CVE-2003-0179

Current Description

Buffer overflow in the COM Object Control Handler for Lotus Domino 6.0.1 and earlier allows remote attackers to execute arbitrary code via multiple attack vectors, as demonstrated using the InitializeUsingNotesUserName method in the iNotes ActiveX control.

Basic Data

PublishedApril 02, 2003
Last ModifiedJuly 11, 2017
Assignercve@mitre.org
Data TypeCVE
Data FormatMITRE
Data Version4.0
Problem TypeNVD-CWE-Other
CVE Data Version4.0

Base Metric V2

CVSS 2 - Version2.0
CVSS 2 - Vector StringAV:N/AC:L/Au:N/C:P/I:P/A:P
CVSS 2 - Access VectorNETWORK
CVSS 2 - Access ComplexityLOW
CVSS 2 - AuthenticationNONE
CVSS 2 - Confidentiality ImpactPARTIAL
CVSS 2 - Availability ImpactPARTIAL
CVSS 2 - Base Score7.5
SeverityHIGH
Exploitability Score10.0
Impact Score6.4
Obtain All Privilegefalse
Obtain User Privilegetrue
Obtain Other Privilegefalse

Base Metric V3

No data provided.

Configurations

  • OR - Configuration 1
    Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
    2.3ApplicationIbmLotus Domino Web Server6.0*******
    2.3ApplicationIbmLotus Notes Client6.0*******

Vulnerable Software List

VendorProductVersions
Ibm Lotus Domino Web Server 6.0
Ibm Lotus Notes Client 6.0

References

NameSourceURLTags
20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0082.htmlVULNWATCH
20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)http://marc.info/?l=bugtraq&m=104550124032513&w=2BUGTRAQ
20030217 Domino Advisories UPDATEhttp://marc.info/?l=bugtraq&m=104550335103136&w=2BUGTRAQ
20030217 Lotus iNotes Client ActiveX Control Buffer Overrun (#NISR17022003c)http://marc.info/?l=ntbugtraq&m=104558778131373&w=2NTBUGTRAQ
20030217 Domino Advisories UPDATEhttp://marc.info/?l=ntbugtraq&m=104558778331387&w=2NTBUGTRAQ
CA-2003-11http://www.cert.org/advisories/CA-2003-11.htmlCERTUS Government Resource
N-065http://www.ciac.org/ciac/bulletins/n-065.shtmlCIAC
VU#571297http://www.kb.cert.org/vuls/id/571297CERT-VNPatch Third Party Advisory US Government Resource
http://www.nextgenss.com/advisories/lotus-inotesclientaxbo.txthttp://www.nextgenss.com/advisories/lotus-inotesclientaxbo.txtMISC
6872http://www.securityfocus.com/bid/6872BIDPatch Vendor Advisory
http://www-1.ibm.com/support/docview.wss?uid=swg21104543http://www-1.ibm.com/support/docview.wss?uid=swg21104543CONFIRM
lotus-notes-activex-bo(11339)https://exchange.xforce.ibmcloud.com/vulnerabilities/11339XF