVE-2018-1437 Untrusted Search Path vulnerability in IBM Notes
IBM Notes 8.5 and 9.0 could allow an attacker to execute arbitrary code on the system, caused by an error related to multiple untrusted search path.
network
ibm CWE-426
critical
9.3
2018-03-14 CVE-2018-1435 Untrusted Search Path vulnerability in IBM Notes
IBM Notes 8.5 and 9.0 is vulnerable to a DLL hijacking attack.
network
ibm CWE-426
6.8
2018-02-19 CVE-2018-1411 Unspecified vulnerability in IBM Client Application Access and Notes
IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system.
local
low complexity
ibm
7.2
2018-02-19 CVE-2018-1410 Unspecified vulnerability in IBM Client Application Access and Notes
IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system.
local
low complexity
ibm
4.6
2018-02-19 CVE-2018-1409 Unspecified vulnerability in IBM Client Application Access and Notes
IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system.
local
low complexity
ibm
7.2
2018-02-13 CVE-2017-1720 Command Injection vulnerability in IBM Client Application Access and Notes
IBM Notes 8.5 and 9.0 could allow a local attacker to execute arbitrary commands by carefully crafting a command line sent via the shared memory IPC.
local
low complexity
ibm CWE-77
4.6
2018-02-13 CVE-2017-1714 Unspecified vulnerability in IBM Client Application Access and Notes
IBM Notes and Domino NSD 8.5 and 9.0 could allow an authenticated local user without administrative privileges to gain System privilege.
local
low complexity
ibm
7.2