Multiple vulnerabilities are found in IBM Lotus Notes related to Apache Xerces-C XML Parser library. These vulnerabilities are caused by a stack-based buffer overflow and improper bounds checking during processing and error reporting. A remote attacker could exploit the vulnerabilities by enticing a user to open a specially crafted input documents.
Depending on the vulnerability exploited, a successful attack could lead to arbitrary code execution or a denial-of-service condition.
The vendor has released a fix to address the issues and it can be downloaded at the following URL:
https://www-01.ibm.com/support/docview.wss?uid=swg21984073
https://www-01.ibm.com/support/docview.wss?uid=swg21987066
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0729
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-4463