![](/assets/img/cve_300x82_sin_bg.png)
CVE-2018-1435
https://notcve.org/view.php?id=CVE-2018-1435
14 Mar 2018 — IBM Notes 8.5 and 9.0 is vulnerable to a DLL hijacking attack. A remote attacker could trick a user to double click a malicious executable in an attacker-controlled directory, which could result in code execution. IBM X-Force ID: 139563. IBM Notes 8.5 y 9.0 es vulnerable a un ataque de secuestro de DLL. Un atacante remoto podría engañar a un usuario para que haga doble clic sobre un ejecutable malicioso en un directorio controlado por el atacante, lo que podría resultar en la ejecución de código. • http://www.ibm.com/support/docview.wss?uid=swg22014198 • CWE-426: Untrusted Search Path •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2018-1437
https://notcve.org/view.php?id=CVE-2018-1437
14 Mar 2018 — IBM Notes 8.5 and 9.0 could allow an attacker to execute arbitrary code on the system, caused by an error related to multiple untrusted search path. A local attacker could exploit this vulnerability to DLL hijacking to execute arbitrary code on the system or cause the application to crash. IBM X-Force ID: 139565. IBM Notes 8.5 y 9.0 podría permitir que un atacante ejecute código arbitrario en el sistema. Esto ha sido provocado por un error relacionado con múltiples rutas de búsqueda no fiables. • http://www.ibm.com/support/docview.wss?uid=swg22014201 • CWE-426: Untrusted Search Path •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2018-1409
https://notcve.org/view.php?id=CVE-2018-1409
19 Feb 2018 — IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system. By crafting a command line sent via the shared memory IPC, which could be tricked into executing an executable chosen by the attacker. IBM X-Force ID: 138708. IBM Notes Diagnostics (IBM Client Application Access e IBM Notes) podría permitir que un usuario local ejecute comandos en el sistema. Esto se logra al manipular una línea de comandos enviada mediante el IPC de la memoria com... • http://www.ibm.com/support/docview.wss?uid=swg22010766 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2018-1411
https://notcve.org/view.php?id=CVE-2018-1411
19 Feb 2018 — IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system. By crafting a command line sent via the shared memory IPC, which could be tricked into executing an executable chosen by the attacker. IBM X-Force ID: 138710. IBM Notes Diagnostics (IBM Client Application Access e IBM Notes) podría permitir que un usuario local ejecute comandos en el sistema. Esto se logra al manipular una línea de comandos enviada mediante el IPC de la memoria com... • http://www.ibm.com/support/docview.wss?uid=swg22010766 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2018-1410
https://notcve.org/view.php?id=CVE-2018-1410
19 Feb 2018 — IBM Notes Diagnostics (IBM Client Application Access and IBM Notes) could allow a local user to execute commands on the system. By crafting a command line sent via the shared memory IPC, which could be tricked into executing an executable chosen by the attacker. IBM X-Force ID: 138709. IBM Notes Diagnostics (IBM Client Application Access e IBM Notes) podría permitir que un usuario local ejecute comandos en el sistema. Esto se logra al manipular una línea de comandos enviada mediante el IPC de la memoria com... • http://www.ibm.com/support/docview.wss?uid=swg22010766 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2017-1714
https://notcve.org/view.php?id=CVE-2017-1714
13 Feb 2018 — IBM Notes and Domino NSD 8.5 and 9.0 could allow an authenticated local user without administrative privileges to gain System privilege. IBM X-Force ID: 134633. IBM Notes and Domino NSD 8.5 y 9.0 podrían permitir que un usuario local autenticado sin privilegios administrativos obtenga privilegios System. IBM X-Force ID: 134633. • http://www.ibm.com/support/docview.wss?uid=swg22010776 •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2017-1720
https://notcve.org/view.php?id=CVE-2017-1720
13 Feb 2018 — IBM Notes 8.5 and 9.0 could allow a local attacker to execute arbitrary commands by carefully crafting a command line sent via the shared memory IPC. IBM X-Force ID: 134807. Las versiones 8.5 y 9.0 de IBM Notes podrían permitir que un atacante local ejecute comandos arbitrarios manipulando cuidadosamente una línea de comandos enviada mediante el IPC de la memoria compartida. IBM X-Force ID: 134807. • http://www.ibm.com/support/docview.wss?uid=swg22010766 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2017-1711
https://notcve.org/view.php?id=CVE-2017-1711
13 Feb 2018 — IBM iNotes 8.5 and 9.0 SUService can be misguided into running malicious code from a DLL masquerading as a windows DLL in the temp directory. IBM X-Force ID: 134532. Las versiones 8.5 y 9.0 de IBM iNotes SUService pueden manipularse para que ejecuten código malicioso de un DLL disfrazado de DLL de windows en el directorio temp. IBM X-Force ID: 134532. • http://www.ibm.com/support/docview.wss?uid=swg22010774 • CWE-426: Untrusted Search Path •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2014-3086 – JDK: Privilege escalation issue
https://notcve.org/view.php?id=CVE-2014-3086
12 Aug 2014 — Unspecified vulnerability in the IBM Java Virtual Machine, as used in IBM WebSphere Real Time 3 before Service Refresh 7 FP1 and other products, allows remote attackers to gain privileges by leveraging the ability to execute code in the context of a security manager. Vulnerabilidad no especificada en IBM Java Virtual Machine, utilizado en IBM WebSphere Real Time 3 anterior a Service Refresh 7 FP1 y otros productos, permite a atacantes remotos ganar privilegios mediante el aprovechamiento de la habilidad de ... • http://secunia.com/advisories/59680 • CWE-266: Incorrect Privilege Assignment •
![](/assets/img/cve_300x82_sin_bg.png)
CVE-2014-0892
https://notcve.org/view.php?id=CVE-2014-0892
23 Apr 2014 — IBM Notes and Domino 8.5.x before 8.5.3 FP6 IF3 and 9.x before 9.0.1 FP1 on 32-bit Linux platforms use incorrect gcc options, which makes it easier for remote attackers to execute arbitrary code by leveraging the absence of the NX protection mechanism and placing crafted x86 code on the stack, aka SPR KLYH9GGS9W. IBM Notes y Domino 8.5.x anterior a 8.5.3 FP6 IF3 y 9.x anterior a 9.0.1 FP1 en plataformas de 32-bit de Linux utilizan opciones gcc incorrectas, lo que facilita a atacantes remotos ejecutar código... • http://www-01.ibm.com/support/docview.wss?uid=swg21670264 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •