Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2010-2709

CWE-119Buffer Overflow5 documents4 sources
Severity
9.3CRITICAL
EPSS
83.7%
top 0.71%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedAug 5
Latest updateMay 17

Description

Stack-based buffer overflow in webappmon.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via a long OvJavaLocale value in a cookie.

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-jx78-jgwx-p7fv: Stack-based buffer overflow in webappmon2022-05-17
CVEList
CVE-2010-2709: Stack-based buffer overflow in webappmon2010-08-05

💥Exploits & PoCs

2
Exploit-DB
HP Network Node Manager (NMM) - CGI 'webappmon.exe OvJavaLocale' Remote Buffer Overflow (Metasploit)2011-03-23
Exploit-DB
HP OpenView Network Node Manager (OV NNM) 7.53 - 'OvJavaLocale' Buffer Overflow2010-08-03