Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-0977

49
FAUCET Score

CVE-2007-0977 describes a vulnerability in IBM Lotus Domino R5 and R6 WebMail, specifically when the "Generate HTML for all fields" option is enabled. This flaw allows attackers to retrieve HTTPPassword hashes from the names.nsf file via Readviewentries and OpenDocument requests to the defaultview view. The vulnerability carries a CVSS score of 7.1, indicating high severity, with a network attack vector and medium attack complexity, potentially leading to complete confidentiality compromise. While not listed in CISA's KEV catalog, exploit code is publicly available, including a Metasploit module and an ExploitDB entry, though community discussion and media coverage are minimal.

Impacted Technologies

VendorProductVersion(s)CPE
5.0CPE matchmatch criteria
cpe:2.3:a:ibm:lotus_domino:5.0:*:*:*:*:*:*:*
6.0CPE matchmatch criteria
cpe:2.3:a:ibm:lotus_domino:6.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.1HIGH

AV:N/AC:M/Au:N/C:C/I:N/A:N

Confidentiality Impact
COMPLETE
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
6.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
18.96%
Probability of exploitation in next 30 days
EPSS Percentile
97.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
ExploitDB: EDB-3302 · Feb 13, 2007
This CVE's current EPSS score of 0.1896 is in the 84th percentile among its peer group of 8,920 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

osvdb.org / 35764
exploit-db.com / exploits/3302