CVE-2007-4474

Scores

EPSS

0.873high87.3%
0%20%40%60%80%100%

Percentile: 87.3%

CVSS

9.3critical2.0
0246810

CVSS Score: 9.3/10

All CVSS Scores

CVSS 2.0
9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Description

Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, inotes6w.dll, dwa7.dll, and dwa7w.dll, in Domino 6.x and 7.x allow remote attackers to execute arbitrary code, as demonstrated by an overflow from a long General_ServerName property value when calling the InstallBrowserHelperDll function in the Upload Module in the dwa7.dwa7.1 control in dwa7w.dll 7.0.34.1.

Scaner-VS 7 — a modern vulnerability management solution

Uses this database for vulnerability detection. High-speed search, cross-platform, advanced configuration audit, and flexible filtering. Suitable for organizations of any size.
Learn more about Scaner-VS 7

Sources

nvd

CWEs

CWE-119

Exploits

Exploit ID: 16502

Source: exploitdb

URL: https://www.exploit-db.com/exploits/16502

Exploit ID: 4818

Source: exploitdb

URL: https://www.exploit-db.com/exploits/4818

Exploit ID: 4820

Source: exploitdb

URL: https://www.exploit-db.com/exploits/4820

Exploit ID: 5111

Source: exploitdb

URL: https://www.exploit-db.com/exploits/5111

Vulnerable Software (2)

Type: Configuration

Vendor: *

Product: domino_web_access

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:ibm:domino_web_access:6.0:*:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:ibm:domino_web_access:6.0.1:*:*:*:*:*...

Source: nvd

Type: Configuration

Vendor: *

Product: lotus_domino_web_access

Operating System: * * *

Trait:
{  "cpe_match": [    {      "cpe23uri": "cpe:2.3:a:ibm:domino_web_access:6.0:*:*:*:*:*:*:*",      "vulnerable": true    },    {      "cpe23uri": "cpe:2.3:a:ibm:domino_web_access:6.0.1:*:*:*:*:*...

Source: nvd

End of list