CVE-2007-6204

critical

Description

Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allow remote attackers to execute arbitrary code via unspecified long arguments to (1) ovlogin.exe, (2) OpenView5.exe, (3) snmpviewer.exe, and (4) webappmon.exe, as demonstrated via a long Action parameter to OpenView5.exe.

References

https://www.exploit-db.com/exploits/4724

https://exchange.xforce.ibmcloud.com/vulnerabilities/38892

http://www.zerodayinitiative.com/advisories/ZDI-07-071.html

http://www.vupen.com/english/advisories/2007/4111

http://www.securitytracker.com/id?1019055

http://www.securityfocus.com/archive/1/484704/100/0/threaded

http://securityreason.com/securityalert/3441

http://secunia.com/advisories/27964

http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01188923

Details

Source: Mitre, NVD

Published: 2007-12-13

Updated: 2018-10-15

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical