Lucene search

K
cveMitreCVE-2010-3106
HistoryAug 23, 2010 - 10:00 p.m.

CVE-2010-3106

2010-08-2322:00:03
CWE-20
mitre
web.nvd.nist.gov
27
ienipp.ocx
activex control
browser plugin
novell iprint client
cve-2010-3106
security vulnerability
remote code execution
denial of service
stack memory corruption
nvd

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.199

Percentile

96.4%

The ienipp.ocx ActiveX control in the browser plugin in Novell iPrint Client before 5.42 does not properly validate the debug parameter, which allows remote attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via a parameter value with a crafted length, related to the ExecuteRequest method.

Affected configurations

Nvd
Node
novelliprintRange5.40
OR
novelliprintMatch4.26
OR
novelliprintMatch4.27
OR
novelliprintMatch4.28
OR
novelliprintMatch4.30
OR
novelliprintMatch4.32
OR
novelliprintMatch4.34
OR
novelliprintMatch4.36
OR
novelliprintMatch4.38
OR
novelliprintMatch5.04
OR
novelliprintMatch5.12
OR
novelliprintMatch5.20b
OR
novelliprintMatch5.30
OR
novelliprintMatch5.32
VendorProductVersionCPE
novelliprint*cpe:2.3:a:novell:iprint:*:*:*:*:*:*:*:*
novelliprint4.26cpe:2.3:a:novell:iprint:4.26:*:*:*:*:*:*:*
novelliprint4.27cpe:2.3:a:novell:iprint:4.27:*:*:*:*:*:*:*
novelliprint4.28cpe:2.3:a:novell:iprint:4.28:*:*:*:*:*:*:*
novelliprint4.30cpe:2.3:a:novell:iprint:4.30:*:*:*:*:*:*:*
novelliprint4.32cpe:2.3:a:novell:iprint:4.32:*:*:*:*:*:*:*
novelliprint4.34cpe:2.3:a:novell:iprint:4.34:*:*:*:*:*:*:*
novelliprint4.36cpe:2.3:a:novell:iprint:4.36:*:*:*:*:*:*:*
novelliprint4.38cpe:2.3:a:novell:iprint:4.38:*:*:*:*:*:*:*
novelliprint5.04cpe:2.3:a:novell:iprint:5.04:*:*:*:*:*:*:*
Rows per page:
1-10 of 141

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.199

Percentile

96.4%