Vulnerability Name: | CVE-2006-0120 (CCN-24212) | ||||||||
Assigned: | 2006-01-03 | ||||||||
Published: | 2006-01-03 | ||||||||
Updated: | 2017-07-20 | ||||||||
Summary: | Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (application crash) via multiple vectors, involving (1) a malformed message sent to an "Out Of Office" agent (SPR LPEE6DMQWJ), (2) the compact command (RTIN5U2SAJ), (3) malformed bitmap images (MYAA6FH5HW), (4) the "Delete Attachment" action (YPHG6844LD), (5) parsing certificates from a remote Certificate Table (AELE6DZFJW), and (6) creating a SSL key ring with the Domino Administration client (NSUA4FQPTN). | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-0120 Source: CCN Type: SA18328 IBM Lotus Domino/Notes Multiple Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory 18328 Source: CCN Type: IBM Support and Downloads Fix List for Lotus Notes and Lotus Domino Release 6.5.5 Maintenance Release (MR) Source: CONFIRM Type: UNKNOWN http://www-1.ibm.com/support/docview.wss?uid=swg27007054 Source: CCN Type: Notes/Domino Fix List SPR # LPEE6DMQWJ fixed in 6.5.5; 6.5.4 FP2 release Source: CONFIRM Type: UNKNOWN http://www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/258394eaa824f2c08525708a004209d3?OpenDocument Source: CONFIRM Type: UNKNOWN http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/040482aeb1416bb7852570e4001badd6?OpenDocument Source: CONFIRM Type: UNKNOWN http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/2bb4f466a9e986ae852570e4001babbb?OpenDocument Source: CONFIRM Type: UNKNOWN http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/4118a1f266afb26c852570e4001baf5e?OpenDocument Source: CONFIRM Type: UNKNOWN http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/5f166a44ee743b2c852570e4001baf31?OpenDocument Source: CONFIRM Type: UNKNOWN http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ad0dd14aa109f96b852570e4001bb08c?OpenDocument Source: CONFIRM Type: UNKNOWN http://www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ced5f873baea4e8b852570e4001baa6d?OpenDocument Source: CCN Type: IBM Technote Number: 1178185 Domino server crashes on AMGR when the OutOfOffice agent attempts to reply to a long Subject field Source: BID Type: Patch 16158 Source: CCN Type: BID-16158 IBM Lotus Domino and Notes Multiple Unspecified Vulnerabilities Source: VUPEN Type: UNKNOWN ADV-2006-0081 Source: XF Type: UNKNOWN lotus-outofoffice-dos(24212) Source: XF Type: UNKNOWN lotus-outofoffice-dos(24212) Source: XF Type: UNKNOWN lotus-compact-dos(24213) Source: XF Type: UNKNOWN lotus-bmp-dos(24214) Source: XF Type: UNKNOWN lotus-delete-attachment-dos(24215) Source: XF Type: UNKNOWN lotus-certificate-parsing-dos(24216) Source: XF Type: UNKNOWN lotus-ssl-keyring-dos(24217) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Vulnerability Name: | CVE-2006-0120 (CCN-24213) | ||||||||
Assigned: | 2006-01-03 | ||||||||
Published: | 2006-01-03 | ||||||||
Updated: | 2006-01-03 | ||||||||
Summary: | IBM Lotus Notes and Lotus Domino is vulnerable to a denial of service attack, caused by an issue related to the "Enable client based archiving" option. A remote malicious client could exploit this vulnerability by executing the "compact" command to cause the server to crash. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-0120 Source: CCN Type: SA18328 IBM Lotus Domino/Notes Multiple Vulnerabilities Source: CCN Type: IBM Support and Downloads Fix List for Lotus Notes and Lotus Domino Release 6.5.5 Maintenance Release (MR) Source: CCN Type: Notes/Domino Fix List SPR # RTIN5U2SAJ fixed in 6.5.5 release Source: CCN Type: IBM Technote Number: 1155450 Compact is Executing Every Tuesday at 12:00 PM and Can Crash or Hang the Server Source: CCN Type: BID-16158 IBM Lotus Domino and Notes Multiple Unspecified Vulnerabilities Source: XF Type: UNKNOWN lotus-compact-dos(24213) | ||||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Vulnerability Name: | CVE-2006-0120 (CCN-24214) | ||||||||
Assigned: | 2006-01-03 | ||||||||
Published: | 2006-01-03 | ||||||||
Updated: | 2006-01-03 | ||||||||
Summary: | IBM Lotus Notes and Lotus Domino is vulnerable to a denial of service attack, caused by improper handling of malformed BMP images. A remote attacker could exploit this vulnerability using a specially-crafted BMP image to cause the HTTP server to crash. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-0120 Source: CCN Type: SA18328 IBM Lotus Domino/Notes Multiple Vulnerabilities Source: CCN Type: IBM Support and Downloads Fix List for Lotus Notes and Lotus Domino Release 6.5.5 Maintenance Release (MR) Source: CCN Type: Notes/Domino Fix List SPR # MYAA6FH5HW fixed in 6.5.5 release Source: CCN Type: BID-16158 IBM Lotus Domino and Notes Multiple Unspecified Vulnerabilities Source: XF Type: UNKNOWN lotus-bmp-dos(24214) | ||||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Vulnerability Name: | CVE-2006-0120 (CCN-24215) | ||||||||
Assigned: | 2006-01-03 | ||||||||
Published: | 2006-01-03 | ||||||||
Updated: | 2006-01-03 | ||||||||
Summary: | IBM Lotus Notes and Lotus Domino is vulnerable to a denial of service attack, caused by an issue related to the "Delete Attachment" action. It may be possible for a remote attacker to exploit this vulnerability to cause the HTTP server to crash. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-0120 Source: CCN Type: SA18328 IBM Lotus Domino/Notes Multiple Vulnerabilities Source: CCN Type: IBM Support and Downloads Fix List for Lotus Notes and Lotus Domino Release 6.5.5 Maintenance Release (MR) Source: CCN Type: Notes/Domino Fix List SPR # YPHG6844LD fixed in 6.5.5 release Source: CCN Type: BID-16158 IBM Lotus Domino and Notes Multiple Unspecified Vulnerabilities Source: XF Type: UNKNOWN lotus-delete-attachment-dos(24215) | ||||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Vulnerability Name: | CVE-2006-0120 (CCN-24216) | ||||||||
Assigned: | 2006-01-03 | ||||||||
Published: | 2006-01-03 | ||||||||
Updated: | 2017-07-20 | ||||||||
Summary: | Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (application crash) via multiple vectors, involving (1) a malformed message sent to an "Out Of Office" agent (SPR LPEE6DMQWJ), (2) the compact command (RTIN5U2SAJ), (3) malformed bitmap images (MYAA6FH5HW), (4) the "Delete Attachment" action (YPHG6844LD), (5) parsing certificates from a remote Certificate Table (AELE6DZFJW), and (6) creating a SSL key ring with the Domino Administration client (NSUA4FQPTN). | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-0120 Source: CCN Type: SA18328 IBM Lotus Domino/Notes Multiple Vulnerabilities Source: CCN Type: IBM Support and Downloads Fix List for Lotus Notes and Lotus Domino Release 6.5.5 Maintenance Release (MR) Source: CCN Type: BID-16158 IBM Lotus Domino and Notes Multiple Unspecified Vulnerabilities Source: XF Type: UNKNOWN lotus-certificate-parsing-dos(24216) | ||||||||
Vulnerability Name: | CVE-2006-0120 (CCN-24217) | ||||||||
Assigned: | 2006-01-03 | ||||||||
Published: | 2006-01-03 | ||||||||
Updated: | 2006-01-03 | ||||||||
Summary: | IBM Lotus Notes and Lotus Domino is vulnerable to a denial of service attack, caused by an issue related to the creation of SSL key rings. It may be possible for a remote attacker to exploit this vulnerability to cause the Domino Administration client to crash. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||
Vulnerability Consequences: | Denial of Service | ||||||||
References: | Source: MITRE Type: CNA CVE-2006-0120 Source: CCN Type: SA18328 IBM Lotus Domino/Notes Multiple Vulnerabilities Source: CCN Type: IBM Support and Downloads Fix List for Lotus Notes and Lotus Domino Release 6.5.5 Maintenance Release (MR) Source: CCN Type: Notes/Domino Fix List SPR # NSUA4FQPTN fixed in 6.5.5 release Source: CCN Type: BID-16158 IBM Lotus Domino and Notes Multiple Unspecified Vulnerabilities Source: XF Type: UNKNOWN lotus-ssl-keyring-dos(24217) | ||||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |