← Vulnerability feed

Vulnerability record · CVE-2003-0178 · published 2 April 2003

CVE-2003-0178: Ibm lotus domino web server vulnerability

Ibm · Lotus Domino Web Server

Multiple buffer overflows in Lotus Domino Web Server before 6.0.1 allow remote attackers to cause a denial of service or execute arbitrary code via (1) the s_ViewName option in the PresetFields parameter for iNotes, (2) the Foldername option in the PresetFields parameter for iNotes, or (3) a long Host header, which is inserted into a long Location header and used during a redirect operation.

10.0 CVSS 2.0 High EPSS 15% · top 3.4%
10.0CVSS 2.0 base score
15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
40References
16 Jun 2026Last modified by NVD

Description

Multiple buffer overflows in Lotus Domino Web Server before 6.0.1 allow remote attackers to cause a denial of service or execute arbitrary code via (1) the s_ViewName option in the PresetFields parameter for iNotes, (2) the Foldername option in the PresetFields parameter for iNotes, or (3) a long Host header, which is inserted into a long Location header and used during a redirect operation.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0080.html
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0081.html
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0082.html
http://marc.info/?l=bugtraq&m=104550063431461&w=2
http://marc.info/?l=bugtraq&m=104550063431463&w=2
http://marc.info/?l=bugtraq&m=104550335103136&w=2
http://marc.info/?l=ntbugtraq&m=104558777331345&w=2
http://marc.info/?l=ntbugtraq&m=104558777531350&w=2
http://marc.info/?l=ntbugtraq&m=104558778331387&w=2
http://www.cert.org/advisories/CA-2003-11.html US Government Resource
http://www.ciac.org/ciac/bulletins/n-065.shtml
http://www.kb.cert.org/vuls/id/206361 US Government Resource
http://www.kb.cert.org/vuls/id/542873 US Government Resource
http://www.kb.cert.org/vuls/id/772817 PatchThird Party AdvisoryUS Government Resource
http://www.nextgenss.com/advisories/lotus-hostlocbo.txt
http://www.nextgenss.com/advisories/lotus-inotesoflow.txt
http://www.securityfocus.com/bid/6870
http://www.securityfocus.com/bid/6871 PatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/11336
https://exchange.xforce.ibmcloud.com/vulnerabilities/11337
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0080.html
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0081.html
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0082.html
http://marc.info/?l=bugtraq&m=104550063431461&w=2
http://marc.info/?l=bugtraq&m=104550063431463&w=2
http://marc.info/?l=bugtraq&m=104550335103136&w=2
http://marc.info/?l=ntbugtraq&m=104558777331345&w=2
http://marc.info/?l=ntbugtraq&m=104558777531350&w=2
http://marc.info/?l=ntbugtraq&m=104558778331387&w=2
http://www.cert.org/advisories/CA-2003-11.html US Government Resource
http://www.ciac.org/ciac/bulletins/n-065.shtml
http://www.kb.cert.org/vuls/id/206361 US Government Resource
http://www.kb.cert.org/vuls/id/542873 US Government Resource
http://www.kb.cert.org/vuls/id/772817 PatchThird Party AdvisoryUS Government Resource
http://www.nextgenss.com/advisories/lotus-hostlocbo.txt
http://www.nextgenss.com/advisories/lotus-inotesoflow.txt
http://www.securityfocus.com/bid/6870
http://www.securityfocus.com/bid/6871 PatchVendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/11336
https://exchange.xforce.ibmcloud.com/vulnerabilities/11337

Track CVE-2003-0178 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2003-0178), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.