CVE-2010-0919: Buffer Overflow

Published Mar 3, 2010
·
Updated

Stack-based buffer overflow in the Lotus Domino Web Access ActiveX control in IBM Lotus iNotes (aka Domino Web Access or DWA) 6.5, 7.0 before 7.0.4, 8.0, 8.0.2, and before 229.281 for Domino 8.0.2 FP4 allows remote attackers to execute arbitrary code via a long URL argument to an unspecified method, aka PRAD7JTNHJ.

Affected Software

55 affected components
IBM Domino Web Access=8.0.2
IBM Domino Web Access=7.0
IBM Domino Web Access=7.0.1
IBM Domino Web Access=7.0.3
IBM Domino Web Access=6.5
IBM Domino Web Access=7.0.2
IBM Domino Web Access=8.0
IBM Lotus iNotes<=229.271
IBM Lotus iNotes=229.011
IBM Lotus iNotes=229.021
IBM Lotus iNotes=229.031
IBM Lotus iNotes=229.041
IBM Lotus iNotes=229.051
IBM Lotus iNotes=229.061
IBM Lotus iNotes=229.101
IBM Lotus iNotes=229.111
IBM Lotus iNotes=229.131
IBM Lotus iNotes=229.141
IBM Lotus iNotes=229.151
IBM Lotus iNotes=229.161
IBM Lotus iNotes=229.171
IBM Lotus iNotes=229.181
IBM Lotus iNotes=229.191
IBM Lotus iNotes=229.201
IBM Lotus iNotes=229.211
IBM Lotus iNotes=229.221
IBM Lotus iNotes=229.231
IBM Lotus iNotes=229.241
IBM Lotus iNotes=229.251
IBM Lotus iNotes=229.261
IBM Lotus Domino=8.0.2.4
All of the following
Any of the following
IBM Lotus iNotes<=229.271
IBM Lotus iNotes=229.011
IBM Lotus iNotes=229.021
IBM Lotus iNotes=229.031
IBM Lotus iNotes=229.041
IBM Lotus iNotes=229.051
IBM Lotus iNotes=229.061
IBM Lotus iNotes=229.101
IBM Lotus iNotes=229.111
IBM Lotus iNotes=229.131
IBM Lotus iNotes=229.141
IBM Lotus iNotes=229.151
IBM Lotus iNotes=229.161
IBM Lotus iNotes=229.171
IBM Lotus iNotes=229.181
IBM Lotus iNotes=229.191
IBM Lotus iNotes=229.201
IBM Lotus iNotes=229.211
IBM Lotus iNotes=229.221
IBM Lotus iNotes=229.231
IBM Lotus iNotes=229.241
IBM Lotus iNotes=229.251
IBM Lotus iNotes=229.261
IBM Lotus Domino=8.0.2.4

Event History

Mar 3, 2010
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:30 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2010-0919?

CVE-2010-0919 is considered to have a high severity rating due to its potential for remote code execution.

2

How do I fix CVE-2010-0919?

To fix CVE-2010-0919, update your IBM Lotus iNotes or Domino Web Access to the latest recommended version.

3

What versions are affected by CVE-2010-0919?

CVE-2010-0919 affects IBM Lotus Domino Web Access versions 6.5, 7.0 before 7.0.4, and versions 8.0, 8.0.2 before 8.0.2 FP4.

4

What kind of attack does CVE-2010-0919 facilitate?

CVE-2010-0919 allows attackers to execute arbitrary code on the victim's system via a crafted long URL.

5

Is there a workaround for CVE-2010-0919?

While updating the software is the best solution, temporarily disabling ActiveX controls in your browser can mitigate risk associated with CVE-2010-0919.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203