CVE-2009-3849
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 74%
from disclosure to weapon336 days
Published on NVDDec 10
1st PoC+336d
metasploitDec 9
exploitation probability
74%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via (1) a long Template parameter to nnmRptConfig.exe, related to the strcat function; or (2) a long Oid parameter to snmp.exe.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/16780unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01950877http://marc.info/?l=bugtraq&m=126046355120442&w=2https://exchange.xforce.ibmcloud.com/vulnerabilities/54652https://exchange.xforce.ibmcloud.com/vulnerabilities/54654http://www.securityfocus.com/archive/1/508348/100/0/threadedhttp://www.securityfocus.com/archive/1/508349/100/0/threadedhttp://www.securityfocus.com/bid/37261http://www.securityfocus.com/bid/37298http://www.securityfocus.com/bid/37299http://zerodayinitiative.com/advisories/ZDI-09-095/http://zerodayinitiative.com/advisories/ZDI-09-097/