CVE-2006-0120
Summary
| CVE | CVE-2006-0120 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-01-09 11:03:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (application crash) via multiple vectors, involving (1) a malformed message sent to an "Out Of Office" agent (SPR LPEE6DMQWJ), (2) the compact command (RTIN5U2SAJ), (3) malformed bitmap images (MYAA6FH5HW), (4) the "Delete Attachment" action (YPHG6844LD), (5) parsing certificates from a remote Certificate Table (AELE6DZFJW), and (6) creating a SSL key ring with the Domino Administration client (NSUA4FQPTN). |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:N/I:N/A:P
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Lotus Domino | 6.5.0 | All | All | All |
| Application | Ibm | Lotus Domino | 6.5.1 | All | All | All |
| Application | Ibm | Lotus Domino | 6.5.2 | All | All | All |
| Application | Ibm | Lotus Domino | 6.5.3 | All | All | All |
| Application | Ibm | Lotus Domino | 6.5.4 | All | All | All |
| Application | Ibm | Lotus Domino | 6.5.4 | All | fp1 | All |
| Application | Ibm | Lotus Domino | 6.5.4 | All | fp2 | All |
| Application | Ibm | Lotus Domino Enterprise Server | 6.5.2 | All | All | All |
| Application | Ibm | Lotus Domino Enterprise Server | 6.5.4 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5.1 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5.2 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5.3 | All | All | All |
| Application | Ibm | Lotus Notes | 6.5.4 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM Lotus Domino and Notes Multiple Unspecified Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| www-10.lotus.com/ldd/r5fixlist.nsf/e7dbb5aee9a94c56852570c90056a95d/ced5f873ba... | af854a3a-2127-422b-91ae-364da2661108 | www-10.lotus.com | |
| Notes/Domino Fix List - SPR Number RTIN5U2SAJ | af854a3a-2127-422b-91ae-364da2661108 | www-10.lotus.com | |
| Notes/Domino Fix List - SPR Number SEGN63CBLR | af854a3a-2127-422b-91ae-364da2661108 | www-10.lotus.com | |
| Notes/Domino Fix List - SPR Number MYAA6FH5HW | af854a3a-2127-422b-91ae-364da2661108 | www-10.lotus.com | |
| Notes/Domino Fix List - SPR Number YPHG6844LD | af854a3a-2127-422b-91ae-364da2661108 | www-10.lotus.com | |
| Notes/Domino Fix List - SPR Number LBRD645RQ5 | af854a3a-2127-422b-91ae-364da2661108 | www-10.lotus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| IBM Lotus Domino/Notes Multiple Vulnerabilities - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| IBM notice: The page you requested cannot be displayed | af854a3a-2127-422b-91ae-364da2661108 | www-1.ibm.com | |
| www-10.lotus.com/ldd/r5fixlist.nsf/5c087391999d06e7852569280062619d/258394eaa8... | af854a3a-2127-422b-91ae-364da2661108 | www-10.lotus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.