CVE-2010-3107
Estado: ModificadaAlta (7.1)—
A certain ActiveX control in ienipp.ocx in the browser plugin in Novell iPrint Client before 5.42 does not properly restrict the set of files to be deleted, which allows remote attackers to cause a denial of service (recursive file deletion) via unspecified vectors related to a "logic flaw" in the CleanUploadFiles method in the nipplib.dll module.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C
- Puntuación base: 7.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.40%
- Percentil entre todas las CVEs puntuadas: 72
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-264
Referencias
- http://download.novell.com/Download?buildid=ftwZBxEFjIg~
- http://dvlabs.tippingpoint.com/advisory/TPTI-10-05
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12074
- http://download.novell.com/Download?buildid=ftwZBxEFjIg~
- http://dvlabs.tippingpoint.com/advisory/TPTI-10-05
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12074
JSON original (NVD)
Mostrar
{
"id": "CVE-2010-3107",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.1,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:N/A:C",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 6.9,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2010-08-23T22:00:03.440",
"references": [
{
"url": "http://download.novell.com/Download?buildid=ftwZBxEFjIg~",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://dvlabs.tippingpoint.com/advisory/TPTI-10-05",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12074",
"source": "cve@mitre.org"
},
{
"url": "http://download.novell.com/Download?buildid=ftwZBxEFjIg~",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://dvlabs.tippingpoint.com/advisory/TPTI-10-05",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12074",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A certain ActiveX control in ienipp.ocx in the browser plugin in Novell iPrint Client before 5.42 does not properly restrict the set of files to be deleted, which allows remote attackers to cause a denial of service (recursive file deletion) via unspecified vectors related to a \"logic flaw\" in the CleanUploadFiles method in the nipplib.dll module."
},
{
"lang": "es",
"value": "Un control ActiveX en ienipp.ocx en el plugin para el navegador del cliente de Novell iPrint antes de v5.42 no limita apropiadamente el conjunto de archivos que desea eliminar, lo que permite provocar a atacantes remotos una denegación de servicio (mediante eliminación de archivos de forma recursiva) a través de vectores no especificados relacionados con \"fallo lógico\" en el método CleanUploadFiles en el módulo nipplib.dll."
}
],
"lastModified": "2026-06-16T23:22:08.367",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:novell:iprint:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "583C6EB4-A372-4B15-8B3A-09A0D778ECA3",
"versionEndIncluding": "5.40"
},
{
"criteria": "cpe:2.3:a:novell:iprint:4.26:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3332CB43-D2ED-4720-8ED4-AE222C6F7FF3"
},
{
"criteria": "cpe:2.3:a:novell:iprint:4.27:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E9AD9057-2218-481E-96CB-BF568AD3A9F2"
},
{
"criteria": "cpe:2.3:a:novell:iprint:4.28:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0D044326-00CB-4158-A652-7D7FBDB380C7"
},
{
"criteria": "cpe:2.3:a:novell:iprint:4.30:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3BDA0CD3-3E49-42E9-8D41-2B93FEE53610"
},
{
"criteria": "cpe:2.3:a:novell:iprint:4.32:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AAB01661-76E1-4181-A798-6325EFD681FE"
},
{
"criteria": "cpe:2.3:a:novell:iprint:4.34:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "16769BC0-66AE-4AA3-B504-03389717A56D"
},
{
"criteria": "cpe:2.3:a:novell:iprint:4.36:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "25B2994C-8E01-4E7B-A5CA-9F9BE4C634C7"
},
{
"criteria": "cpe:2.3:a:novell:iprint:4.38:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CCCA90D8-A320-43B0-A667-DAFC0D00924F"
},
{
"criteria": "cpe:2.3:a:novell:iprint:5.04:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6F12CAA5-6C37-4FBA-BA41-03C7F81AE6BE"
},
{
"criteria": "cpe:2.3:a:novell:iprint:5.12:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CCA3CFFD-8D4B-4BEC-934A-7E5D18F87807"
},
{
"criteria": "cpe:2.3:a:novell:iprint:5.20b:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A2A31E77-BFE6-4F54-9839-8323F8E4995E"
},
{
"criteria": "cpe:2.3:a:novell:iprint:5.30:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7E8EC466-1CA2-4D8E-8D3F-F1246DC1850B"
},
{
"criteria": "cpe:2.3:a:novell:iprint:5.32:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "27533465-909A-4300-A713-36924FB330CA"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}