← Vulnerability feed

Vulnerability record · CVE-2007-5360 · published 8 January 2008

CVE-2007-5360: Openpegasus management server memory buffer overflow vulnerability

OOpenpegasus · Management Server

Buffer overflow in OpenPegasus Management server, when compiled to use PAM and with PEGASUS_USE_PAM_STANDALONE_PROC defined, as used in VMWare ESX Server 3.0.1 and 3.0.2, might allow remote attackers to execute arbitrary code via vectors related to PAM authentication, a different vulnerability than CVE-2008-0003.

7.5 CVSS 2.0 High EPSS 15% · top 3.3% CWE-119 · Memory buffer overflow
7.5CVSS 2.0 base score
15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
34References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in OpenPegasus Management server, when compiled to use PAM and with PEGASUS_USE_PAM_STANDALONE_PROC defined, as used in VMWare ESX Server 3.0.1 and 3.0.2, might allow remote attackers to execute arbitrary code via vectors related to PAM authentication, a different vulnerability than CVE-2008-0003.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01438409
http://lists.vmware.com/pipermail/security-announce/2008/000002.html
http://secunia.com/advisories/28358 PatchVendor Advisory
http://secunia.com/advisories/28368 Vendor Advisory
http://secunia.com/advisories/28636
http://secunia.com/advisories/29986
http://securityreason.com/securityalert/3538
http://www.attrition.org/pipermail/vim/2008-January/001879.html
http://www.novell.com/linux/security/advisories/suse_security_summary_report.html
http://www.securityfocus.com/archive/1/485936/100/0/threaded
http://www.securityfocus.com/archive/1/486859/100/0/threaded
http://www.vmware.com/security/advisories/VMSA-2008-0001.html
http://www.vupen.com/english/advisories/2008/0063
http://www.vupen.com/english/advisories/2008/0064
http://www.vupen.com/english/advisories/2008/1391/references
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2007-5360
https://exchange.xforce.ibmcloud.com/vulnerabilities/39524
http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01438409
http://lists.vmware.com/pipermail/security-announce/2008/000002.html
http://secunia.com/advisories/28358 PatchVendor Advisory
http://secunia.com/advisories/28368 Vendor Advisory
http://secunia.com/advisories/28636
http://secunia.com/advisories/29986
http://securityreason.com/securityalert/3538
http://www.attrition.org/pipermail/vim/2008-January/001879.html
http://www.novell.com/linux/security/advisories/suse_security_summary_report.html
http://www.securityfocus.com/archive/1/485936/100/0/threaded
http://www.securityfocus.com/archive/1/486859/100/0/threaded
http://www.vmware.com/security/advisories/VMSA-2008-0001.html
http://www.vupen.com/english/advisories/2008/0063
http://www.vupen.com/english/advisories/2008/0064
http://www.vupen.com/english/advisories/2008/1391/references
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2007-5360
https://exchange.xforce.ibmcloud.com/vulnerabilities/39524

Track CVE-2007-5360 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-7169GNU Bash environment variable function parsing command injection (Shellshock variant)GNU Bash through 4.3 bash43-025 processes trailing strings after malformed function definitions in environment variable values, allowing command inje…KEVEPSS 100%analysed9.8CVE-2014-6271GNU Bash environment variable command injection (ShellShock)GNU Bash through 4.3 processes trailing strings after function definitions in environment variable values, allowing injected commands to run when Bas…KEVEPSS 100%analysed10.0CVE-2013-1405Vmware vcenter server improper authentication vulnerabilityVMware vCenter Server 4.0 before Update 4b and 4.1 before Update 3a, VMware VirtualCenter 2.5, VMware vSphere Client 4.0 before Update 4b and 4.1 bef…EPSS 2.8%10.0CVE-2008-0003Openpegasus management server memory buffer overflow vulnerabilityStack-based buffer overflow in the PAMBasicAuthenticator::PAMCallback function in OpenPegasus CIM management server (tog-pegasus), when compiled to u…EPSS 7.8%10.0CVE-2007-0061Vmware ace memory buffer overflow vulnerabilityThe DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 bef…EPSS 6.5%10.0CVE-2007-0063Vmware ace vulnerabilityInteger underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 5…EPSS 20%9.9CVE-2012-1516Vmware esx memory buffer overflow vulnerabilityThe VMX process in VMware ESXi 3.5 through 4.1 and ESX 3.5 through 4.1 does not properly handle RPC commands, which allows guest OS users to cause a …EPSS 3.2%9.4CVE-2013-3658Vmware esx path traversal vulnerabilityDirectory traversal vulnerability in VMware ESXi 4.0 through 5.0, and ESX 4.0 and 4.1, allows remote attackers to delete arbitrary host OS files via …EPSS 3.7%

Source: NIST National Vulnerability Database (record CVE-2007-5360), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.