Unrated severityNVD Advisory· Published Dec 27, 2007· Updated Apr 23, 2026
CVE-2007-4474
CVE-2007-4474
Description
Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, inotes6w.dll, dwa7.dll, and dwa7w.dll, in Domino 6.x and 7.x allow remote attackers to execute arbitrary code, as demonstrated by an overflow from a long General_ServerName property value when calling the InstallBrowserHelperDll function in the Upload Module in the dwa7.dwa7.1 control in dwa7w.dll 7.0.34.1.
Affected products
17cpe:2.3:a:ibm:domino_web_access:6.0:*:*:*:*:*:*:*+ 14 more
- cpe:2.3:a:ibm:domino_web_access:6.0:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:domino_web_access:6.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:domino_web_access:6.0.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:domino_web_access:6.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:domino_web_access:6.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:domino_web_access:6.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:domino_web_access:6.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:domino_web_access:6.5:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:domino_web_access:6.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:domino_web_access:6.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:domino_web_access:6.5.3:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:domino_web_access:6.5.4:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:domino_web_access:6.5.5:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:domino_web_access:7.0:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:domino_web_access:7.0.1:*:*:*:*:*:*:*
cpe:2.3:a:ibm:lotus_domino_web_access:7.0.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:ibm:lotus_domino_web_access:7.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:ibm:lotus_domino_web_access:7.0.34.1:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- lists.grok.org.uk/pipermail/full-disclosure/2007-December/059233.htmlnvdExploit
- www.securityfocus.com/bid/26972nvdExploit
- secunia.com/advisories/28184nvdVendor Advisory
- www.kb.cert.org/vuls/id/963889nvdUS Government Resource
- osvdb.org/40954nvd
- www.securitytracker.com/idnvd
- www.vupen.com/english/advisories/2007/4296nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/39175nvd
- www.exploit-db.com/exploits/4818nvd
- www.exploit-db.com/exploits/4820nvd
- www.exploit-db.com/exploits/5111nvd
News mentions
0No linked articles in our index yet.