CVE-2010-2709
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 42%
from disclosure to weapon0 days
Published on NVDAug 5
1st PoCAug 3
metasploitAug 3
exploitation probability
42%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Stack-based buffer overflow in webappmon.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long OvJavaLocale value in a cookie.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencewww.exploit-db.com/exploits/14547unverifiedexploitdbwww.exploit-db.com/exploits/17029unverifiedexploitdbwww.exploit-db.com/exploits/14547unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://seclists.org/bugtraq/2010/Aug/21http://securityreason.com/securityalert/8150http://securitytracker.com/id?1024274https://exchange.xforce.ibmcloud.com/vulnerabilities/60880http://www.coresecurity.com/content/hp-nnm-ovjavalocale-buffer-overflowhttp://www.exploit-db.com/exploits/14547http://www.securityfocus.com/bid/42154