Page 11 of 52 results (0.003 seconds)

CVSS: 4.3EPSS: 0%CPEs: 17EXPL: 0

Cross-site scripting (XSS) vulnerability in the MIME e-mail functionality in iNotes in IBM Domino 9.0 before IF3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN986NAA. Vulnerabilidad Cross-site scripting (XSS) en la funcionalidad MIME e-mail en iNotes en IBM Domino v9.0 anterior a IF3 permite a atacantes remotos inyectar código script o HTML a través de vectores sin especificar, también conocido como SPR PTHN986NAA. • http://www-01.ibm.com/support/docview.wss?uid=swg21644599 http://www-01.ibm.com/support/docview.wss?uid=swg21645503 https://exchange.xforce.ibmcloud.com/vulnerabilities/84622 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.3EPSS: 95%CPEs: 1EXPL: 0

Integer overflow in the DWA9W ActiveX control in iNotes in IBM Domino 9.0 before IF3 allows remote attackers to execute arbitrary code via a crafted web page, aka SPR PTHN97XHFW. Desbordamiento de entero en el control ActiveX DWA9W en iNotes en IBM Domino v9.0 anterior a IF3 permite a atacantes remotos ejecutar código arbitrario a través de una página web diseñada, también conocido como SPR PTHN97XHFW. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM Lotus iNotes. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of user provided input in ActiveX controls. An integer overflow exists which leads to a heap buffer overflow. • http://www-01.ibm.com/support/docview.wss?uid=swg21644599 http://www-01.ibm.com/support/docview.wss?uid=swg21645503 https://exchange.xforce.ibmcloud.com/vulnerabilities/84381 • CWE-189: Numeric Errors •