Back

CVE-2004-0480

Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to execute arbitrary code via a notes: URI that uses a UNC network share pathname to provide an alternate notes.ini configuration file to notes.exe.

Published: Dec 6, 2004 Modified: Jun 16, 2026
CWE-88

CVSS Metrics

Affected Products (2)

Vendor Product Version
ibm lotus_notes 6.0.3
ibm lotus_notes 6.5

GitHub Security Advisory GHSA-gv89-cmj2-j2r6

Argument injection vulnerability in IBM Lotus Notes 6.0.3 and 6.5 allows remote attackers to...

References (10)

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 8.65%

Top 5% most likely to be exploited

Threat Score 42.6 / 100

Data Sources

NVD EPSS GitHub