← Vulnerability feed

Vulnerability record · CVE-2007-5846 · published 6 November 2007

CVE-2007-5846: Net-snmp vulnerability

Net Snmp · Net Snmp

The SNMP agent (snmp_agent.c) in net-snmp before 5.4.1 allows remote attackers to cause a denial of service (CPU and memory consumption) via a GETBULK request with a large max-repeaters value.

7.8 CVSS 2.0 High EPSS 29% · top 1.9% CWE-399 · CWE-399
7.8CVSS 2.0 base score
29%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
58References
16 Jun 2026Last modified by NVD

Description

The SNMP agent (snmp_agent.c) in net-snmp before 5.4.1 allows remote attackers to cause a denial of service (CPU and memory consumption) via a GETBULK request with a large max-repeaters value.

AV:N/AC:L/Au:N/C:N/I:N/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://bugs.gentoo.org/show_bug.cgi?id=198346
http://lists.vmware.com/pipermail/security-announce/2008/000014.html Patch
http://net-snmp.svn.sourceforge.net/viewvc/net-snmp/tags/Ext-5-4-1/net-snmp/agent/snmp_agent.c?view=log
http://osvdb.org/38904
http://secunia.com/advisories/27558 Vendor Advisory
http://secunia.com/advisories/27685 Vendor Advisory
http://secunia.com/advisories/27689 Vendor Advisory
http://secunia.com/advisories/27733 Vendor Advisory
http://secunia.com/advisories/27740 Vendor Advisory
http://secunia.com/advisories/27965 Vendor Advisory
http://secunia.com/advisories/28413 Vendor Advisory
http://secunia.com/advisories/28825 Vendor Advisory
http://secunia.com/advisories/29785 Vendor Advisory
http://security.gentoo.org/glsa/glsa-200711-31.xml
http://sourceforge.net/project/shownotes.php?release_id=528095&group_id=12694
http://sourceforge.net/tracker/index.php?func=detail&aid=1712988&group_id=12694&atid=112694
http://www.debian.org/security/2008/dsa-1483 Patch
http://www.mandriva.com/security/advisories?name=MDKSA-2007:225
http://www.novell.com/linux/security/advisories/2007_25_sr.html
http://www.redhat.com/support/errata/RHSA-2007-1045.html
http://www.securityfocus.com/archive/1/490917/100/0/threaded
http://www.securityfocus.com/bid/26378 Patch
http://www.securitytracker.com/id?1018918
http://www.ubuntu.com/usn/usn-564-1
http://www.vupen.com/english/advisories/2007/3802 Vendor Advisory
http://www.vupen.com/english/advisories/2008/1234/references Vendor Advisory
https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA43730
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11258
https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00613.html
http://bugs.gentoo.org/show_bug.cgi?id=198346
http://lists.vmware.com/pipermail/security-announce/2008/000014.html Patch
http://net-snmp.svn.sourceforge.net/viewvc/net-snmp/tags/Ext-5-4-1/net-snmp/agent/snmp_agent.c?view=log
http://osvdb.org/38904
http://secunia.com/advisories/27558 Vendor Advisory
http://secunia.com/advisories/27685 Vendor Advisory
http://secunia.com/advisories/27689 Vendor Advisory
http://secunia.com/advisories/27733 Vendor Advisory
http://secunia.com/advisories/27740 Vendor Advisory
http://secunia.com/advisories/27965 Vendor Advisory
http://secunia.com/advisories/28413 Vendor Advisory

Track CVE-2007-5846 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-4837Net-snmp vulnerabilitysnmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allows remote …EPSS 9.7%10.0CVE-2005-1740Net-snmp vulnerabilityfixproc in Net-snmp 5.x before 5.2.1-r1 creates temporary files insecurely, which allows local users to modify the contents of those files to execute…EPSS 8.6%9.8CVE-2025-68615Net-snmp memory buffer overflow vulnerabilitynet-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted packet to an net-snmp snmptrapd …EPSS 42%9.8CVE-2018-1000116Net-snmp out-of-bounds write vulnerabilityNET-SNMP version 5.7.2 contains a heap corruption vulnerability in the UDP protocol handler that can result in command execution.EPSS 6.3%8.8CVE-2022-24810Net-snmp null pointer dereference vulnerabilitynet-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can us…EPSS 1.1%8.8CVE-2022-24805Net-snmp classic buffer overflow vulnerabilitynet-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a buffer overflow in the handling of the …EPSS 1.3%7.8CVE-2020-15861Net-snmp link following vulnerabilityNet-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following.EPSS 0.46%7.8CVE-2020-15862Net-snmp improper privilege management vulnerabilityNet-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as …EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2007-5846), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.