{"api_version":"1","generated_at":"2026-07-23T07:15:49+00:00","cve":"CVE-2007-2238","urls":{"html":"https://cve.report/CVE-2007-2238","api":"https://cve.report/api/cve/CVE-2007-2238.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-2238","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-2238"},"summary":{"title":"CVE-2007-2238","description":"Multiple stack-based buffer overflows in the Whale Client Components ActiveX control (WhlMgr.dll), as used in Microsoft Intelligent Application Gateway (IAG) before 3.7 SP2, allow remote attackers to execute arbitrary code via long arguments to the (1) CheckForUpdates or (2) UpdateComponents methods.","state":"PUBLISHED","assigner":"certcc","published_at":"2009-04-16 15:12:57","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2009/1061","name":"http://www.vupen.com/english/advisories/2009/1061","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/34725","name":"http://secunia.com/advisories/34725","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Whale IAG / Client Components ActiveX Control Buffer Overflows - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49888","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49888","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/34532","name":"http://www.securityfocus.com/bid/34532","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Microsoft IAG 2007 ActiveX Control Multiple Stack Based Buffer Overflow Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.kb.cert.org/vuls/id/789121","name":"http://www.kb.cert.org/vuls/id/789121","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"VU#789121 - Microsoft Whale Intelligent Application Gateway Whale Client Components ActiveX control stack buffer overflows","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-2238","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-2238","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"2238","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"intelligent_application_gateway_2007","cpe6":"*","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"2238","vulnerable":"1","versionEndIncluding":"3.7","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":"intelligent_application_gateway_2007","cpe6":"*","cpe7":"sp1","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T13:33:27.624Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"VU#789121","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/789121"},{"name":"ADV-2009-1061","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2009/1061"},{"name":"34725","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/34725"},{"name":"34532","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/34532"},{"name":"iag-activex-bo(49888)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49888"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-04-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple stack-based buffer overflows in the Whale Client Components ActiveX control (WhlMgr.dll), as used in Microsoft Intelligent Application Gateway (IAG) before 3.7 SP2, allow remote attackers to execute arbitrary code via long arguments to the (1) CheckForUpdates or (2) UpdateComponents methods."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"name":"VU#789121","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/789121"},{"name":"ADV-2009-1061","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2009/1061"},{"name":"34725","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/34725"},{"name":"34532","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/34532"},{"name":"iag-activex-bo(49888)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49888"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cert@cert.org","ID":"CVE-2007-2238","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple stack-based buffer overflows in the Whale Client Components ActiveX control (WhlMgr.dll), as used in Microsoft Intelligent Application Gateway (IAG) before 3.7 SP2, allow remote attackers to execute arbitrary code via long arguments to the (1) CheckForUpdates or (2) UpdateComponents methods."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"VU#789121","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/789121"},{"name":"ADV-2009-1061","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2009/1061"},{"name":"34725","refsource":"SECUNIA","url":"http://secunia.com/advisories/34725"},{"name":"34532","refsource":"BID","url":"http://www.securityfocus.com/bid/34532"},{"name":"iag-activex-bo(49888)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/49888"}]}}}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2007-2238","datePublished":"2009-04-16T15:00:00.000Z","dateReserved":"2007-04-25T00:00:00.000Z","dateUpdated":"2024-08-07T13:33:27.624Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-04-16 15:12:57","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:intelligent_application_gateway_2007:*:sp1:*:*:*:*:*:*","matchCriteriaId":"EADE9F62-25C2-42D3-AD6B-F42D5532C708"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:intelligent_application_gateway_2007:*:sp1:*:*:*:*:*:*","versionEndIncluding":"3.7","matchCriteriaId":"F6E439F6-4014-4019-A5B1-567B6D9C51B4"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"2238","Ordinal":"1","Title":"CVE-2007-2238","CVE":"CVE-2007-2238","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"2238","Ordinal":"1","NoteData":"Multiple stack-based buffer overflows in the Whale Client Components ActiveX control (WhlMgr.dll), as used in Microsoft Intelligent Application Gateway (IAG) before 3.7 SP2, allow remote attackers to execute arbitrary code via long arguments to the (1) CheckForUpdates or (2) UpdateComponents methods.","Type":"Description","Title":"CVE-2007-2238"},{"CveYear":"2007","CveId":"2238","Ordinal":"2","NoteData":"2009-04-16","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"2238","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}