Page 3 of 31 results (0.011 seconds)

CVSS: 4.3EPSS: 0%CPEs: 17EXPL: 0

Cross-site scripting (XSS) vulnerability in the MIME e-mail functionality in iNotes in IBM Domino 9.0 before IF3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN986NAA. Vulnerabilidad Cross-site scripting (XSS) en la funcionalidad MIME e-mail en iNotes en IBM Domino v9.0 anterior a IF3 permite a atacantes remotos inyectar código script o HTML a través de vectores sin especificar, también conocido como SPR PTHN986NAA. • http://www-01.ibm.com/support/docview.wss?uid=swg21644599 http://www-01.ibm.com/support/docview.wss?uid=swg21645503 https://exchange.xforce.ibmcloud.com/vulnerabilities/84622 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 4.3EPSS: 0%CPEs: 19EXPL: 0

Cross-site scripting (XSS) vulnerability in the MIME e-mail functionality in iNotes in IBM Domino 9.0 before IF3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN98FLQ2. Vulnerabilidad Cross-site scripting (XSS) en la funcionalidad MIME e-mail en iNotes en IBM Domino v9.0 anterior a IF3 permite a atacantes remotos inyectar código script o HTML a través de vectores sin especificar, también conocido como SPR PTHN98FLQ2. • http://www-01.ibm.com/support/docview.wss?uid=swg21644599 http://www-01.ibm.com/support/docview.wss?uid=swg21645503 https://exchange.xforce.ibmcloud.com/vulnerabilities/84971 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.3EPSS: 29%CPEs: 3EXPL: 0

Buffer overflow in the Lotus Quickr for Domino ActiveX control in qp2.cab in IBM Lotus Quickr 8.1 before FP 8.1.0.32-001a, 8.2 before FP 8.2.0.28-001a, and 8.5.1 before FP 8.5.1.39-002a for Domino allows remote attackers to execute arbitrary code via a crafted web site. Desbordamiento de búfer en el control ActiveX Lotus Quickr para Domino en qp2.cab IBM Lotus Quickr 8.1 anterior a FP 8.1.0.32-001a, 8.2 anterior a FP 8.2.0.28-001a, y 8.5.1 anterior a FP 8.5.1.39-002a para Domino, permite a atacantes remotos ejecutar código arbitrario a través de un sitio web manipulado. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM Quickr for Domino. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of user provided input in an ActiveX control. An integer overflow exists which leads to a heap buffer overflow. • http://www-01.ibm.com/support/docview.wss?uid=swg21639643 https://exchange.xforce.ibmcloud.com/vulnerabilities/84381 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 4.3EPSS: 0%CPEs: 16EXPL: 0

Memory leak in the HTTP server in IBM Domino 8.5.x allows remote attackers to cause a denial of service (memory consumption and daemon crash) via GET requests, aka SPR KLYH92NKZY. Fuga de memoria en el servidor HTTP IBM Domino 8.5.x, permite a atacantes remotos provocar una denegación de servicio (consumo de memoria y caída de demonio) a través de peticiones GET. Aka SPR KLYH92NKZY. • http://jvn.jp/en/jp/JVN51305555/index.html http://jvndb.jvn.jp/ja/contents/2013/JVNDB-2013-000030.html http://www-01.ibm.com/support/docview.wss?uid=swg21627597 https://exchange.xforce.ibmcloud.com/vulnerabilities/81812 • CWE-399: Resource Management Errors •

CVSS: 4.3EPSS: 0%CPEs: 16EXPL: 0

Cross-site scripting (XSS) vulnerability in webadmin.nsf (aka the Web Administrator client) in IBM Domino 8.5.x allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en webadmin.nsf (también conocido como cliente Web Administrator) en IBM Domino v8.5.x permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg21627597 https://exchange.xforce.ibmcloud.com/vulnerabilities/81853 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •