CVE-2007-4349
Estado: ModificadaMedia (4.3)—
The Shared Trace Service (aka OVTrace) in HP Performance Agent C.04.70 (aka 4.70), HP OpenView Performance Agent C.04.60 and C.04.61, HP Reporter 3.8, and HP OpenView Reporter 3.7 (aka Report 3.70) allows remote attackers to cause a denial of service via an unspecified series of RPC requests (aka Trace Event Messages) that triggers an out-of-bounds memory access, related to an erroneous object reference.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 3.08%
- Percentil entre todas las CVEs puntuadas: 87
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (4)
CWE
- NVD-CWE-Other
Referencias
- http://marc.info/?l=bugtraq&m=122876677518654&w=2
- http://marc.info/?l=bugtraq&m=122876827120961&w=2
- http://secunia.com/advisories/27054
- http://secunia.com/secunia_research/2007-83/
- http://securityreason.com/securityalert/4501
- http://www.securityfocus.com/archive/1/497648/100/0/threaded
- http://www.securityfocus.com/bid/31860
- http://www.securitytracker.com/id?1021092
- http://www.vupen.com/english/advisories/2008/2888
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46028
- http://marc.info/?l=bugtraq&m=122876677518654&w=2
- http://marc.info/?l=bugtraq&m=122876827120961&w=2
- http://secunia.com/advisories/27054
- http://secunia.com/secunia_research/2007-83/
- http://securityreason.com/securityalert/4501
- http://www.securityfocus.com/archive/1/497648/100/0/threaded
- http://www.securityfocus.com/bid/31860
- http://www.securitytracker.com/id?1021092
- http://www.vupen.com/english/advisories/2008/2888
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46028
JSON original (NVD)
Mostrar
{
"id": "CVE-2007-4349",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "PSIRT-CNA@flexerasoftware.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-10-23T22:00:01.027",
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=122876677518654&w=2",
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://marc.info/?l=bugtraq&m=122876827120961&w=2",
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://secunia.com/advisories/27054",
"tags": [
"Vendor Advisory"
],
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://secunia.com/secunia_research/2007-83/",
"tags": [
"Vendor Advisory"
],
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://securityreason.com/securityalert/4501",
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://www.securityfocus.com/archive/1/497648/100/0/threaded",
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://www.securityfocus.com/bid/31860",
"tags": [
"Patch"
],
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://www.securitytracker.com/id?1021092",
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://www.vupen.com/english/advisories/2008/2888",
"tags": [
"Vendor Advisory"
],
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46028",
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "http://marc.info/?l=bugtraq&m=122876677518654&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=bugtraq&m=122876827120961&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/27054",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/secunia_research/2007-83/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/4501",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/497648/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/31860",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1021092",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2008/2888",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/46028",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Shared Trace Service (aka OVTrace) in HP Performance Agent C.04.70 (aka 4.70), HP OpenView Performance Agent C.04.60 and C.04.61, HP Reporter 3.8, and HP OpenView Reporter 3.7 (aka Report 3.70) allows remote attackers to cause a denial of service via an unspecified series of RPC requests (aka Trace Event Messages) that triggers an out-of-bounds memory access, related to an erroneous object reference."
},
{
"lang": "es",
"value": "El servicio Shared Trace (también se conoce como OVTrace) en HP Performance Agent versión C.04.70 (4.70), HP OpenView Performance Agent versiones C.04.60 y C.04.61, HP Reporter versión 3.8 y HP OpenView Reporter versión 3.7 (Informe 3.70), permite a los atacantes remotos causar una denegación de servicio por medio de una serie no especificada de peticiones RPC (también se conoce como Mensajes de Eventos de Rastreo) que desencadena un acceso de memoria fuera de límites, relacionado con una referencia de objeto errónea."
}
],
"lastModified": "2026-06-16T22:43:51.803",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:hp:openview_performance_agent:c.04.60:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9374AB08-64F6-4376-BF01-652E88A7E050"
},
{
"criteria": "cpe:2.3:a:hp:openview_performance_agent:c.04.61:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "15053C63-0407-422A-9E7B-591E336D6121"
},
{
"criteria": "cpe:2.3:a:hp:openview_reporter:3.70:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "380F0F94-E4D6-4630-AC10-C4D8922760A4"
},
{
"criteria": "cpe:2.3:a:hp:performance_agent:4.70:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4B769539-D927-4086-9160-F162488F5337"
},
{
"criteria": "cpe:2.3:a:hp:reporter:3.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2BCEDB40-6EC3-4F4F-A2E5-5B223AA58DDF"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "PSIRT-CNA@flexerasoftware.com"
}