CVE-2007-3872 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 30.3% (pctl 98)
Patch early
A public exploit exists.
Description
Multiple stack-based buffer overflows in the Shared Trace Service (OVTrace) service for HP OpenView Operations A.07.50 for Windows, and possibly earlier versions, allow remote attackers to execute arbitrary code via certain crafted requests.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 30.28% — more likely to be exploited than 98% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-08-09 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| hp | openview operations |
| hp | shared trace service |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | HP OpenView - Operations OVTrace Buffer Overflow (Metasploit) | 2010-06-22 |
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01106515
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01109171
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01109584
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01109617
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01110576
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01110627
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01111851
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01112038
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01114023
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01114156
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01115068
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=574
- http://secunia.com/advisories/26394
- http://www.securityfocus.com/bid/25255
- http://www.securitytracker.com/id?1018548
- http://www.vupen.com/english/advisories/2007/2841
- https://exchange.xforce.ibmcloud.com/vulnerabilities/35928
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01106515
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01109171
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01109584
→ the Explorer · watch your stack · NVD