{"api_version":"1","generated_at":"2026-07-23T10:22:02+00:00","cve":"CVE-2010-1961","urls":{"html":"https://cve.report/CVE-2010-1961","api":"https://cve.report/api/cve/CVE-2010-1961.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-1961","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-1961"},"summary":{"title":"CVE-2010-1961","description":"Buffer overflow in ovutil.dll in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unspecified variables to jovgraph.exe, which are not properly handled in a call to the sprintf function.","state":"PUBLISHED","assigner":"hp","published_at":"2010-06-10 00:30:07","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securitytracker.com/id?1024071","name":"http://www.securitytracker.com/id?1024071","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - HP OpenView Network Node Manager 'jovgraph.exe' Lets Remote Users Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/59250","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/59250","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=127602909915281&w=2","name":"http://marc.info/?l=bugtraq&m=127602909915281&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"'[security bulletin] HPSBMA02537 SSRT010027 rev.1 - HP OpenView Network Node Manager (OV NNM), Remote' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/40638","name":"http://www.securityfocus.com/bid/40638","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"HP OpenView Network Node Manager 'ovutil.dll' Stack Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.zerodayinitiative.com/advisories/ZDI-10-106/","name":"http://www.zerodayinitiative.com/advisories/ZDI-10-106/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Zero Day Initiative","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/511731/100/0/threaded","name":"http://www.securityfocus.com/archive/1/511731/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://secunia.com/advisories/40101","name":"http://secunia.com/advisories/40101","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"HP OpenView Network Node Manager Buffer Overflow Vulnerabilities - Advisories - Community","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-1961","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-1961","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"1961","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hp","cpe5":"openview_network_node_manager","cpe6":"7.51","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"1961","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hp","cpe5":"openview_network_node_manager","cpe6":"7.51","cpe7":"-","cpe8":"hp-ux","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"1961","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hp","cpe5":"openview_network_node_manager","cpe6":"7.51","cpe7":"-","cpe8":"linux","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"1961","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hp","cpe5":"openview_network_node_manager","cpe6":"7.51","cpe7":"-","cpe8":"solaris","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"1961","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hp","cpe5":"openview_network_node_manager","cpe6":"7.51","cpe7":"-","cpe8":"windows","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"1961","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hp","cpe5":"openview_network_node_manager","cpe6":"7.53","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"1961","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hp","cpe5":"openview_network_node_manager","cpe6":"7.53","cpe7":"-","cpe8":"hp-ux","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"1961","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hp","cpe5":"openview_network_node_manager","cpe6":"7.53","cpe7":"-","cpe8":"linux","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"1961","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hp","cpe5":"openview_network_node_manager","cpe6":"7.53","cpe7":"-","cpe8":"solaris","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2010","cve_id":"1961","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"hp","cpe5":"openview_network_node_manager","cpe6":"7.53","cpe7":"-","cpe8":"windows","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T02:17:14.359Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"40638","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/40638"},{"name":"HPSBMA02537","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=127602909915281&w=2"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-10-106/"},{"name":"20100608 ZDI-10-106: Hewlett-Packard OpenView NNM ovutil.dll getProxiedStorageAddress Remote Code Execution Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/511731/100/0/threaded"},{"name":"40101","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/40101"},{"name":"SSRT010027","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=127602909915281&w=2"},{"name":"ovnnm-getproxiedstorageaddress-bo(59250)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/59250"},{"name":"1024071","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1024071"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2010-06-08T00:00:00.000Z","descriptions":[{"lang":"en","value":"Buffer overflow in ovutil.dll in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unspecified variables to jovgraph.exe, which are not properly handled in a call to the sprintf function."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-10T18:57:01.000Z","orgId":"74586083-13ce-40fd-b46a-8e5d23cfbcb2","shortName":"hp"},"references":[{"name":"40638","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/40638"},{"name":"HPSBMA02537","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=127602909915281&w=2"},{"tags":["x_refsource_MISC"],"url":"http://www.zerodayinitiative.com/advisories/ZDI-10-106/"},{"name":"20100608 ZDI-10-106: Hewlett-Packard OpenView NNM ovutil.dll getProxiedStorageAddress Remote Code Execution Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/511731/100/0/threaded"},{"name":"40101","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/40101"},{"name":"SSRT010027","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=127602909915281&w=2"},{"name":"ovnnm-getproxiedstorageaddress-bo(59250)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/59250"},{"name":"1024071","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1024071"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"hp-security-alert@hp.com","ID":"CVE-2010-1961","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Buffer overflow in ovutil.dll in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unspecified variables to jovgraph.exe, which are not properly handled in a call to the sprintf function."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"40638","refsource":"BID","url":"http://www.securityfocus.com/bid/40638"},{"name":"HPSBMA02537","refsource":"HP","url":"http://marc.info/?l=bugtraq&m=127602909915281&w=2"},{"name":"http://www.zerodayinitiative.com/advisories/ZDI-10-106/","refsource":"MISC","url":"http://www.zerodayinitiative.com/advisories/ZDI-10-106/"},{"name":"20100608 ZDI-10-106: Hewlett-Packard OpenView NNM ovutil.dll getProxiedStorageAddress Remote Code Execution Vulnerability","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/511731/100/0/threaded"},{"name":"40101","refsource":"SECUNIA","url":"http://secunia.com/advisories/40101"},{"name":"SSRT010027","refsource":"HP","url":"http://marc.info/?l=bugtraq&m=127602909915281&w=2"},{"name":"ovnnm-getproxiedstorageaddress-bo(59250)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/59250"},{"name":"1024071","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1024071"}]}}}},"cveMetadata":{"assignerOrgId":"74586083-13ce-40fd-b46a-8e5d23cfbcb2","assignerShortName":"hp","cveId":"CVE-2010-1961","datePublished":"2010-06-10T00:00:00.000Z","dateReserved":"2010-05-19T00:00:00.000Z","dateUpdated":"2024-08-07T02:17:14.359Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-06-10 00:30:07","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:hp:openview_network_node_manager:7.51:*:*:*:*:*:*:*","matchCriteriaId":"F5CC1E39-5607-41A9-8BBE-A51F1AC9D5CB"},{"vulnerable":true,"criteria":"cpe:2.3:a:hp:openview_network_node_manager:7.51:-:hp-ux:*:*:*:*:*","matchCriteriaId":"6692E05F-4864-449F-8A52-9001028D8C44"},{"vulnerable":true,"criteria":"cpe:2.3:a:hp:openview_network_node_manager:7.51:-:linux:*:*:*:*:*","matchCriteriaId":"2A40F2C6-AFF9-4D63-ACD0-A9D37160BA3D"},{"vulnerable":true,"criteria":"cpe:2.3:a:hp:openview_network_node_manager:7.51:-:solaris:*:*:*:*:*","matchCriteriaId":"FC1DA299-A180-4078-9172-67D116840D29"},{"vulnerable":true,"criteria":"cpe:2.3:a:hp:openview_network_node_manager:7.51:-:windows:*:*:*:*:*","matchCriteriaId":"FED610E9-7639-48FE-8B4F-B394A7EEC7C9"},{"vulnerable":true,"criteria":"cpe:2.3:a:hp:openview_network_node_manager:7.53:*:*:*:*:*:*:*","matchCriteriaId":"A3A4986C-97B8-4382-AC4B-55E22C6BAE62"},{"vulnerable":true,"criteria":"cpe:2.3:a:hp:openview_network_node_manager:7.53:-:hp-ux:*:*:*:*:*","matchCriteriaId":"C1935DA4-A1AF-4867-BCB1-F5BB75360702"},{"vulnerable":true,"criteria":"cpe:2.3:a:hp:openview_network_node_manager:7.53:-:linux:*:*:*:*:*","matchCriteriaId":"769ED1A5-C3C5-404E-8040-655D69C2AA88"},{"vulnerable":true,"criteria":"cpe:2.3:a:hp:openview_network_node_manager:7.53:-:solaris:*:*:*:*:*","matchCriteriaId":"186EFE05-AC1C-48FF-91B7-0CCD49FEABCC"},{"vulnerable":true,"criteria":"cpe:2.3:a:hp:openview_network_node_manager:7.53:-:windows:*:*:*:*:*","matchCriteriaId":"D5CE1F56-FA80-416D-8F42-C1C291F0965C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"1961","Ordinal":"1","Title":"CVE-2010-1961","CVE":"CVE-2010-1961","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"1961","Ordinal":"1","NoteData":"Buffer overflow in ovutil.dll in ovwebsnmpsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute arbitrary code via unspecified variables to jovgraph.exe, which are not properly handled in a call to the sprintf function.","Type":"Description","Title":"CVE-2010-1961"},{"CveYear":"2010","CveId":"1961","Ordinal":"2","NoteData":"2010-06-09","Type":"Other","Title":"Published"},{"CveYear":"2010","CveId":"1961","Ordinal":"3","NoteData":"2018-10-10","Type":"Other","Title":"Modified"}]}}}