VendorsNovellfile_reporterall versions
Vulnerabilities

Novell File Reporter (NFR)

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2012-4959
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and execute files via a 130 /FSF/CMD request with a .. (dot dot) in a FILE element of an FSFUI record.
Published 2012-11-18 · Modified
10.02 PoCEPSS 0.712
CVE-2012-4956
Heap-based buffer overflow in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to execute arbitrary code via a large number of VOL elements in an SRS record.
Published 2012-11-18 · Modified
10.0EPSS 0.377
CVE-2011-0994
Stack-based buffer overflow in NFRAgent.exe in Novell File Reporter (NFR) before 1.0.2 allows remote attackers to execute arbitrary code via unspecified XML data.
Published 2011-04-10 · Modified
10.0EPSS 0.179
CVE-2011-2220
Stack-based buffer overflow in NFREngine.exe in Novell File Reporter Engine before 1.0.2.53, as used in Novell File Reporter and other products, allows remote attackers to execute arbitrary code via a crafted RECORD element.
Published 2011-07-14 · Modified
10.0EPSS 0.161
CVE-2012-4958
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrary files via a 126 /FSF/CMD request with a .. (dot dot) in a FILE element of an FSFUI record.
Published 2012-11-18 · Modified
7.81 PoCEPSS 0.735
CVE-2012-4957
Absolute path traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrary files via a /FSF/CMD request with a full pathname in a PATH element of an SRS record.
Published 2012-11-18 · Modified
7.81 PoCEPSS 0.676
CVE-2011-2750
NFRAgent.exe in Novell File Reporter 1.0.4.2 and earlier allows remote attackers to delete arbitrary files via a full pathname in an SRS OPERATION 4 CMD 5 request to /FSF/CMD.
Published 2011-07-17 · Modified
5.0EPSS 0.167