Domino

Vendor:

First CVE: Jul 1, 2020 · Active for 6 years

22
Total CVEs
More Total CVEs than 95% of tracked products
5.5
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Domino over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 1, 2020
6 years ago
Most Recent CVE
Jul 8, 2024
750 days ago

CVE Severity & Scoring

Domino22 CVEs
All CVEs353,173 CVEs
MediumHighCritical
Attack Vector
Local5 (22.7%)
Network17 (77.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (90.9%)
High2 (9.1%)
Unknown0 (0.0%)
User Interaction
None14 (63.6%)
Unknown0 (0.0%)
Required8 (36.4%)
Privileges Required
Low3 (13.6%)
High0 (0.0%)
None19 (86.4%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A vulnerability in the MIME message handling of the Domino server (versions 9 and 10) could potentially be exploited by an unauthenticated attacker resulting in a stack buffer over
Dec 14, 20209.831NONO
HCL Domino is susceptible to a Buffer Overflow vulnerability in DXL due to improper validation of user input. A successful exploit could enable an attacker to crash Domino or execu
Dec 2, 20209.829NONO
HCL XPages applications are susceptible to a Cross Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker could exploit this vulnerability to perform actions in th
Nov 4, 20228.827NONO
HCL Domino is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the appli
Dec 19, 20227.826NONO
HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the applic
Dec 19, 20227.825NONO
HCL Domino is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the applic
Dec 19, 20227.825NONO
HCL Domino is affected by an Insufficient Access Control vulnerability. An authenticated attacker with local access to the system could exploit this vulnerability to attain escalat
May 19, 20227.825NONO
HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak
Aug 29, 20227.524NONO
HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as user
Aug 29, 20227.424NONO
A security vulnerability in HCL Domino could allow disclosure of sensitive configuration information. A remote unauthenticated attacker could exploit this vulnerability to obtain
Jul 8, 20247.523NONO

Exploit Exposure

Signals from CVEs in this product scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (22 CVEs).

Media Mentions

Signals from CVEs in this product scope (22 CVEs).

Top CNAs Publishing CVEs For Domino

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.0.197.30.6%00
9.067.50.5%00
14.026.50.4%00
12.0.215.30.3%00
12.0.137.00.5%00
12.056.40.4%00
11.0.166.40.5%00
11.0.026.41.1%00
11.066.70.5%00
10.0.196.50.9%00
10.0.025.80.5%00
10.037.10.4%00