This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Ibm First view 2017-02-08
Product Notes Last view 2020-02-21
Version Type
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:a:ibm:notes:8.5.2.4:*:*:*:*:*:*:* 7
cpe:2.3:a:ibm:notes:8.5.1.5:*:*:*:*:*:*:* 7
cpe:2.3:a:ibm:notes:9.0.1.9:*:*:*:*:*:*:* 6
cpe:2.3:a:ibm:notes:9.0:*:*:*:*:*:*:* 6
cpe:2.3:a:ibm:notes:8.5.3.6:*:*:*:*:*:*:* 6
cpe:2.3:a:ibm:notes:8.5.0.0:*:*:*:*:*:*:* 5
cpe:2.3:a:ibm:notes:8.5.1.0:*:*:*:*:*:*:* 5
cpe:2.3:a:ibm:notes:8.5.2.0:*:*:*:*:*:*:* 5
cpe:2.3:a:ibm:notes:8.5.3:*:*:*:*:*:*:* 4
cpe:2.3:a:ibm:notes:8.5.2:*:*:*:*:*:*:* 4
cpe:2.3:a:ibm:notes:8.5.1:*:*:*:*:*:*:* 4
cpe:2.3:a:ibm:notes:8.5:*:*:*:*:*:*:* 4
cpe:2.3:a:ibm:notes:9.0.1.0:*:*:*:*:*:*:* 4
cpe:2.3:a:ibm:notes:8.5.3.0:*:*:*:*:*:*:* 4
cpe:2.3:a:ibm:notes:9.0.0.0:*:*:*:*:*:*:* 4
cpe:2.3:a:ibm:notes:8.5.0.2:*:*:*:*:*:*:* 4
cpe:2.3:a:ibm:notes:-:*:*:*:*:*:*:* 3
cpe:2.3:a:ibm:notes:9.0.1:*:*:*:*:*:*:* 3
cpe:2.3:a:ibm:notes:*:*:*:*:*:*:*:* 2
cpe:2.3:a:ibm:notes:9.0.1.5:*:*:*:*:*:*:* 2
cpe:2.3:a:ibm:notes:9.0.1.4:*:*:*:*:*:*:* 2
cpe:2.3:a:ibm:notes:9.0.1.3:*:*:*:*:*:*:* 2
cpe:2.3:a:ibm:notes:9.0.1.10:interim_fix_9:*:*:*:*:*:* 1
cpe:2.3:a:ibm:notes:9.0.1.10:interim_fix_1:*:*:*:*:*:* 1
cpe:2.3:a:ibm:notes:9.0.1.10:-:*:*:*:*:*:* 1
cpe:2.3:a:ibm:notes:9.0.1.10:interim_fix_2:*:*:*:*:*:* 1
cpe:2.3:a:ibm:notes:9.0.1.10:interim_fix_3:*:*:*:*:*:* 1
cpe:2.3:a:ibm:notes:9.0.1.10:interim_fix_4:*:*:*:*:*:* 1
cpe:2.3:a:ibm:notes:9.0.1.10:interim_fix_5:*:*:*:*:*:* 1
cpe:2.3:a:ibm:notes:9.0.1.10:interim_fix_6:*:*:*:*:*:* 1
cpe:2.3:a:ibm:notes:9.0.1.10:interim_fix_7:*:*:*:*:*:* 1
cpe:2.3:a:ibm:notes:9.0.1.10:interim_fix_8:*:*:*:*:*:* 1
cpe:2.3:a:ibm:notes:9.0.1.10:interim_fix_10:*:*:*:*:*:* 1
cpe:2.3:a:ibm:notes:9.0.0.0:if3:*:*:*:*:*:* 1
cpe:2.3:a:ibm:notes:9.0.1.10:if4:*:*:*:*:*:* 1
cpe:2.3:a:ibm:notes:9.0.1.10:if2:*:*:*:*:*:* 1
cpe:2.3:a:ibm:notes:9.0.0.0:if2:*:*:*:*:*:* 1
cpe:2.3:a:ibm:notes:9.0.0.0:if1:*:*:*:*:*:* 1
cpe:2.3:a:ibm:notes:9.0.1.10:if5:*:*:*:*:*:* 1
cpe:2.3:a:ibm:notes:9.0.0.0:if4:*:*:*:*:*:* 1
cpe:2.3:a:ibm:notes:9.0.1.10:if3:*:*:*:*:*:* 1
cpe:2.3:a:ibm:notes:9.0.1.10:if1:*:*:*:*:*:* 1

