cbcvebase.

Hp Network Node Manager vulnerabilities

4 known vulnerabilities affecting hp/network_node_manager.

Total CVEs
4
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH2

Vulnerabilities

Page 1 of 1
CVE-2009-0920P2HIGHCVSS 7.5PoCv7.0.1v7.5.1+1 more2009-03-25
CVE-2009-0920 [HIGH] CVE-2009-0920: Stack-based buffer overflow in OvCgi/Toolbar.exe in HP OpenView Network Node Manager (OV NNM) 7.01, Stack-based buffer overflow in OvCgi/Toolbar.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long OvOSLocale cookie, a variant of CVE-2008-0067.
nvd
CVE-2010-0445P3CRITICALCVSS 10.0v8.10v8.11+2 more2010-02-11
CVE-2010-0445 [CRITICAL] CVE-2010-0445: Unspecified vulnerability in HP Network Node Manager (NNM) 8.10, 8.11, 8.12, and 8.13 allows remote Unspecified vulnerability in HP Network Node Manager (NNM) 8.10, 8.11, 8.12, and 8.13 allows remote attackers to execute arbitrary commands via unknown vectors.
nvd
CVE-2009-0921P3CRITICALCVSS 10.0v7.0.1v7.5.1+1 more2009-03-25
CVE-2009-0921 [CRITICAL] CWE-119 CVE-2009-0921: Multiple heap-based buffer overflows in OvCgi/Toolbar.exe in HP OpenView Network Node Manager (OV NN Multiple heap-based buffer overflows in OvCgi/Toolbar.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote attackers to execute arbitrary code via (1) a long OvAcceptLang cookie, which triggers the error in ov.dll and ovwww.dll, or (2) a long Accept-Language HTTP header, which triggers the error in ovwww.dll or libovwww
nvd
CVE-2007-0819P4HIGHCVSS 7.2v7.52007-02-08
CVE-2007-0819 [HIGH] CVE-2007-0819: HP Network Node Manager (NNM) Remote Console 7.50, 7.51, and 7.53 assigns Everyone Full Control perm HP Network Node Manager (NNM) Remote Console 7.50, 7.51, and 7.53 assigns Everyone Full Control permission for the %PROGRAMFILES%\HP OpenView directory tree, which allows local users to gain privileges via a Trojan horse executable file or ActiveX component, or a modified bin\ovtrcsvc.exe for the HP Open View Shared Trace Service.
nvd
Hp Network Node Manager vulnerabilities | cvebase