CVE-2015-1981
https://notcve.org/view.php?id=CVE-2015-1981
Cross-site scripting (XSS) vulnerability in the web server in IBM Domino 8.5.x before 8.5.3 FP6 IF8 and 9.x before 9.0.1 FP4, when Webmail is enabled, allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, aka SPR KLYH9WYPR5. Vulnerabilidad de XSS en el servidor web en IBM Domino 8.5.x anterior a 8.5.3 FP6 IF8 y 9.x anterior a 9.0.1 FP4, cuando Webmail está deshabilitado, permite a usuarios remotos autenticados inyectar secuencias de comandos web arbitrarios o HTML a través de una URL manipulada, también conocida como SPR KLYH9WYPR5. • http://seclists.org/fulldisclosure/2015/Jun/56 http://www-01.ibm.com/support/docview.wss?uid=swg21959908 http://www.securityfocus.com/bid/74908 http://www.securitytracker.com/id/1032673 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2015-1902 – IBM Lotus Domino BMP Integer Overflow Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2015-1902
Stack-based buffer overflow in IBM Domino 8.5 before 8.5.3 FP6 IF7 and 9.0 before 9.0.1 FP3 IF3 allows remote attackers to execute arbitrary code via a crafted BMP image, aka SPR KLYH9TSMLA. Desbordamiento de buffer basado en pila en IBM Domino 8.5 anterior a 8.5.3 FP6 IF7 y 9.0 anterior a 9.0.1 FP3 IF3 permite a atacantes remotos ejecutar código arbitrario a través de una imagen BMP manipulada, también conocido como SPR KLYH9TSMLA. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM Lotus Domino. Authentication is not required to exploit this vulnerability. The flaw exists within the nrouter.exe component which handles e-mails dispatched from nsmtp.exe listening on port 25. By specifying malicious dimensions within a BMP, an integer overflow can occur potentially resulting in an undersized buffer being allocated. • http://www-01.ibm.com/support/docview.wss?uid=swg21883245 http://www.securityfocus.com/bid/74597 http://www.securitytracker.com/id/1032376 http://www.zerodayinitiative.com/advisories/ZDI-15-193 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2015-1903 – IBM Lotus Domino BMP Parsing Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2015-1903
Stack-based buffer overflow in IBM Domino 8.5 before 8.5.3 FP6 IF7 and 9.0 before 9.0.1 FP3 IF3 allows remote attackers to execute arbitrary code via a crafted BMP image, aka SPR KLYH9TSN3Y. Desbordamiento de buffer basado en pila en IBM Domino 8.5 anterior a 8.5.3 FP6 IF7 y 9.0 anterior a 9.0.1 FP3 IF3 permite a atacantes remotos ejecutar código arbitrario a través de una imagen BMP manipulada, también conocido como SPR KLYH9TSN3Y. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM Lotus Domino. Authentication is not required to exploit this vulnerability. The flaw exists within the nrouter.exe component which handles e-mails dispatched from nsmtp.exe listening on port 25. It is possible to trigger a stack-based buffer overflow by specifying an overly large number of colors in the color palette within a BMP. • http://www-01.ibm.com/support/docview.wss?uid=swg21883245 http://www.securityfocus.com/bid/74598 http://www.securitytracker.com/id/1032376 http://www.zerodayinitiative.com/advisories/ZDI-15-194 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2015-0135 – IBM Lotus Domino GIF Integer Truncation Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2015-0135
IBM Domino 8.5 before 8.5.3 FP6 IF4 and 9.0 before 9.0.1 FP3 IF2 allows remote attackers to execute arbitrary code or cause a denial of service (integer truncation and application crash) via a crafted GIF image, aka SPR KLYH9T7NT9. IBM Domino 8.5 anterior a 8.5.3 FP6 IF4 y 9.0 anterior a 9.0.1 FP3 IF2 permite a atacantes remotos ejecutar código arbitrario o causar una denegación de servicio (truncación de enteros y caída de aplicación) a través de una imagen GIF manipulada, también conocido como SPR KLYH9T7NT9. This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM Lotus Domino. Authentication is not required to exploit this vulnerability. The flaw exists within the nrouter.exe component which handles e-mails dispatched from nsmtp.exe listening on port 25. By specifying malicious dimensions within a GIF, an integer truncation can occur potentially resulting in an undersized buffer being allocated. • http://www-01.ibm.com/support/docview.wss?uid=swg21701647 http://www.securitytracker.com/id/1032151 • CWE-189: Numeric Errors •
CVE-2015-0179 – Lotus Notes Diagnostic Tool 8.5/9.0 - Local Privilege Escalation
https://notcve.org/view.php?id=CVE-2015-0179
Notes System Diagnostic (NSD) in IBM Domino 8.5.x before 8.5.3 FP6 IF6 and 9.x before 9.0.1 FP3 IF1 allows local users to obtain the System privilege via unspecified vectors, aka SPR TCHL9SST8V. Notes System Diagnostic (NSD) en IBM Domino 8.5.x anterior a 8.5.3 FP6 IF6 y 9.x anterior a 9.0.1 FP3 IF1 permite a usuarios locales obtener el privilegio System a través de vectores no especificados, también conocido como SPR TCHL9SST8V. • https://www.exploit-db.com/exploits/42605 http://www-01.ibm.com/support/docview.wss?uid=swg21700029 http://www.securitytracker.com/id/1032027 • CWE-264: Permissions, Privileges, and Access Controls •