Novell Iprint vulnerabilities
30 known vulnerabilities affecting novell/iprint.
Total CVEs
30
CISA KEV
0
Public exploits
4
Exploited in wild
0
Severity breakdown
CRITICAL25HIGH2MEDIUM3
Vulnerabilities
Page 2 of 2
CVE-2010-4314P3HIGHCVSS 8.8≤ 5.402017-03-11
CVE-2010-4314 [HIGH] CWE-119 CVE-2010-4314: Remote attackers can use the iPrint web-browser ActiveX plugin in Novell iPrint Client before 5.42 f
Remote attackers can use the iPrint web-browser ActiveX plugin in Novell iPrint Client before 5.42 for Windows XP/Vista/Win7 to execute code by overflowing the "name" parameter.
nvd
CVE-2011-4187P3CRITICALCVSS 10.0≤ 5.74v4.26+22 more2012-02-21
CVE-2011-4187 [CRITICAL] CVE-2011-4187: Buffer overflow in the GetDriverSettings function in nipplib.dll in Novell iPrint Client before 5.78
Buffer overflow in the GetDriverSettings function in nipplib.dll in Novell iPrint Client before 5.78 on Windows allows remote attackers to execute arbitrary code via a long realm field, a different vulnerability than CVE-2011-3173.
nvd
CVE-2011-4185P3CRITICALCVSS 10.0≤ 5.74v4.26+22 more2012-02-21
CVE-2011-4185 [CRITICAL] CVE-2011-4185: The GetPrinterURLList2 method in the ActiveX control in Novell iPrint Client before 5.78 on Windows
The GetPrinterURLList2 method in the ActiveX control in Novell iPrint Client before 5.78 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2008-2431 and CVE-2008-2436.
nvd
CVE-2008-5231P3CRITICALCVSS 9.3≤ 5.04v4.26+7 more2008-11-26
CVE-2008-5231 [CRITICAL] CVE-2008-5231: Stack-based buffer overflow in the ExecuteRequest method in the Novell iPrint ActiveX control in ien
Stack-based buffer overflow in the ExecuteRequest method in the Novell iPrint ActiveX control in ienipp.ocx in Novell iPrint Client 5.06 and earlier allows remote attackers to execute arbitrary code via a long target-frame option value, a different vulnerability than CVE-2008-2431.
nvd
CVE-2010-3105P3CRITICALCVSS 9.3≤ 5.42v4.26+13 more2010-08-23
CVE-2010-3105 [CRITICAL] CWE-119 CVE-2010-3105: The PluginGetDriverFile function in Novell iPrint Client before 5.44 interprets an uninitialized mem
The PluginGetDriverFile function in Novell iPrint Client before 5.44 interprets an uninitialized memory location as a pointer value, which allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
nvd
CVE-2009-3176P3CRITICALCVSS 9.3v4.382009-09-11
CVE-2009-3176 [CRITICAL] CWE-119 CVE-2009-3176: Buffer overflow in the ActiveX control in Novell iPrint Client 4.38 allows remote attackers to cause
Buffer overflow in the ActiveX control in Novell iPrint Client 4.38 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown attack vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.1, "Novell iPrint Client 4.38 ActiveX exploit." NOTE: as of 20090909, this disclosure has
nvd
CVE-2010-3107P4HIGHCVSS 7.1≤ 5.40v4.26+12 more2010-08-23
CVE-2010-3107 [HIGH] CWE-264 CVE-2010-3107: A certain ActiveX control in ienipp.ocx in the browser plugin in Novell iPrint Client before 5.42 do
A certain ActiveX control in ienipp.ocx in the browser plugin in Novell iPrint Client before 5.42 does not properly restrict the set of files to be deleted, which allows remote attackers to cause a denial of service (recursive file deletion) via unspecified vectors related to a "logic flaw" in the CleanUploadFiles method in the nipplib.dll module.
nvd
CVE-2008-2432P4MEDIUMCVSS 5.0≤ 5.04v4.26+7 more2008-11-26
CVE-2008-2432 [MEDIUM] CWE-200 CVE-2008-2432: Insecure method vulnerability in the GetFileList method in an unspecified ActiveX control in Novell
Insecure method vulnerability in the GetFileList method in an unspecified ActiveX control in Novell iPrint Client before 5.06 allows remote attackers to list the image files in an arbitrary directory via a directory name in the argument.
nvd
CVE-2013-3708P4MEDIUMCVSS 5.0≤ 5.90v4.26+26 more2013-12-01
CVE-2013-3708 [MEDIUM] CVE-2013-3708: The id1.GetPrinterURLList function in Novell iPrint Client before 5.93 allows remote attackers to ca
The id1.GetPrinterURLList function in Novell iPrint Client before 5.93 allows remote attackers to cause a denial of service via unspecified vectors.
nvd
CVE-2008-1701P4MEDIUMCVSS 5.0v6.52008-04-08
CVE-2008-1701 [MEDIUM] CVE-2008-1701: Novell NetWare 6.5 allows attackers to cause a denial of service (ABEND) via a crafted Macintosh iPr
Novell NetWare 6.5 allows attackers to cause a denial of service (ABEND) via a crafted Macintosh iPrint client request.
nvd
← Previous2 / 2