Lucene search

K
nvd[email protected]NVD:CVE-2008-2436
HistorySep 05, 2008 - 4:08 p.m.

CVE-2008-2436

2008-09-0516:08:00
CWE-94
web.nvd.nist.gov
2

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.226

Percentile

96.5%

Multiple heap-based buffer overflows in the IppCreateServerRef function in nipplib.dll in Novell iPrint Client 4.x before 4.38 and 5.x before 5.08 allow remote attackers to execute arbitrary code via a long argument to the (1) GetPrinterURLList, (2) GetPrinterURLList2, or (3) GetFileList2 function in the Novell iPrint ActiveX control in ienipp.ocx.

Affected configurations

NVD
Node
novelliprint_clientMatch4.26windows
OR
novelliprint_clientMatch4.32windows
OR
novelliprint_clientMatch4.35windows
OR
novelliprint_clientMatch4.36windows
OR
novelliprint_clientMatch5.06vista

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.226

Percentile

96.5%