Tab navigation
Security bulletins provide important information about Lotus software products, including known security issues, troubleshooting tips, and more. Security bulletins come from the Lotus Support site.
2007
November 2007
- Buffer overflow vulnerability in Lotus Notes file viewer for Lotus 1-2-3
- Cross Site Scripting (XSS) vulnerability in IBM Lotus Domino Web Server
October 2007
- Lotus Domino IMAP Buffer Overflow Vulnerability
- Potential Security Issue with CA Process Command in Lotus Domino Console
- IBM Lotus Notes Memory Mapped Files
- Lotus Notes Buffer Overflow Vulnerability with HTML message
- Potential Notes Workstation Execution Control List (ECL) Security Vulnerability
- Evaluate LotusScript Method Returning Unexpected Results
- Buffer Overflow Vulnerability in Lotus Notes File Viewers (multiple file formats)
- Buffer Overflow Vulnerability in Lotus Notes File Viewers (.wpd, .sam, .doc, and .mif )
- Lotus Notes Denial of Service due to malformed SMTP message
July 2007
- Potential Cross Site Scripting (XSS) vulnerability in IBM Lotus Sametime Server
- Response to 'Password exposure in Lotus Notes'
June 2007
- Accessing certain URLs can cause the IBM Lotus Domino Web Server to crash
- Vulnerability in agent signature verification which may result in elevation of user's rights to Full Access Administrator
March 2007
- Potential Cross Site Scripting (XSS) Vulnerability in Domino Web Access
- IBM Lotus Sametime JNILoader Vulnerability
- IBM Lotus Domino IMAP Server Buffer Overflow Vulnerability
- IBM Lotus Domino Buffer Overflow Vulnerability in LDAP Server Task
- Lotus Domino Web Access Cross-Site Scripting Vulnerability
February 2007
2006
November 2006
September 2006
- IBM Lotus Notes File Viewer Overflow Vulnerability (dunzip32.dll)
- AltCopyTo and INetCopyTo fields may be out of sync when using "Reply to All"
July 2006
April 2006
February 2006
2005
September 2005
- Validating Domino Frameset Src Arguments
- Cross Site Scripting Vulnerability Addressed in Domino 6.5.4 FP1 and 7.0
August 2005
July 2005
- CYBSEC Advisory: Default Configuration Information Disclosure in Lotus Domino
- Bugtraq posted titled "Cross site scripting in Lotus Notes web mail"
April 2005
- Long String of UNICODE 430 Characters Reported to Cause Denial of Service on Domino Web Server
- CERT VU#699798 - Lotus Domino allows HTTP header injection
- Potential Denial of Service Vulnerability During Notes Authentication
- Buffer Overruns in Certain Date Fields Cause Domino Server Crash
- Potential Denial of Service Vulnerability in Notes Client
2004
October 2004
- Response to the "IBM Lotus Notes/Domino fails to encode Square Brackets ( [ ] )" advisory on Bugtraq
September 2004
- Does Microsoft Security Bulletin MS04-028: "Buffer Overrun in JPEG Processing (GDI+) Could Allow Code Execution (833987)" affect IBM Lotus software Customers?
- MIME Vulnerability Advisory by NISCC Posted September 13, 2004
July 2004
- Security vulnerabilities reported with Java applets
- Lotus Domino Web Access malicious email view remote Denial of Service vulnerability
- Setting mail database quota via Telnet on IMAP overrides settings
- Web Authentication Using Soundex Values May Increase the Risk of a Brute Force Attack
- Potential DOS Vulnerability SSL with IBM Lotus Instant Messaging and Web Conferencing (Sametime) 3.x and 6.5.1
June 2004
- Cross-site Scripting Vulnerability Addressed in 6.0.4 and 6.5.2
- Lotus Notes URI Handler Argument Injection Vulnerability
March 2004
January 2004
2003
November 2003
October 2003
March 2003
- Response to "Lotus Domino DOT Bug Allows for Source Code Viewing"
- Lotus Domino is not vulnerable to Remote Buffer Overflow in Sendmail
- Preventing SMTP Denial of Service Attacks from Specified IP Addresses
February 2003
- Lotus Domino Web Server iNotes Overflow; reported by NGSS
- Lotus Domino Denial of Service Attacks; reported by NGSS
- Lotus Domino Web Server Host/Location Buffer Overflow Vulnerability; reported by NGSS
- Lotus iNotes Web Access Buffer Overrun; reported by NGSS
- Lotus iNotes Client ActiveX Control Buffer Overrun; Reported by NGSS
2002
February 2002
2001
December 2001
- Reported Denial of Service Attack using Malformed URL
- Lotus Domino SunRPC Denial of Service Vulnerability