
CVE-2017-1714
https://notcve.org/view.php?id=CVE-2017-1714
13 Feb 2018 — IBM Notes and Domino NSD 8.5 and 9.0 could allow an authenticated local user without administrative privileges to gain System privilege. IBM X-Force ID: 134633. IBM Notes and Domino NSD 8.5 y 9.0 podrían permitir que un usuario local autenticado sin privilegios administrativos obtenga privilegios System. IBM X-Force ID: 134633. • http://www.ibm.com/support/docview.wss?uid=swg22010776 •

CVE-2017-1720
https://notcve.org/view.php?id=CVE-2017-1720
13 Feb 2018 — IBM Notes 8.5 and 9.0 could allow a local attacker to execute arbitrary commands by carefully crafting a command line sent via the shared memory IPC. IBM X-Force ID: 134807. Las versiones 8.5 y 9.0 de IBM Notes podrían permitir que un atacante local ejecute comandos arbitrarios manipulando cuidadosamente una línea de comandos enviada mediante el IPC de la memoria compartida. IBM X-Force ID: 134807. • http://www.ibm.com/support/docview.wss?uid=swg22010766 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVE-2016-0270
https://notcve.org/view.php?id=CVE-2016-0270
08 Feb 2017 — IBM Domino 9.0.1 Fix Pack 3 Interim Fix 2 through 9.0.1 Fix Pack 5 Interim Fix 1, when using TLS and AES GCM, uses random nonce generation, which makes it easier for remote attackers to obtain the authentication key and spoof data by leveraging the reuse of a nonce in a session and a "forbidden attack." NOTE: this CVE has been incorrectly used for GCM nonce reuse issues in other products; see CVE-2016-10213 for the A10 issue, CVE-2016-10212 for the Radware issue, and CVE-2017-5933 for the Citrix issue. IBM ... • http://www-01.ibm.com/support/docview.wss?uid=swg21979604 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2014-8921
https://notcve.org/view.php?id=CVE-2014-8921
02 Mar 2015 — The IBM Notes Traveler Companion application 1.0 and 1.1 before 201411010515 for Window Phone, as distributed in IBM Notes Traveler 9.0.1, does not properly restrict the number of executions of the automatic configuration option, which makes it easier for remote attackers to capture credentials by conducting a phishing attack involving an encrypted e-mail message. La aplicación IBM Notes Traveler Companion 1.0 y 1.1 anterior a 201411010515 para Window Phone, distribuido en IBM Notes Traveler 9.0.1, no restr... • http://www-01.ibm.com/support/docview.wss?uid=swg21690582 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2014-6130
https://notcve.org/view.php?id=CVE-2014-6130
04 Nov 2014 — The IBM Notes Traveler application before 9.0.1.3 for Android lacks a warning message during selection of an HTTP session, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during a session in which the user had intended to use HTTPS. La aplicación IBM Notes Traveler anterior a 9.0.1.3 para Android le falta un mensaje de aviso durante la selección de una sesión HTTP, lo que facilita a atacantes remotos obtener información sensible mediante la captura de trafi... • http://www-01.ibm.com/support/docview.wss?uid=swg21688840 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2014-3086 – JDK: Privilege escalation issue
https://notcve.org/view.php?id=CVE-2014-3086
12 Aug 2014 — Unspecified vulnerability in the IBM Java Virtual Machine, as used in IBM WebSphere Real Time 3 before Service Refresh 7 FP1 and other products, allows remote attackers to gain privileges by leveraging the ability to execute code in the context of a security manager. Vulnerabilidad no especificada en IBM Java Virtual Machine, utilizado en IBM WebSphere Real Time 3 anterior a Service Refresh 7 FP1 y otros productos, permite a atacantes remotos ganar privilegios mediante el aprovechamiento de la habilidad de ... • http://secunia.com/advisories/59680 • CWE-266: Incorrect Privilege Assignment •

CVE-2014-0892
https://notcve.org/view.php?id=CVE-2014-0892
23 Apr 2014 — IBM Notes and Domino 8.5.x before 8.5.3 FP6 IF3 and 9.x before 9.0.1 FP1 on 32-bit Linux platforms use incorrect gcc options, which makes it easier for remote attackers to execute arbitrary code by leveraging the absence of the NX protection mechanism and placing crafted x86 code on the stack, aka SPR KLYH9GGS9W. IBM Notes y Domino 8.5.x anterior a 8.5.3 FP6 IF3 y 9.x anterior a 9.0.1 FP1 en plataformas de 32-bit de Linux utilizan opciones gcc incorrectas, lo que facilita a atacantes remotos ejecutar código... • http://www-01.ibm.com/support/docview.wss?uid=swg21670264 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2012-6349
https://notcve.org/view.php?id=CVE-2012-6349
18 Jul 2013 — Buffer overflow in the .mdb parser in Autonomy KeyView IDOL, as used in IBM Notes 8.5.x before 8.5.3 FP4, allows remote attackers to execute arbitrary code via a crafted file, aka SPR KLYH92XL3W. Desbordamiento de búfer en el parser .mdb en Autonomy KeyView IDOL, como se utilizaba en IBM Notes v8.5.x anterior a v8.5.3 FP4, permite a atacantes remotos ejecutar código arbitrario a través de un archivo especialmente elaborado, también conocido como SPR KLYH92XL3W. • http://www-01.ibm.com/support/docview.wss?uid=swg21627992 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2013-0536
https://notcve.org/view.php?id=CVE-2013-0536
21 Jun 2013 — ntmulti.exe in the Multi User Profile Cleanup service in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3 before FP5, and 9.0 before IF2 allows local users to gain privileges via vectors that arrange for code to be executed during the next login session of a different user, aka SPR PJOK959J24. ntmulti.exe en el servicio Multi User Profile Cleanup en IBM Notes v8.0, v8.0.1, v8.0.2, v8.5, v8.5.1, v8.5.2, v8.5.3 anterior a FP5, y v9.0 anterior a IF2 permite a usuarios locales ganar privilegios mediante ve... • http://www-01.ibm.com/support/docview.wss?uid=swg21633827 • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2013-2977
https://notcve.org/view.php?id=CVE-2013-2977
10 May 2013 — Integer overflow in IBM Notes 8.5.x before 8.5.3 FP4 Interim Fix 1 and 9.x before 9.0 Interim Fix 1 on Windows, and 8.5.x before 8.5.3 FP5 and 9.x before 9.0.1 on Linux, allows remote attackers to execute arbitrary code via a malformed PNG image in a previewed e-mail message, aka SPR NPEI96K82Q. Desbordamiento de entero en IBM Notes v8.5.x anterior a v8.5.3 FP4 Interim Fix 1 y v9.x anterior a v9.0 Interim Fix 1 en Windows, y v8.5.x anterior a v8.5.3 FP5 y v9.x anterior a v9.0.1 en Linux, permite a atacantes... • https://github.com/defrancescojp/CVE-2013-2977 • CWE-189: Numeric Errors •