
CVE-2020-4102
https://notcve.org/view.php?id=CVE-2020-4102
02 Dec 2020 — HCL Notes is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successful exploit could enable an attacker to crash Notes or execute attacker-controlled code on the client system. HCL Notes es susceptible a una vulnerabilidad de Desbordamiento de Búfer en DXL debido a una comprobación inapropiada de la entrada de usuario. Una explotación con éxito podría permitir a un atacante bloquear Notes o ejecutar código controlado por el atacante en el sistema clien... • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0085499 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2020-4097
https://notcve.org/view.php?id=CVE-2020-4097
05 Nov 2020 — In HCL Notes version 9 previous to release 9.0.1 FixPack 10 Interim Fix 8, version 10 previous to release 10.0.1 FixPack 6 and version 11 previous to 11.0.1 FixPack 1, a vulnerability in the input parameter handling of the Notes Client could potentially be exploited by an attacker resulting in a buffer overflow. This could enable an attacker to crash HCL Notes or execute attacker-controlled code on the client. En HCL Notes versión 9 anterior a la versión 9.0.1 FixPack 10 Interim Fix 8, versión 10 anterior a... • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0084796 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2020-14240
https://notcve.org/view.php?id=CVE-2020-14240
05 Nov 2020 — HCL Notes versions previous to releases 9.0.1 FP10 IF8, 10.0.1 FP6 and 11.0.1 FP1 is susceptible to a Stored Cross-site Scripting (XSS) vulnerability. An attacker could use this vulnerability to execute script in a victim's Web browser within the security context of the hosting Web site and/or steal the victim's cookie-based authentication credentials. HCL Notes versiones anteriores a 9.0.1 FP10 IF8, 10.0.1 FP6 y 11.0.1 FP1, son susceptibles a una vulnerabilidad de tipo Cross-site Scripting (XSS) almacenado... • https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0084789 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •