9.3
CVSSv2

CVE-2010-3407

Published: 16/09/2010 Updated: 10/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 940
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Stack-based buffer overflow in the MailCheck821Address function in nnotes.dll in the nrouter.exe service in the server in IBM Lotus Domino 8.0.x prior to 8.0.2 FP5 and 8.5.x prior to 8.5.1 FP2 allows remote malicious users to execute arbitrary code via a long e-mail address in an ORGANIZER:mailto header in an iCalendar calendar-invitation e-mail message, aka SPR NRBY7ZPJ9V.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm lotus domino 8.0.1

ibm lotus domino 8.5.0

ibm lotus domino 8.5.1

ibm lotus domino 8.5.1.1

ibm lotus domino 8.0.2.2

ibm lotus domino 8.0.2.3

ibm lotus domino 8.0.2

ibm lotus domino 8.0.2.1

ibm lotus domino 8.0

ibm lotus domino 8.0.2.4

ibm lotus domino 8.5.0.1

Exploits

## # $Id: domino_icalendar_organizerrb 12236 2011-04-04 17:43:34Z sinn3r $ ## ## # This file is part of the Metasploit Framework and may be subject to # redistribution and commercial restrictions Please see the Metasploit # Framework web site for more information on licensing and terms of use # metasploitcom/framework/ ## require 'msf/ ...
source: labsmwrinfosecuritycom/advisories/lotus_domino_ical_stack_buffer_overflow/ IBM Lotus Domino iCalendar Email Address Stack Buffer Overflow Vulnerability Package Name: Lotus Domino Server Date Reported: 2010-01-09 Affected Versions: Versions 80 and 85 on AIX, AIX 64bit, Linux, Linux iSeries, Linux ...