CVE-2010-0919: Buffer Overflow
Stack-based buffer overflow in the Lotus Domino Web Access ActiveX control in IBM Lotus iNotes (aka Domino Web Access or DWA) 6.5, 7.0 before 7.0.4, 8.0, 8.0.2, and before 229.281 for Domino 8.0.2 FP4 allows remote attackers to execute arbitrary code via a long URL argument to an unspecified method, aka PRAD7JTNHJ.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0919?
CVE-2010-0919 is considered to have a high severity rating due to its potential for remote code execution.
How do I fix CVE-2010-0919?
To fix CVE-2010-0919, update your IBM Lotus iNotes or Domino Web Access to the latest recommended version.
What versions are affected by CVE-2010-0919?
CVE-2010-0919 affects IBM Lotus Domino Web Access versions 6.5, 7.0 before 7.0.4, and versions 8.0, 8.0.2 before 8.0.2 FP4.
What kind of attack does CVE-2010-0919 facilitate?
CVE-2010-0919 allows attackers to execute arbitrary code on the victim's system via a crafted long URL.
Is there a workaround for CVE-2010-0919?
While updating the software is the best solution, temporarily disabling ActiveX controls in your browser can mitigate risk associated with CVE-2010-0919.