CVE-2008-2908

Novell Iprint Client < 4.35 - Memory Corruption

Title source: rule

Description

Multiple stack-based buffer overflows in a certain ActiveX control in ienipp.ocx in Novell iPrint Client for Windows before 4.36 allow remote attackers to execute arbitrary code via a long value of the (1) operation, (2) printer-url, or (3) target-frame parameter. NOTE: some of these details are obtained from third party information.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16508
metasploit WORKING POC NORMAL
by MC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/novelliprint_getdriversettings.rb

Scores

EPSS 0.7026
EPSS Percentile 98.7%

Details

CWE
CWE-119
Status published
Products (1)
novell/iprint_client < 4.35
Published Jun 30, 2008
Tracked Since Feb 18, 2026