VYPR
Unrated severityNVD Advisory· Published Jan 9, 2006· Updated Apr 16, 2026

CVE-2006-0120

CVE-2006-0120

Description

Multiple unspecified vulnerabilities in IBM Lotus Notes and Domino Server before 6.5.5 allow attackers to cause a denial of service (application crash) via multiple vectors, involving (1) a malformed message sent to an "Out Of Office" agent (SPR LPEE6DMQWJ), (2) the compact command (RTIN5U2SAJ), (3) malformed bitmap images (MYAA6FH5HW), (4) the "Delete Attachment" action (YPHG6844LD), (5) parsing certificates from a remote Certificate Table (AELE6DZFJW), and (6) creating a SSL key ring with the Domino Administration client (NSUA4FQPTN).

Affected products

14
  • IBM/Lotus Domino7 versions
    cpe:2.3:a:ibm:lotus_domino:6.5.0:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:ibm:lotus_domino:6.5.0:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:lotus_domino:6.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:lotus_domino:6.5.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:lotus_domino:6.5.3:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:lotus_domino:6.5.4:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:lotus_domino:6.5.4:*:fp1:*:*:*:*:*
    • cpe:2.3:a:ibm:lotus_domino:6.5.4:*:fp2:*:*:*:*:*
  • cpe:2.3:a:ibm:lotus_domino_enterprise_server:6.5.2:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:ibm:lotus_domino_enterprise_server:6.5.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:lotus_domino_enterprise_server:6.5.4:*:*:*:*:*:*:*
  • IBM/Lotus Notes5 versions
    cpe:2.3:a:ibm:lotus_notes:6.5:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:ibm:lotus_notes:6.5:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:lotus_notes:6.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:lotus_notes:6.5.2:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:lotus_notes:6.5.3:*:*:*:*:*:*:*
    • cpe:2.3:a:ibm:lotus_notes:6.5.4:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

17

News mentions

0

No linked articles in our index yet.