CVE-2007-6204
Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allow remote attackers to execute arbitrary code via unspecified long arguments to (1) ovlogin.exe, (2) OpenView5.exe, (3) snmpviewer.exe, and (4)…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 69.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allow remote attackers to execute arbitrary code via unspecified long arguments to (1) ovlogin.exe, (2) OpenView5.exe, (3) snmpviewer.exe, and (4) webappmon.exe, as demonstrated via a long Action parameter to OpenView5.exe.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 69.61% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- hp/openview network node manager
- Source
- cve@mitre.org
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01188923
- http://secunia.com/advisories/27964Vendor Advisory
- http://securityreason.com/securityalert/3441
- http://www.securityfocus.com/archive/1/484704/100/0/threaded
- http://www.securityfocus.com/bid/26741Exploit, Patch
- http://www.securitytracker.com/id?1019055
- http://www.vupen.com/english/advisories/2007/4111Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-07-071.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38892
- https://www.exploit-db.com/exploits/4724
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01188923
- http://secunia.com/advisories/27964Vendor Advisory
- http://securityreason.com/securityalert/3441
- http://www.securityfocus.com/archive/1/484704/100/0/threaded
- http://www.securityfocus.com/bid/26741Exploit, Patch
- http://www.securitytracker.com/id?1019055
- http://www.vupen.com/english/advisories/2007/4111Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-07-071.html
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38892
- https://www.exploit-db.com/exploits/4724
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.