Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2009-0920

EPSS 58.77% · P98
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2009-0920

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Stack-based buffer overflow in OvCgi/Toolbar.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a long OvOSLocale cookie, a variant of CVE-2008-0067.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
HP OpenView网络节点管理器OvAcceptLang参数堆溢出漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
HP OpenView网络节点管理器(OV NNM)是HP公司开发和维护的网络管理系统软件,具有强大的网络节点管理功能。 如果远程攻击者向OV NNM的Toolbar.exe应用发送了带有超长OvAcceptLang cookie的HTTP请求的话,就可以触发堆溢出,导致执行任意代码。Toolbar.exe只是一个攻击路径,在OvAcceptLang参数的情况下,bug实际触发于ov.dll库中(Windows平台)。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2009-0920

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2009-0920

登录查看更多情报信息。

Same Patch Batch · n/a · 2009-03-25 · 58 CVEs total

CVE-2009-1075Sun Java System Identity Manager 忘记口令功能信息泄露漏洞
CVE-2009-0787Linux kernel 数字错误漏洞
CVE-2009-0928Adobe Acrobat和Reader JBIG2图形处理堆溢出漏洞
CVE-2009-0921HP OpenView网络节点管理器Accept-Language HTTP头堆溢出漏洞
CVE-2009-0891IBM WebSphere Application Server Username Token Option 会话劫持漏洞
CVE-2009-1061Adobe Acrobat Reader JBIG2未明向量代码执行漏洞
CVE-2009-1079Sun Java System Identity Manager多个跨站脚本漏洞
CVE-2009-1078Sun Java System Identity Manager 权限分配多个未明安全漏洞
CVE-2009-1077Sun Java System Identity Manager 更改口令工具访问控制漏洞
CVE-2009-1076Sun Java System Identity Manager 用户登录功能信息泄露漏洞
CVE-2009-1080Sun Java System Identity Manager多个跨站脚本漏洞
CVE-2009-1074Sun Java System Identity Manager 非加密传输信息泄露漏洞
CVE-2009-0215IBM Access Support ActiveX控件GetXMLValue()方式栈溢出漏洞
CVE-2009-1092GeoVision LiveAudio ActiveX控件GetAudioPlayingTime()方式代码执行漏洞
CVE-2009-1091Rapid Leech upload.php跨站脚本攻击漏洞
CVE-2009-1090Rapid Leech upload.php目录遍历和文件包含漏洞
CVE-2009-1089Rapid Leech upload.php绝对路径遍历漏洞
CVE-2009-1088Hannonhill Cascade Server XLST处理远程命令执行漏洞
CVE-2009-1087PPLive URI处理器LoadModule参数多个代码执行漏洞
CVE-2009-1086Nlnetlabs ldns 'rr.c'远程缓冲区溢出漏洞

Showing top 20 of 58 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2009-0920

No comments yet


Leave a comment