CVE-2009-0714 EXPLOIT
7.2
HIGH · CVSS 2.0 · EPSS 51.6% (pctl 99)
Patch early
A public exploit exists.
Description
Unspecified vulnerability in the dpwinsup module (dpwinsup.dll) for dpwingad (dpwingad.exe) in HP Data Protector Express and Express SSE 3.x before build 47065, and Express and Express SSE 4.x before build 46537, allows remote attackers to cause a denial of service (application crash) or read portions of memory via one or more crafted packets.
Scoring
| CVSS | 7.2 (HIGH, v2.0) |
|---|---|
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 51.61% — more likely to be exploited than 99% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-05-14 |
| Last modified | 2026-06-16 |
Affected (5)
| Vendor | Product |
|---|---|
| hp | data protector express |
| microsoft | windows |
| novell | netware |
| redhat | linux |
| suse | suse linux |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | HP Data Protector 4.00-SP1b43064 - Remote Memory Leak/Denial of Service | 2009-06-23 |
| exploit-db | HP Data Protector 4.00-SP1b43064 - Remote Memory Leak/Denial of Service (Metasploit) | 2009-06-23 |
References
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01697543
- http://ivizsecurity.com/security-advisory-iviz-sr-09002.html
- http://secunia.com/advisories/35084
- http://www.securityfocus.com/bid/34955
- http://www.securitytracker.com/id?1022220
- http://www.vupen.com/english/advisories/2009/1309
- https://www.exploit-db.com/exploits/9006
- https://www.exploit-db.com/exploits/9007
- http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01697543
- http://ivizsecurity.com/security-advisory-iviz-sr-09002.html
- http://secunia.com/advisories/35084
- http://www.securityfocus.com/bid/34955
- http://www.securitytracker.com/id?1022220
- http://www.vupen.com/english/advisories/2009/1309
- https://www.exploit-db.com/exploits/9006
- https://www.exploit-db.com/exploits/9007
→ the Explorer · watch your stack · NVD