peter bassill · operator
$ cve CVE-2010-3106 JSON

CVE-2010-3106 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 37.3% (pctl 98)

Patch early

A public exploit exists.

Description

The ienipp.ocx ActiveX control in the browser plugin in Novell iPrint Client before 5.42 does not properly validate the debug parameter, which allows remote attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via a parameter value with a crafted length, related to the ExecuteRequest method.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS37.33% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2010-08-23
Last modified2026-06-16

Affected (1)

VendorProduct
novelliprint

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD