Current Description

Buffer overflow in Notes server before Lotus Notes R4, R5 before 5.0.11, and early R6 allows remote attackers to execute arbitrary code via a long distinguished name (DN) during NotesRPC authentication and an outer field length that is less than that of the DN field.

Basic Data

PublishedMarch 18, 2003
Last ModifiedDecember 12, 2017
Data TypeCVE
Data FormatMITRE
Data Version4.0
Problem TypeNVD-CWE-Other
CVE Data Version4.0

Base Metric V2

CVSS 2 - Version2.0
CVSS 2 - Vector StringAV:N/AC:L/Au:N/C:N/I:N/A:P
CVSS 2 - Access VectorNETWORK
CVSS 2 - Access ComplexityLOW
CVSS 2 - AuthenticationNONE
CVSS 2 - Confidentiality ImpactNONE
CVSS 2 - Availability ImpactPARTIAL
CVSS 2 - Base Score5.0
Exploitability Score10.0
Impact Score2.9
Obtain All Privilegefalse
Obtain User Privilegefalse
Obtain Other Privilegefalse

Base Metric V3

No data provided.


  • OR - Configuration 1
    Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
    2.3ApplicationIbmLotus Domino4.6.1*******
    2.3ApplicationIbmLotus Domino4.6.3*******
    2.3ApplicationIbmLotus Domino4.6.4*******
    2.3ApplicationIbmLotus Domino5.0*******
    2.3ApplicationIbmLotus Domino5.0.1*******
    2.3ApplicationIbmLotus Domino5.0.2*******
    2.3ApplicationIbmLotus Domino5.0.3*******
    2.3ApplicationIbmLotus Domino5.0.4*******
    2.3ApplicationIbmLotus Domino5.0.4a*******
    2.3ApplicationIbmLotus Domino5.0.5*******
    2.3ApplicationIbmLotus Domino5.0.6*******
    2.3ApplicationIbmLotus Domino5.0.6a*******
    2.3ApplicationIbmLotus Domino5.0.7a*******
    2.3ApplicationIbmLotus Domino5.0.8*******
    2.3ApplicationIbmLotus Domino5.0.8a*******
    2.3ApplicationIbmLotus Domino5.0.9*******
    2.3ApplicationIbmLotus Domino5.0.9a*******
    2.3ApplicationIbmLotus Domino5.0.10*******
    2.3ApplicationIbmLotus Domino5.0.11*******
    2.3ApplicationIbmLotus Notes Client5.0*******
    2.3ApplicationIbmLotus Notes Client5.0.1*******
    2.3ApplicationIbmLotus Notes Client5.0.2*******
    2.3ApplicationIbmLotus Notes Client5.0.3*******
    2.3ApplicationIbmLotus Notes Client5.0.4*******
    2.3ApplicationIbmLotus Notes Client5.0.5*******
    2.3ApplicationIbmLotus Notes Client5.0.9a*******
    2.3ApplicationIbmLotus Notes Client5.0.10*******
    2.3ApplicationIbmLotus Notes Client5.0.11*******
    2.3ApplicationIbmLotus Notes Clientr5*******

Vulnerable Software List

Ibm Lotus Notes Client 5.0, 5.0.1, 5.0.10, 5.0.11, 5.0.2, 5.0.3, 5.0.4, 5.0.5, 5.0.9a, r5
Ibm Lotus Domino 4.6.1, 4.6.3, 4.6.4, 5.0, 5.0.1, 5.0.10, 5.0.11, 5.0.2, 5.0.3, 5.0.4, 5.0.4a, 5.0.5, 5.0.6, 5.0.6a, 5.0.7a, 5.0.8, 5.0.8a, 5.0.9, 5.0.9a


20030313 R7-0010: Buffer Overflow in Lotus Notes Protocol Authentication Party Advisory
20030313 R7-0010: Buffer Overflow in Lotus Notes Protocol Authentication List Third Party Advisory
CA-2003-11 Party Advisory US Government Resource
N-065 Link
VU#433489 Party Advisory US Government Resource Applicable
7037 Third Party Advisory VDB Entry Vendor Advisory Link
lotus-nrpc-bo(11526) Party Advisory VDB Entry