CVE-2007-2280 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 60.3% (pctl 99)
Patch early
A public exploit exists.
Description
Stack-based buffer overflow in OmniInet.exe (aka the backup client service daemon) in the Application Recovery Manager component in HP OpenView Storage Data Protector 5.50 and 6.0 allows remote attackers to execute arbitrary code via an MSG_PROTOCOL command with long arguments, a different vulnerability than CVE-2009-3844.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 60.29% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-12-18 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| hp | openview storage data protector |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | HP - 'OmniInet.exe' MSG_PROTOCOL Buffer Overflow (Metasploit) (2) | 2010-09-20 |
References
- http://marc.info/?l=bugtraq&m=126106261622540&w=2
- http://securitytracker.com/id?1023361
- http://www.securityfocus.com/bid/37396
- http://www.vupen.com/english/advisories/2009/3594
- http://www.zerodayinitiative.com/advisories/ZDI-09-099/
- http://marc.info/?l=bugtraq&m=126106261622540&w=2
- http://securitytracker.com/id?1023361
- http://www.securityfocus.com/bid/37396
- http://www.vupen.com/english/advisories/2009/3594
- http://www.zerodayinitiative.com/advisories/ZDI-09-099/
→ the Explorer · watch your stack · NVD