Lotus's vulnerability footprint centers on its Domino messaging and collaboration server platform, a long-lived enterprise product family that has accumulated disclosures spanning multiple major versions and deployment contexts. The vendor's exposure recurs through information-disclosure and data-exposure weakness classes, reflecting the sensitive nature of mail and directory data resident on these systems and the attack surface presented by their administrative interfaces and protocol handlers. While the absolute severity profile remains modest, vulnerabilities affecting Domino have an elevated tendency to attract public exploit code, making timely patching operationally important despite lower critical-severity prevalence. Defenders should maintain inventory of Domino deployments by version and treat disclosures in this product line as requiring prompt evaluation; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lotus over time
Signals from CVEs in this vendor scope (31 CVEs).
31 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-0846HIGH Lotus Domino 5.x allows remote attackers to read files or execute arbitrary code by requesting the ReplicaID of the Web Administrator template file (webadmin.ntf). | Dec 6, 2001 | 10.0 | 46 | NO | NO |
CVE-2000-1046HIGH Multiple buffer overflows in the ESMTP service of Lotus Domino 5.0.2c and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via long ( | Dec 11, 2000 | 10.0 | 37 | NO | YES |
CVE-2001-0009MEDIUM Directory traversal vulnerability in Lotus Domino 5.0.5 web server allows remote attackers to read arbitrary files via a .. attack. | Feb 12, 2001 | 5.0 | 32 | NO | YES |
CVE-2000-1047HIGH Buffer overflow in SMTP service of Lotus Domino 5.0.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long ENVID keyw | Dec 11, 2000 | 10.0 | 26 | NO | NO |
CVE-2001-0130HIGH Buffer overflow in HTML parser of the Lotus R5 Domino Server before 5.06, and Domino Client before 5.05, allows remote attackers to cause a denial of service and possibly execute a | Mar 12, 2001 | 10.0 | 25 | NO | NO |
CVE-2000-0452MEDIUM Buffer overflow in the ESMTP service of Lotus Domino Server 5.0.1 allows remote attackers to cause a denial of service via a long MAIL FROM command. | May 18, 2000 | 5.0 | 25 | NO | YES |
CVE-2002-2191MEDIUM Lotus Domino 5.0.9a and earlier, even when configured with the 'DominoNoBanner=1' option, allows remote attackers to obtain potential sensitive information such as the version via | Dec 31, 2002 | 5.0 | 23 | NO | YES |
CVE-2011-0290MEDIUM The BlackBerry Collaboration Service in Research In Motion (RIM) BlackBerry Enterprise Server (BES) 5.0.3 through MR4 for Microsoft Exchange and Lotus Domino allows remote authenti | Oct 21, 2011 | 6.5 | 21 | NO | NO |
CVE-2002-0407MEDIUM htcgibin.exe in Lotus Domino server 5.0.9a and earlier allows remote attackers to determine the physical pathname for the server via requests that contain certain MS-DOS device nam | Jul 26, 2002 | 5.0 | 20 | NO | NO |
CVE-2002-0245HIGH Lotus Domino server 5.0.8 with NoBanner enabled allows remote attackers to (1) determine the physical path of the server via a request for a nonexistent file with a .pl (Perl) exte | May 29, 2002 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (31 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lotus.
Media articles that mention a CVE ID that affects a product developed by Lotus — matched by CVE ID, not by vendor name.