peter bassill · operator
$ cve CVE-2007-4474 JSON

CVE-2007-4474 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 44.2% (pctl 99)

Patch early

A public exploit exists.

Description

Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, inotes6w.dll, dwa7.dll, and dwa7w.dll, in Domino 6.x and 7.x allow remote attackers to execute arbitrary code, as demonstrated by an overflow from a long General_ServerName property value when calling the InstallBrowserHelperDll function in the Upload Module in the dwa7.dwa7.1 control in dwa7w.dll 7.0.34.1.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS44.18% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2007-12-27
Last modified2026-06-16

Affected (2)

VendorProduct
ibmdomino web access
ibmlotus domino web access

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD