Novell Iprint vulnerabilities

30 known vulnerabilities affecting novell/iprint.

Total CVEs
30
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL25HIGH2MEDIUM3

Vulnerabilities

Page 1 of 2
CVE-2010-4314HIGHCVSS 8.8≤ 5.402017-03-11
CVE-2010-4314 [HIGH] CWE-119 CVE-2010-4314: Remote attackers can use the iPrint web-browser ActiveX plugin in Novell iPrint Client before 5.42 f Remote attackers can use the iPrint web-browser ActiveX plugin in Novell iPrint Client before 5.42 for Windows XP/Vista/Win7 to execute code by overflowing the "name" parameter.
nvd
CVE-2013-3708MEDIUMCVSS 5.0≤ 5.90v4.26+26 more2013-12-01
CVE-2013-3708 [MEDIUM] CVE-2013-3708: The id1.GetPrinterURLList function in Novell iPrint Client before 5.93 allows remote attackers to ca The id1.GetPrinterURLList function in Novell iPrint Client before 5.93 allows remote attackers to cause a denial of service via unspecified vectors.
nvd
CVE-2013-1091CRITICALCVSS 10.0≤ 5.86v4.26+25 more2013-05-02
CVE-2013-1091 [CRITICAL] CWE-119 CVE-2013-1091: Stack-based buffer overflow in Novell iPrint Client before 5.90 allows remote attackers to execute a Stack-based buffer overflow in Novell iPrint Client before 5.90 allows remote attackers to execute arbitrary code via unspecified vectors.
nvd
CVE-2012-0411CRITICALCVSS 10.0≤ 5.78v4.26+23 more2012-12-24
CVE-2012-0411 [CRITICAL] CVE-2012-0411: Unspecified vulnerability in Novell iPrint Client before 5.82 allows remote attackers to execute arb Unspecified vulnerability in Novell iPrint Client before 5.82 allows remote attackers to execute arbitrary code via an op-client-interface-version action.
nvd
CVE-2011-4187CRITICALCVSS 10.0≤ 5.74v4.26+22 more2012-02-21
CVE-2011-4187 [CRITICAL] CVE-2011-4187: Buffer overflow in the GetDriverSettings function in nipplib.dll in Novell iPrint Client before 5.78 Buffer overflow in the GetDriverSettings function in nipplib.dll in Novell iPrint Client before 5.78 on Windows allows remote attackers to execute arbitrary code via a long realm field, a different vulnerability than CVE-2011-3173.
nvd
CVE-2011-4185CRITICALCVSS 10.0≤ 5.74v4.26+22 more2012-02-21
CVE-2011-4185 [CRITICAL] CVE-2011-4185: The GetPrinterURLList2 method in the ActiveX control in Novell iPrint Client before 5.78 on Windows The GetPrinterURLList2 method in the ActiveX control in Novell iPrint Client before 5.78 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2008-2431 and CVE-2008-2436.
nvd
CVE-2011-4186CRITICALCVSS 9.3≤ 5.74v4.26+22 more2012-02-21
CVE-2011-4186 [CRITICAL] CVE-2011-4186: Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.78 on Windows allows remo Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.78 on Windows allows remote attackers to execute arbitrary code via a crafted client-file-name parameter in a printer-url, a different vulnerability than CVE-2011-1705.
nvd
CVE-2011-1701CRITICALCVSS 9.3≤ 5.60v4.26+18 more2011-06-09
CVE-2011-1701 [CRITICAL] CWE-119 CVE-2011-1701: Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attacker Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted profile-name parameter in a printer-url.
nvd
CVE-2011-1703CRITICALCVSS 9.3≤ 5.60v4.26+18 more2011-06-09
CVE-2011-1703 [CRITICAL] CWE-119 CVE-2011-1703: Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attacker Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted driver-version parameter in a printer-url.
nvd
CVE-2011-1707CRITICALCVSS 9.3≤ 5.60v4.26+18 more2011-06-09
CVE-2011-1707 [CRITICAL] CWE-119 CVE-2011-1707: Stack-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attacke Stack-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted op-printer-list-all-jobs parameter in a printer-url.
nvd
CVE-2011-1700CRITICALCVSS 9.3≤ 5.60v4.26+18 more2011-06-09
CVE-2011-1700 [CRITICAL] CWE-119 CVE-2011-1700: Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attacker Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted profile-time parameter in a printer-url.
nvd
CVE-2011-1708CRITICALCVSS 9.3≤ 5.60v4.26+18 more2011-06-09
CVE-2011-1708 [CRITICAL] CWE-119 CVE-2011-1708: Stack-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attacke Stack-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted op-printer-list-all-jobs cookie.
nvd
CVE-2011-1706CRITICALCVSS 9.3≤ 5.60v4.26+18 more2011-06-09
CVE-2011-1706 [CRITICAL] CWE-119 CVE-2011-1706: Stack-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attacke Stack-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted iprint-client-config-info parameter in a printer-url.
nvd
CVE-2011-1699CRITICALCVSS 9.3≤ 5.60v4.26+18 more2011-06-09
CVE-2011-1699 [CRITICAL] CWE-119 CVE-2011-1699: Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attacker Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted uri parameter in a printer-url.
nvd
CVE-2011-1704CRITICALCVSS 9.3≤ 5.60v4.26+18 more2011-06-09
CVE-2011-1704 [CRITICAL] CWE-119 CVE-2011-1704: Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attacker Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted core-package parameter in a printer-url.
nvd
CVE-2011-1702CRITICALCVSS 9.3≤ 5.60v4.26+18 more2011-06-09
CVE-2011-1702 [CRITICAL] CWE-119 CVE-2011-1702: Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attacker Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted file-date-time parameter in a printer-url.
nvd
CVE-2011-1705CRITICALCVSS 9.3≤ 5.60v4.26+18 more2011-06-09
CVE-2011-1705 [CRITICAL] CWE-119 CVE-2011-1705: Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attacker Heap-based buffer overflow in nipplib.dll in Novell iPrint Client before 5.64 allows remote attackers to execute arbitrary code via a crafted client-file-name parameter in a printer-url.
nvd
CVE-2010-3109CRITICALCVSS 9.3≤ 5.40v4.26+12 more2010-08-23
CVE-2010-3109 [CRITICAL] CWE-119 CVE-2010-3109: Stack-based buffer overflow in the browser plugin in Novell iPrint Client before 5.42 allows remote Stack-based buffer overflow in the browser plugin in Novell iPrint Client before 5.42 allows remote attackers to execute arbitrary code via a long operation parameter.
nvd
CVE-2010-3106CRITICALCVSS 9.3PoC≤ 5.40v4.26+12 more2010-08-23
CVE-2010-3106 [CRITICAL] CWE-20 CVE-2010-3106: The ienipp.ocx ActiveX control in the browser plugin in Novell iPrint Client before 5.42 does not pr The ienipp.ocx ActiveX control in the browser plugin in Novell iPrint Client before 5.42 does not properly validate the debug parameter, which allows remote attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via a parameter value with a crafted length, related to the ExecuteRequest method.
nvd
CVE-2010-3108CRITICALCVSS 9.3≤ 5.40v4.26+12 more2010-08-23
CVE-2010-3108 [CRITICAL] CWE-119 CVE-2010-3108: Buffer overflow in the browser plugin in Novell iPrint Client before 5.42 allows remote attackers to Buffer overflow in the browser plugin in Novell iPrint Client before 5.42 allows remote attackers to execute arbitrary code by using EMBED elements to pass parameters with long names.
nvd