CVE-2007-4474

N/A Unknown
Published: December 27, 2007 Modified: April 23, 2026
View on NVD

Description

Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, inotes6w.dll, dwa7.dll, and dwa7w.dll, in Domino 6.x and 7.x allow remote attackers to execute arbitrary code, as demonstrated by an overflow from a long General_ServerName property value when calling the InstallBrowserHelperDll function in the Upload Module in the dwa7.dwa7.1 control in dwa7w.dll 7.0.34.1.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://osvdb.org/40954
Source: cret@cert.org
http://secunia.com/advisories/28184
Source: cret@cert.org
Vendor Advisory
http://www.kb.cert.org/vuls/id/963889
Source: cret@cert.org
US Government Resource
http://www.securityfocus.com/bid/26972
Source: cret@cert.org
Exploit
http://lists.grok.org.uk/pipermail/full-disclosure/2007-December/059233.html
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://osvdb.org/40954
Source: af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/28184
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
http://www.kb.cert.org/vuls/id/963889
Source: af854a3a-2127-422b-91ae-364da2661108
US Government Resource
http://www.securityfocus.com/bid/26972
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
http://www.securitytracker.com/id?1019138
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/4296
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/39175
Source: af854a3a-2127-422b-91ae-364da2661108
https://www.exploit-db.com/exploits/4818
Source: af854a3a-2127-422b-91ae-364da2661108
https://www.exploit-db.com/exploits/4820
Source: af854a3a-2127-422b-91ae-364da2661108
https://www.exploit-db.com/exploits/5111
Source: af854a3a-2127-422b-91ae-364da2661108

22 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
44.2%
99th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

ibm