CVE-2009-1286
Last modified
CVE-2009-1286 is a vulnerability of currently unknown severity. The IMAP task in the server in IBM Lotus Domino 8.0.2 before FP1 IF1 and 8.5 before IF3 allows remote attackers to cause a denial of service (daemon crash) via a MIME e-mail message with RFC822 attachments (aka blobs) containing malformed root entities.. EPSS estimates a 1.84% chance of exploitation in the next 30 days.
Description
The IMAP task in the server in IBM Lotus Domino 8.0.2 before FP1 IF1 and 8.5 before IF3 allows remote attackers to cause a denial of service (daemon crash) via a MIME e-mail message with RFC822 attachments (aka blobs) containing malformed root entities.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Lotus Domino | 8.0 |
| Ibm | Lotus Domino | 8.0.1 |
| Ibm | Lotus Domino | 8.0.2 |
| Ibm | Lotus Domino | 8.0.2.1 |
References
- http://secunia.com/advisories/34657Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21379915Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2009/0986Vendor Advisory
- http://secunia.com/advisories/34657Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg21379915Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2009/0986Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2009-1286?
How severe is CVE-2009-1286?
How do I fix CVE-2009-1286?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2009
- CVE-2009-1280Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2009-1281Cross-site scripting (XSS) vulnerability in glFusion before …
- CVE-2009-1282SQL injection vulnerability in private/system/lib-session.ph…
- CVE-2009-1283glFusion before 1.1.3 performs authentication with a user-pr…
- CVE-2009-1284Buffer overflow in BibTeX 0.99 allows context-dependent atta…
- CVE-2009-1285Static code injection vulnerability in the getConfigFile fun…
- CVE-2009-1287Cross-site scripting (XSS) vulnerability in Cisco Subscriber…
- CVE-2009-1288Multiple cross-site scripting (XSS) vulnerabilities in the A…
- CVE-2009-1289private/login.ssi in the Advanced Management Module (AMM) on…
- CVE-2009-1290Multiple cross-site request forgery (CSRF) vulnerabilities i…
- CVE-2009-1291Stack-based buffer overflow in TIBCO SmartSockets before 6.8…
- CVE-2009-1292UCM-CQ in IBM Rational ClearCase 7.0.0.x before 7.0.0.5, 7.0…
Are you affected by CVE-2009-1286?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
