CVE-2007-4474
Last modified
CVE-2007-4474 is a vulnerability of currently unknown severity. Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, inotes6w.dll, dwa7.dll, and dwa7w.dll, in Domino 6.x and 7.x allow remote attackers to execute arbitrary code, as demonstrated by an overflow from a long General_ServerName property value when calling the InstallBrowserHelperDll function in the Upload Module in the dwa7.dwa7.1 control in dwa7w.dll 7.0.34.1.. EPSS estimates a 44.18% chance of exploitation in the next 30 days.
Description
Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, inotes6w.dll, dwa7.dll, and dwa7w.dll, in Domino 6.x and 7.x allow remote attackers to execute arbitrary code, as demonstrated by an overflow from a long General_ServerName property value when calling the InstallBrowserHelperDll function in the Upload Module in the dwa7.dwa7.1 control in dwa7w.dll 7.0.34.1.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Domino Web Access | 6.0 |
| Ibm | Domino Web Access | 6.0.1 |
| Ibm | Domino Web Access | 6.0.1.1 |
| Ibm | Domino Web Access | 6.0.2 |
| Ibm | Domino Web Access | 6.0.3 |
| Ibm | Domino Web Access | 6.0.4 |
| Ibm | Domino Web Access | 6.0.5 |
| Ibm | Domino Web Access | 6.5 |
| Ibm | Domino Web Access | 6.5.1 |
| Ibm | Domino Web Access | 6.5.2 |
| Ibm | Domino Web Access | 6.5.3 |
| Ibm | Domino Web Access | 6.5.4 |
| Ibm | Domino Web Access | 6.5.5 |
| Ibm | Domino Web Access | 7.0 |
| Ibm | Domino Web Access | 7.0.1 |
| Ibm | Lotus Domino Web Access | 7.0.1 |
| Ibm | Lotus Domino Web Access | 7.0.34.1 |
References
- http://secunia.com/advisories/28184Vendor Advisory
- http://www.kb.cert.org/vuls/id/963889US Government Resource
- http://secunia.com/advisories/28184Vendor Advisory
- http://www.kb.cert.org/vuls/id/963889US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-4474?
How severe is CVE-2007-4474?
How do I fix CVE-2007-4474?
Are you affected by CVE-2007-4474?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
