This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Ibm First view 2010-01-09
Product Lotus Inotes Last view 2016-11-24
Version 8.5.2.0 Type Application
Update *  
Edition *  
Language *  
Sofware Edition *  
Target Software *  
Target Hardware *  
Other *  
 
CPE Product cpe:2.3:a:ibm:lotus_inotes

Activity : Overall

Related : CVE

  Date Alert Description
5.4 2016-11-24 CVE-2016-0282

Cross-site scripting (XSS) vulnerability in IBM iNotes before 8.5.3 FP6 IF2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, aka SPR KLYHAAHNUS.

4.3 2013-08-26 CVE-2013-0595

Multiple cross-site scripting (XSS) vulnerabilities in iNotes 8.5.x in IBM Lotus Domino 8.5 before 8.5.3 FP5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN95XNR3.

3.5 2013-08-26 CVE-2013-0591

Cross-site scripting (XSS) vulnerability in iNotes 8.5.x in IBM Lotus Domino 8.5 before 8.5.3 FP5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN95XNR3, a different vulnerability than CVE-2013-0590.

3.5 2013-08-26 CVE-2013-0590

Cross-site scripting (XSS) vulnerability in iNotes 8.5.x in IBM Lotus Domino 8.5 before 8.5.3 FP5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN95XNR3, a different vulnerability than CVE-2013-0591.

7.2 2013-06-21 CVE-2013-0536

ntmulti.exe in the Multi User Profile Cleanup service in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3 before FP5, and 9.0 before IF2 allows local users to gain privileges via vectors that arrange for code to be executed during the next login session of a different user, aka SPR PJOK959J24.

1.5 2013-03-26 CVE-2013-0525

Multiple cross-site scripting (XSS) vulnerabilities in IBM iNotes 8.5.x allow local users to inject arbitrary web script or HTML via a shared mail file, aka SPR DKEN8PDNTX.

4.3 2013-03-26 CVE-2012-5943

Cross-site scripting (XSS) vulnerability in IBM iNotes 8.5.x before 8.5.3 FP4 allows user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving mail, aka SPR JDOE8ZZS9.

9.3 2012-06-20 CVE-2012-2175

Buffer overflow in the Attachment_Times method in a certain ActiveX control in dwa85W.dll in IBM Lotus iNotes 8.5.x before 8.5.3 FP2 allows remote attackers to execute arbitrary code via a long argument.

6.8 2010-03-03 CVE-2010-0921

Cross-site request forgery (CSRF) vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 allows remote attackers to hijack the authentication of unspecified victims via vectors related to lack of "XSS/CSRF Get Filter and Referer Check fixes."

4.3 2010-03-03 CVE-2010-0920

Cross-site scripting (XSS) vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 allows remote attackers to inject arbitrary web script or HTML via vectors related to lack of "XSS/CSRF Get Filter and Referer Check fixes."

10 2010-03-03 CVE-2010-0918

Multiple unspecified vulnerabilities in the UltraLite functionality in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.281 for Domino 8.0.2 FP4 have unknown impact and attack vectors.

10 2010-01-09 CVE-2010-0275

Ultra-light Mode in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 does not properly handle script commands in the status-alerts URL, which has unspecified impact and attack vectors, aka SPR LSHR7TBM58.

10 2010-01-09 CVE-2010-0274

Unspecified vulnerability in the Edit Contact scene in Ultra-light Mode in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.241 for Domino 8.0.2 FP3 has unknown impact and attack vectors, aka SPR LSHR7TBLY5.

10 2010-01-09 CVE-2009-4594

Unspecified vulnerability in IBM Lotus iNotes (aka Domino Web Access or DWA) before 229.131 for Domino 8.0.x has unknown impact and attack vectors, aka SPR SDOY7RHBNH.

CWE : Common Weakness Enumeration

%idName
70% (7) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')
10% (1) CWE-352 Cross-Site Request Forgery (CSRF)
10% (1) CWE-264 Permissions, Privileges, and Access Controls
10% (1) CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer

SAINT Exploits

Description Link
Lotus Notes iNotes Attachment_Times ActiveX Overflow More info here

Open Source Vulnerability Database (OSVDB)

id Description
62755 IBM Lotus iNotes UltraLite Functionality Multiple Unspecified Issues
62754 IBM Lotus iNotes Get Filter and Referer Check Fixes Weakness XSS
62753 IBM Lotus iNotes Get Filter and Referer Check Fixes Weakness CSRF
61646 IBM Lotus Domino iNotes Ultra-light Mode Status-alerts URL Command Handling W...
61645 IBM Lotus Domino iNotes Ultra-light Mode Edit Contact Scene Unspecified Issue...
61637 IBM Lotus Domino iNotes Unspecified Issue (SPR SDOY7RHBNH)

Snort® IPS/IDS

Date Description
2016-03-14 IBM Lotus iNotes Attachment_Times ActiveX clsid access
RuleID : 36646 - Type : BROWSER-PLUGINS - Revision : 3
2016-03-14 IBM Lotus iNotes Attachment_Times ActiveX clsid access
RuleID : 36645 - Type : BROWSER-PLUGINS - Revision : 3
2016-03-14 IBM Lotus iNotes Attachment_Times ActiveX clsid access
RuleID : 36644 - Type : BROWSER-PLUGINS - Revision : 3
2014-01-10 IBM Lotus iNotes Attachement_Times ActiveX clsid access
RuleID : 24773 - Type : BROWSER-PLUGINS - Revision : 9
2014-01-10 IBM Lotus iNotes Attachment_Times ActiveX clsid access
RuleID : 24772 - Type : BROWSER-PLUGINS - Revision : 6
2014-01-10 IBM Lotus iNotes Attachment_Times ActiveX clsid access
RuleID : 24771 - Type : BROWSER-PLUGINS - Revision : 6

Nessus® Vulnerability Scanner

id Description
2016-12-15 Name: A business collaboration application running on the remote host is affected b...
File: domino_swg21992835.nasl - Type: ACT_GATHER_INFO
2013-06-20 Name: The remote host has software installed that is affected by a code execution v...
File: lotus_notes_swg21633827.nasl - Type: ACT_GATHER_INFO
2012-06-19 Name: The remote Windows host has an ActiveX control that is affected by a buffer o...
File: lotus_notes_upload_activex_bof.nasl - Type: ACT_GATHER_INFO