CVE-2009-3977
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
Multiple buffer overflows in a certain ActiveX control in ActiveDom.ocx in HP OpenView Network Node Manager (OV NNM) 7.53 might allow remote attackers to cause a denial of service (memory corruption) or have unspecified other impact via a long string argument to the (1) DisplayName, (2) AddGroup, (3) InstallComponent, or (4) Subscribe method. NOTE: this issue is not a vulnerability in many environments, because the control is not marked as safe for scripting and would not execute with default Internet Explorer settings.
Múltiples desbordamientos de búfer en distintos controles ActiveX en ActiveDom.ocx en HP OpenView Network Node Manager (OV NNM) v7.53, podrían permitir a atacantes remotos provocar una denegación de servicio (corrupción de memoria) o tener otro impacto a través de una cadena con un argumento largo en los métodos 1) DisplayName, (2) AddGroup, (3) InstallComponent, o(4) Subscribe. NOTA: esta cuestión no es una vulnerabilidad en determinados entornos ya que el control no está marcado como "seguro" para la ejecución de secuencias de comandos y podría no ejecutarse con las opciones por defecto en Internet Explorer.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2009-11-18 CVE Reserved
- 2009-11-19 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/54377 | Vdb Entry |
URL | Date | SRC |
---|---|---|
http://seclists.org/fulldisclosure/2009/Nov/199 | 2024-08-07 | |
http://www.coresecurity.com/content/openview_nnm_internaldb_dos | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Hp Search vendor "Hp" | Openview Network Node Manager Search vendor "Hp" for product "Openview Network Node Manager" | 7.53 Search vendor "Hp" for product "Openview Network Node Manager" and version "7.53" | - |
Affected
|