CVE Tools

Lotus

28 CVEs tracked since 2000. Since Feb 2000, none of them reached CISA KEV.

Lotus CVEs per month

Feb 2000 to Apr 2005. Point at a month, or focus the strip and use the arrow keys.
Lotus CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2000-0210
2000-0320
2000-04null or fewer
2000-05null or fewer
2000-06null or fewer
2000-0710
2000-08null or fewer
2000-09null or fewer
2000-10null or fewer
2000-1110
2000-12null or fewer
2001-01null or fewer
2001-02null or fewer
2001-03null or fewer
2001-04null or fewer
2001-0530
2001-06null or fewer
2001-0750
2001-08null or fewer
2001-0920
2001-10null or fewer
2001-1110
2001-12null or fewer
2002-01null or fewer
2002-0210
2002-0330
2002-04null or fewer
2002-0510
2002-0640
2002-07null or fewer
2002-0810
2002-09null or fewer
2002-10null or fewer
2002-11null or fewer
2002-12null or fewer
2003-01null or fewer
2003-02null or fewer
2003-03null or fewer
2003-04null or fewer
2003-05null or fewer
2003-06null or fewer
2003-07null or fewer
2003-08null or fewer
2003-09null or fewer
2003-10null or fewer
2003-11null or fewer
2003-12null or fewer
2004-01null or fewer
2004-02null or fewer
2004-03null or fewer
2004-04null or fewer
2004-05null or fewer
2004-06null or fewer
2004-07null or fewer
2004-08null or fewer
2004-0910
2004-10null or fewer
2004-11null or fewer
2004-12null or fewer
2005-01null or fewer
2005-02null or fewer
2005-03null or fewer
2005-0410

Products

The products that kept showing up in Lotus's monthly top three, with their CVEs summed over those months.

  1. Domino117 months
  2. Domino R5 Server73 months
  3. Domino Mail Server44 months
  4. Domino Server32 months
  5. Domino Enterprise Server22 months
  6. Domino R411 month
  7. Domino R5 Client11 month
  8. Domino Web Server11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Lotus.

  1. CVE-2003-1408Lotus Domino Server 5.0 and 6.0 allows remote attackers to read the source code for files via an HTTP request with a filename with a trailing dot.5.0
  2. CVE-2002-2191Lotus Domino 5.0.9a and earlier, even when configured with the 'DominoNoBanner=1' option, allows remote attackers to obtain potential sensitive information such as the version via a request for a n...5.0
  3. CVE-2001-1445Unknown vulnerability in the SMTP server in Lotus Domino 5.0 through 5.7 allows remote attackers to bypass mail relaying restrictions via crafted e-mail addresses in "RCPT TO" commands.7.5
  4. CVE-2000-1203Lotus Domino SMTP server 4.63 through 5.08 allows remote attackers to cause a denial of service (CPU consumption) by forging an email message with the sender as bounce@[127.0.0.1] (localhost), whic...5.0
  5. CVE-2002-1010Lotus Domino R4 allows remote attackers to bypass access restrictions for files in the web root via an HTTP request appended with a "?" character, which is treated as a wildcard character and bypas...7.5
  6. CVE-2001-1161Cross-site scripting (CSS) vulnerability in Lotus Domino 5.0.6 allows remote attackers to execute script on other web clients via a URL that ends in Javascript, which generates an error message tha...7.5
  7. CVE-2001-0939Lotus Domino 5.08 and earlier allows remote attackers to cause a denial of service (crash) via a SunRPC NULL command to port 443.5.0
  8. CVE-2002-0408htcgibin.exe in Lotus Domino server 5.0.9a and earlier, when configured with the NoBanner setting, allows remote attackers to determine the version number of the server via a request that generates...5.0
  9. CVE-2002-0407htcgibin.exe in Lotus Domino server 5.0.9a and earlier allows remote attackers to determine the physical pathname for the server via requests that contain certain MS-DOS device names such as com5, ...5.0
  10. CVE-2002-0245Lotus Domino server 5.0.8 with NoBanner enabled allows remote attackers to (1) determine the physical path of the server via a request for a nonexistent file with a .pl (Perl) extension, which leak...7.5
  11. CVE-2001-0954Lotus Domino 5.0.5 and 5.0.8, and possibly other versions, allows remote attackers to cause a denial of service (block access to databases that have not been previously accessed) via a URL that inc...5.0
  12. CVE-2001-0846Lotus Domino 5.x allows remote attackers to read files or execute arbitrary code by requesting the ReplicaID of the Web Administrator template file (webadmin.ntf).10.0
  13. CVE-2002-0087bindsock in Lotus Domino 5.07 on Solaris allows local users to create arbitrary files via a symlink attack on temporary files.2.1
  14. CVE-2001-1018Lotus Domino web server 5.08 allows remote attackers to determine the internal IP address of the server when NAT is enabled via a GET request that contains a long sequence of / (slash) characters.5.0
  15. CVE-2001-0847Lotus Domino Web Server 5.x allows remote attackers to gain sensitive information by accessing the default navigator $defaultNav via (1) URL encoding the request, or (2) directly requesting the Rep...7.5

The record

Peak rank
#2 in Jul 2001
Busiest month shown
Jul 2001, 5 CVEs
Months with a KEV entry
0 since Feb 2000
Monthly snapshots
15 since 2000
Lotus's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store