CVE-2008-3544
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 18%
from disclosure to weapon0 days
Published on NVDOct 13
1st PoCApr 7
exploitation probability
18%top 3% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Multiple stack-based buffer overflows in ovalarmsrv in HP OpenView Network Node Manager (OV NNM) 7.51, and possibly 7.01, 7.50, and 7.53, allow remote attackers to execute arbitrary code via a long (1) REQUEST_SEV_CHANGE (aka number 47), (2) REQUEST_SAVE_STATE (aka number 61), or (3) REQUEST_RESTORE_STATE (aka number 62) request to TCP port 2954.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/5396⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://aluigi.altervista.org/adv/closedview_old-adv.txthttp://downloads.securityfocus.com/vulnerabilities/exploits/28668.chttp://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01537275http://secunia.com/advisories/31688http://securityreason.com/securityalert/4397http://www.securityfocus.com/archive/1/490541http://www.securityfocus.com/bid/28668