CVE-2010-3106 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 37.3% (pctl 98)
Patch early
A public exploit exists.
Description
The ienipp.ocx ActiveX control in the browser plugin in Novell iPrint Client before 5.42 does not properly validate the debug parameter, which allows remote attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via a parameter value with a crafted length, related to the ExecuteRequest method.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 37.33% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-20 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2010-08-23 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| novell | iprint |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Novell iPrint Client - ActiveX Control 'debug' Remote Buffer Overflow (Metasploit) | 2010-09-21 |
| exploit-db | Novell iPrint Client - ActiveX Control ExecuteRequest debug Buffer Overflow (Metasploit) | 2010-09-21 |
References
- http://download.novell.com/Download?buildid=ftwZBxEFjIg~
- http://dvlabs.tippingpoint.com/advisory/TPTI-10-06
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12044
- http://download.novell.com/Download?buildid=ftwZBxEFjIg~
- http://dvlabs.tippingpoint.com/advisory/TPTI-10-06
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12044
→ the Explorer · watch your stack · NVD