CVE-2008-1842

Integer signedness error in ovspmd.exe in HP OpenView Network Node Manager (OV NNM) 8.01, and 7.53 and earlier, allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a long request to TCP port 8886 that begins with a certain negative integer, which passes a signed comparison and triggers a heap-based buffer overflow.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 96%
VendorProductVersion
hpopenview_network_node_manager
𝑥
≤ 7.53
hpopenview_network_node_manager
4.11
hpopenview_network_node_manager
5.0.1
hpopenview_network_node_manager
5.01
hpopenview_network_node_manager
6.0.1
hpopenview_network_node_manager
6.1
hpopenview_network_node_manager
6.2
hpopenview_network_node_manager
6.4
hpopenview_network_node_manager
6.10
hpopenview_network_node_manager
6.20
hpopenview_network_node_manager
6.31
hpopenview_network_node_manager
6.41
hpopenview_network_node_manager
7.0.1
hpopenview_network_node_manager
7.01
hpopenview_network_node_manager
7.50
hpopenview_network_node_manager
7.51
hpopenview_network_node_manager
8.01
𝑥
= Vulnerable software versions
Common Weakness Enumeration