CVE-2010-1961 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 67.3% (pctl 99)
Patch early
A public exploit exists.
Description
Buffer overflow in ovutil.dll in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unspecified variables to jovgraph.exe, which are not properly handled in a call to the sprintf function.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 67.32% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2010-06-10 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| hp | openview network node manager |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | HP OpenView Network Node Manager (OV NNM) - 'ovwebsnmpsrv.exe ovutil' Remote Buffer Overflow (Metasploit) | 2011-03-23 |
References
- http://marc.info/?l=bugtraq&m=127602909915281&w=2
- http://secunia.com/advisories/40101
- http://www.securityfocus.com/archive/1/511731/100/0/threaded
- http://www.securityfocus.com/bid/40638
- http://www.securitytracker.com/id?1024071
- http://www.zerodayinitiative.com/advisories/ZDI-10-106/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/59250
- http://marc.info/?l=bugtraq&m=127602909915281&w=2
- http://secunia.com/advisories/40101
- http://www.securityfocus.com/archive/1/511731/100/0/threaded
- http://www.securityfocus.com/bid/40638
- http://www.securitytracker.com/id?1024071
- http://www.zerodayinitiative.com/advisories/ZDI-10-106/
- https://exchange.xforce.ibmcloud.com/vulnerabilities/59250
→ the Explorer · watch your stack · NVD