Lucene search

K
cveMitreCVE-2009-0921
HistoryMar 25, 2009 - 1:30 a.m.

CVE-2009-0921

2009-03-2501:30:00
CWE-119
mitre
web.nvd.nist.gov
38
cve-2009-0921
buffer overflows
hp openview network node manager
ov nnm
security vulnerability
remote code execution
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.056

Percentile

93.3%

Multiple heap-based buffer overflows in OvCgi/Toolbar.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via (1) a long OvAcceptLang cookie, which triggers the error in ov.dll and ovwww.dll, or (2) a long Accept-Language HTTP header, which triggers the error in ovwww.dll or libovwww.so.4.

Affected configurations

Nvd
Node
hpnetwork_node_managerMatch7.0.1
OR
hpnetwork_node_managerMatch7.5.1
OR
hpnetwork_node_managerMatch7.5.3
VendorProductVersionCPE
hpnetwork_node_manager7.0.1cpe:2.3:a:hp:network_node_manager:7.0.1:*:*:*:*:*:*:*
hpnetwork_node_manager7.5.1cpe:2.3:a:hp:network_node_manager:7.5.1:*:*:*:*:*:*:*
hpnetwork_node_manager7.5.3cpe:2.3:a:hp:network_node_manager:7.5.3:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.056

Percentile

93.3%