CVE-2017-1274
45Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck and has a public proof of concept.
ssvc Actepss 6.8%
from disclosure to weapon743 days
Published on NVDApr 25
1st PoC+743d
VulnCheckMar 20
exploitation probability
6.8%top 7% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
IBM Domino 8.5.3, and 9.0 is vulnerable to a stack based overflow in the IMAP service that could allow an authenticated attacker to execute arbitrary code by specifying a large mailbox name. IBM X-Force ID: 124749.
Affected products
IBM · Dominopublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/46808unverifiedcve_referencepacketstormsecurity.com/files/152786/Lotus-Domino-8.5.3-EXAMINE-Stack-Buffer-Overflow.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/152786/Lotus-Domino-8.5.3-EXAMINE-Stack-Buffer-Overflow.htmlhttps://www.kb.cert.org/vuls/id/676632http://www.ibm.com/support/docview.wss?uid=swg22002280http://www.securityfocus.com/bid/97910http://www.securityfocus.com/bid/98019http://www.securitytracker.com/id/1038358