Integer overflow in the DWA9W ActiveX control in iNotes in IBM Domino 9.0 before IF3 allows remote attackers to execute arbitrary code via a crafted web page, aka SPR PTHN97XHFW.
https://exchange.xforce.ibmcloud.com/vulnerabilities/84381
https://euvd.enisa.europa.eu/vulnerability/EUVD-2013-2966