VendorsIBMlotus_symphonyall versions
Vulnerabilities

IBM Lotus Symphony

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2011-2884
Multiple unspecified vulnerabilities in IBM Lotus Symphony 3 before FP3 have unknown impact and attack vectors, related to "critical security vulnerability issues."
Published 2011-07-27 · Modified
10.0EPSS 0.023
CVE-2012-0192
Multiple integer overflows in vclmi.dll in the visual class library module in IBM Lotus Symphony before 3.0.1 might allow remote attackers to execute arbitrary code via an embedded (1) JPEG or (2) PNG image object in a Symphony document that triggers a heap-based buffer overflow, as demonstrated by a .doc file.
Published 2012-01-23 · Modified
9.3EPSS 0.051
CVE-2010-5204
Multiple untrusted search path vulnerabilities in IBM Lotus Symphony 1.3.0 20090908.0900 allow local users to gain privileges via a Trojan horse (1) eclipse_1114.dll or (2) emser645mi.dll file in the current working directory, as demonstrated by a directory that contains a .odm, .odt, .otp, .stc, .stw, .sxg, or .sxw file. NOTE: some of these details are obtained from third party information.
Published 2012-09-06 · Modified
6.9EPSS 0.003
CVE-2011-2885
IBM Lotus Symphony 3 before FP3 allows remote attackers to cause a denial of service (application crash) via the sample .doc document that incorporates a user-defined toolbar.
Published 2011-07-27 · Modified
4.3EPSS 0.022
CVE-2011-2887
IBM Lotus Symphony 3 before FP3 on Linux allows remote attackers to cause a denial of service (application crash) via a certain sample document.
Published 2011-07-27 · Modified
4.3EPSS 0.022
CVE-2011-2888
IBM Lotus Symphony 3 before FP3 allows remote attackers to cause a denial of service (application hang) via complex graphics in a presentation.
Published 2011-07-27 · Modified
4.3EPSS 0.022
CVE-2011-2886
IBM Lotus Symphony 3 before FP3 allows remote attackers to cause a denial of service (application crash) via a .docx document with empty bullet styles for parent bullets.
Published 2011-07-27 · Modified
4.3EPSS 0.015
CVE-2011-2893
The DataPilot feature in IBM Lotus Symphony 3 before FP3 allows user-assisted remote attackers to cause a denial of service (application crash) via a large .xls spreadsheet with an invalid Value reference.
Published 2011-07-27 · Modified
4.3EPSS 0.015