CVE-2009-3840
published 2009-11-19CVE-2009-3840: The embedded database engine service (aka ovdbrun.exe) in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to cause a denial of…
PriorityP431medium5CVSS 2.0
AVNACLAuNCNINAP
EXPLOIT
EPSS
9.34%
94.8th percentile
The embedded database engine service (aka ovdbrun.exe) in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to cause a denial of service (daemon crash) via an invalid Error Code field in a packet.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hp | openview_network_node_manager | — | — |
| hp | openview_network_node_manager | — | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
IBM SolidDB - Invalid Error Code
exploitdb·2009-11-18·CVSS 5.0
CVE-2009-3840 [MEDIUM] IBM SolidDB - Invalid Error Code
IBM SolidDB - Invalid Error Code
---
1. Advisory Information
Title: IBM SolidDB invalid error code vulnerability
Advisory Id: CORE-2009-1027
Advisory URL: http://www.coresecurity.com/content/ibm-soliddb-errorcode-dos
Date published: 2009-11-18
Date of last update: 2009-11-18
Vendors contacted: IBM
Release mode: Forced release
2. Vulnerability Information
Class: External Initialization of Trusted Variables [CWE-454]
Impact: Denial of Service
Remotely Exploitable: Yes
Locally Exploitable: No
Bugtraq ID: N/A
CVE Name: CVE-2009-3840
3. Vulnerability Description
SolidDB is an in-memory relational database from IBM with over 3,000,000 deployments [1]. It is used as an embedded database by independent software vendors of enterprise applications, telecommunications and embedded software and s
Exploit-DB
HP OpenView Network Node Manager (OV NNM) 7.53 - Invalid DB Error Code
exploitdb·2009-11-17·CVSS 5.0
CVE-2009-3840 [MEDIUM] HP OpenView Network Node Manager (OV NNM) 7.53 - Invalid DB Error Code
HP OpenView Network Node Manager (OV NNM) 7.53 - Invalid DB Error Code
---
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Core Security Technologies - CoreLabs Advisory
http://www.coresecurity.com/corelabs/
HP Openview NNM 7.53 Invalid DB Error Code vulnerability
1. *Advisory Information*
Title: HP Openview NNM 7.53 Invalid DB Error Code vulnerability
Advisory Id: CORE-2009-0814
Advisory URL:
http://www.coresecurity.com/content/openview_nnm_internaldb_dos
Date published: 2009-11-17
Date of last update: 2009-11-17
Vendors contacted: HP
Release mode: Coordinated release
2. *Vulnerability Information*
Class: External Initialization of Trusted Variables [CWE-454]
Impact: Denial of Service
Remotely Exploitable: Yes
Locally Exploitable: No
Bugtraq ID: N/A
CVE Name: CVE-2009-3840
3. *V
No writeups or analysis indexed.
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01926980http://osvdb.org/60200http://seclists.org/fulldisclosure/2009/Nov/199http://www.coresecurity.com/content/openview_nnm_internaldb_doshttp://www.securityfocus.com/bid/37046http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01926980http://osvdb.org/60200http://seclists.org/fulldisclosure/2009/Nov/199http://www.coresecurity.com/content/openview_nnm_internaldb_doshttp://www.securityfocus.com/bid/37046
2009-11-19
Published