IBM Lotus Domino Web Access 7.0.1

CPE Details

IBM Lotus Domino Web Access 7.0.1
7.0.1
2007-08-23
19h16 +00:00
2007-09-14
15h36 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:ibm:lotus_domino_web_access:7.0.1:*:*:*:*:*:*:*

Informations

Vendor

ibm

Product

lotus_domino_web_access

Version

7.0.1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2007-4474 2007-12-27 21h00 +00:00 Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, inotes6w.dll, dwa7.dll, and dwa7w.dll, in Domino 6.x and 7.x allow remote attackers to execute arbitrary code, as demonstrated by an overflow from a long General_ServerName property value when calling the InstallBrowserHelperDll function in the Upload Module in the dwa7.dwa7.1 control in dwa7w.dll 7.0.34.1.
9.3
CVE-2006-4763 2006-09-13 21h00 +00:00 IBM Lotus Domino Web Access (DWA) 7.0.1 does not expire a client's Lightweight Third-Party Authentication token (LtpaToken) upon logout, which allows remote attackers to obtain a user's privileges by intercepting the LtpaToken cookie.
7.5