Vulnerabilities > Novell > Iprint > High

DATE CVE VULNERABILITY TITLE RISK
2017-03-11 CVE-2010-4314 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Novell Iprint
Remote attackers can use the iPrint web-browser ActiveX plugin in Novell iPrint Client before 5.42 for Windows XP/Vista/Win7 to execute code by overflowing the "name" parameter.
network
low complexity
novell CWE-119
8.8
2010-08-23 CVE-2010-3107 Permissions, Privileges, and Access Controls vulnerability in Novell Iprint
A certain ActiveX control in ienipp.ocx in the browser plugin in Novell iPrint Client before 5.42 does not properly restrict the set of files to be deleted, which allows remote attackers to cause a denial of service (recursive file deletion) via unspecified vectors related to a "logic flaw" in the CleanUploadFiles method in the nipplib.dll module.
network
novell CWE-264
7.1