{"api_version":"1","generated_at":"2026-07-23T09:57:14+00:00","cve":"CVE-2007-6706","urls":{"html":"https://cve.report/CVE-2007-6706","api":"https://cve.report/api/cve/CVE-2007-6706.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-6706","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-6706"},"summary":{"title":"CVE-2007-6706","description":"Unspecified vulnerability in nlnotes.dll in the client in IBM Lotus Notes 6.5, 7.0.x before 7.0.2 CCH or 7.0.3, and possibly 8.0 allows remote attackers to execute arbitrary code via crafted text in an e-mail message sent over SMTP.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-03-09 02:44:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-94","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://osvdb.org/40956","name":"http://osvdb.org/40956","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/27279","name":"http://secunia.com/advisories/27279","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM Lotus Notes Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www-1.ibm.com/support/docview.wss?uid=swg21271957","name":"http://www-1.ibm.com/support/docview.wss?uid=swg21271957","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"410"},{"url":"http://www.vupen.com/english/advisories/2007/3597","name":"http://www.vupen.com/english/advisories/2007/3597","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1019464","name":"http://securitytracker.com/id?1019464","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM Lotus Notes SMTP Message Processing Bug Lets Remote Users Execute Arbitrary Code - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-6706","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-6706","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"6706","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"lotus_notes","cpe6":"6.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"6706","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"lotus_notes","cpe6":"8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"6706","vulnerable":"1","versionEndIncluding":"7.0.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"lotus_notes","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T16:18:20.570Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"40956","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/40956"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg21271957"},{"name":"1019464","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1019464"},{"name":"27279","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/27279"},{"name":"ADV-2007-3597","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/3597"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-10-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unspecified vulnerability in nlnotes.dll in the client in IBM Lotus Notes 6.5, 7.0.x before 7.0.2 CCH or 7.0.3, and possibly 8.0 allows remote attackers to execute arbitrary code via crafted text in an e-mail message sent over SMTP."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2008-11-15T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"40956","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/40956"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-1.ibm.com/support/docview.wss?uid=swg21271957"},{"name":"1019464","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1019464"},{"name":"27279","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/27279"},{"name":"ADV-2007-3597","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/3597"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-6706","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in nlnotes.dll in the client in IBM Lotus Notes 6.5, 7.0.x before 7.0.2 CCH or 7.0.3, and possibly 8.0 allows remote attackers to execute arbitrary code via crafted text in an e-mail message sent over SMTP."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"40956","refsource":"OSVDB","url":"http://osvdb.org/40956"},{"name":"http://www-1.ibm.com/support/docview.wss?uid=swg21271957","refsource":"CONFIRM","url":"http://www-1.ibm.com/support/docview.wss?uid=swg21271957"},{"name":"1019464","refsource":"SECTRACK","url":"http://securitytracker.com/id?1019464"},{"name":"27279","refsource":"SECUNIA","url":"http://secunia.com/advisories/27279"},{"name":"ADV-2007-3597","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/3597"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-6706","datePublished":"2008-03-09T02:00:00.000Z","dateReserved":"2008-03-08T00:00:00.000Z","dateUpdated":"2024-08-07T16:18:20.570Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-03-09 02:44:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-94","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:lotus_notes:*:*:*:*:*:*:*:*","versionEndIncluding":"7.0.2","matchCriteriaId":"F61B72CC-BC8D-40AF-AE72-5A6EEFB53B10"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:lotus_notes:6.5:*:*:*:*:*:*:*","matchCriteriaId":"1360A50E-C1E1-4690-874A-04CC7C1A77CC"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:lotus_notes:8.0:*:*:*:*:*:*:*","matchCriteriaId":"692E295E-E650-42D5-AF7A-D6276C3D76E0"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"6706","Ordinal":"1","Title":"CVE-2007-6706","CVE":"CVE-2007-6706","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"6706","Ordinal":"1","NoteData":"Unspecified vulnerability in nlnotes.dll in the client in IBM Lotus Notes 6.5, 7.0.x before 7.0.2 CCH or 7.0.3, and possibly 8.0 allows remote attackers to execute arbitrary code via crafted text in an e-mail message sent over SMTP.","Type":"Description","Title":"CVE-2007-6706"},{"CveYear":"2007","CveId":"6706","Ordinal":"2","NoteData":"2008-03-08","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"6706","Ordinal":"3","NoteData":"2008-11-15","Type":"Other","Title":"Modified"}]}}}