Multiple unspecified vulnerabilities in Autonomy KeyView IDOL before 10.16, as used in Symantec Mail Security for Microsoft Exchange before 6.5.8, Symantec Mail Security for Domino before 8.1.1, Symantec Messaging Gateway before 10.0.1, Symantec Data Loss Prevention (DLP) before 11.6.1, IBM Notes 8.5.x, IBM Lotus Domino 8.5.x before 8.5.3 FP4, and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file, related to "a number of underlying issues" in which "some of these cases demonstrated memory corruption with attacker-controlled input and could be exploited to run arbitrary code."
https://support.symantec.com/us/en/article.symsa1262.html
https://tools.cisco.com/security/center/viewAlert.x?alertId=27482
https://vulmon.com/vulnerabilitydetails?qid=CVE-2012-6277
https://www.energy.gov/cio/articles/v-118-ibm-lotus-domino-multiple-vulnerabilities
https://www.kb.cert.org/vuls/id/849841/
Source: MITRE
Published: 2020-02-21
Updated: 2020-03-04
Type: NVD-CWE-noinfo
Base Score: 9.3
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C
Impact Score: 10
Exploitability Score: 8.6
Severity: HIGH
Base Score: 7.8
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Impact Score: 5.9
Exploitability Score: 1.8
Severity: HIGH
OR
cpe:2.3:a:ibm:domino:*:*:*:*:*:*:*:* versions from 8.5.0 to 8.5.3.6 (inclusive)
cpe:2.3:a:ibm:notes:*:*:*:*:*:*:*:* versions from 8.5 to 8.5.3 (inclusive)
OR
cpe:2.3:a:symantec:data_loss_prevention_endpoint:*:*:*:*:*:*:*:*
cpe:2.3:a:symantec:data_loss_prevention_enforce\/detection_servers:*:*:*:*:*:linux:*:*
cpe:2.3:a:symantec:data_loss_prevention_enforce\/detection_servers:*:*:*:*:*:windows:*:*
cpe:2.3:a:symantec:mail_security:6.5.7:*:*:*:*:*:*:*
cpe:2.3:a:symantec:mail_security:*:*:*:*:*:microsoft_exchange:*:* versions up to 6.5.7 (inclusive)
cpe:2.3:a:symantec:mail_security:*:*:*:*:*:domino:*:* versions up to 8.1.0 (inclusive)
OR
ID | Name | Product | Family | Severity |
---|---|---|---|---|
67192 | IBM Lotus Domino 8.5.x < 8.5.3 FP 4 Multiple Vulnerabilities | Nessus | Web Servers | high |