Related : CVE

  Date Alert Description
7.8 2020-02-21 CVE-2012-6277

Multiple unspecified vulnerabilities in Autonomy KeyView IDOL before 10.16, as used in Symantec Mail Security for Microsoft Exchange before 6.5.8, Symantec Mail Security for Domino before 8.1.1, Symantec Messaging Gateway before 10.0.1, Symantec Data Loss Prevention (DLP) before 11.6.1, IBM Notes 8.5.x, IBM Lotus Domino 8.5.x before 8.5.3 FP4, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, related to "a number of underlying issues" in which "some of these cases demonstrated memory corruption with attacker-controlled input and could be exploited to run arbitrary code."

7.8 2018-12-20 CVE-2018-1771

IBM Domino 9.0 and 9.0.1 could allow an attacker to execute commands on the system by triggering a buffer overflow in the parsing of command line arguments passed to nsd.exe. IBM X-force ID: 148687.

5.9 2018-05-16 CVE-2017-17689

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.

7.8 2018-03-13 CVE-2018-1437

IBM Notes 8.5 and 9.0 could allow an attacker to execute arbitrary code on the system, caused by an error related to multiple untrusted search path. A local attacker could exploit this vulnerability to DLL hijacking to execute arbitrary code on the system or cause the application to crash. IBM X-Force ID: 139565.

7.8 2018-03-13 CVE-2018-1435

IBM Notes 8.5 and 9.0 is vulnerable to a DLL hijacking attack. A remote attacker could trick a user to double click a malicious executable in an attacker-controlled directory, which could result in code execution. IBM X-Force ID: 139563.

7.8 2018-02-19 CVE-2018-1411

IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system. By crafting a command line sent via the shared memory IPC, which could be tricked into executing an executable chosen by the attacker. IBM X-Force ID: 138710.

7.8 2018-02-19 CVE-2018-1410

IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system. By crafting a command line sent via the shared memory IPC, which could be tricked into executing an executable chosen by the attacker. IBM X-Force ID: 138709.

7.8 2018-02-19 CVE-2018-1409

IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system. By crafting a command line sent via the shared memory IPC, which could be tricked into executing an executable chosen by the attacker. IBM X-Force ID: 138708.

5.3 2018-02-13 CVE-2017-1720

IBM Notes 8.5 and 9.0 could allow a local attacker to execute arbitrary commands by carefully crafting a command line sent via the shared memory IPC. IBM X-Force ID: 134807.

7.8 2018-02-13 CVE-2017-1714

IBM Notes and Domino NSD 8.5 and 9.0 could allow an authenticated local user without administrative privileges to gain System privilege. IBM X-Force ID: 134633.

7.8 2018-02-13 CVE-2017-1711

IBM iNotes 8.5 and 9.0 SUService can be misguided into running malicious code from a DLL masquerading as a windows DLL in the temp directory. IBM X-Force ID: 134532.

5.9 2017-02-08 CVE-2016-0270

IBM Domino 9.0.1 Fix Pack 3 Interim Fix 2 through 9.0.1 Fix Pack 5 Interim Fix 1, when using TLS and AES GCM, uses random nonce generation, which makes it easier for remote attackers to obtain the authentication key and spoof data by leveraging the reuse of a nonce in a session and a "forbidden attack." NOTE: this CVE has been incorrectly used for GCM nonce reuse issues in other products; see CVE-2016-10213 for the A10 issue, CVE-2016-10212 for the Radware issue, and CVE-2017-5933 for the Citrix issue.

CWE : Common Weakness Enumeration

%idName
50% (3) CWE-426 Untrusted Search Path
16% (1) CWE-200 Information Exposure
16% (1) CWE-119 Failure to Constrain Operations within the Bounds of a Memory Buffer
16% (1) CWE-77 Improper Sanitization of Special Elements used in a Command ('Comma...

Snort® IPS/IDS

Date Description
2017-12-13 Hewlett-Packard Autonomy KeyView library stack-based buffer overflow attempt
RuleID : 44796 - Type : FILE-OFFICE - Revision : 2
2017-12-13 Hewlett-Packard Autonomy KeyView library stack-based buffer overflow attempt
RuleID : 44795 - Type : FILE-OFFICE - Revision : 2

Nessus® Vulnerability Scanner

id Description
2013-07-05 Name: The remote web server is affected by multiple vulnerabilities.
File: domino_8_5_3fp4.nasl - Type: ACT_GATHER_INFO