VYPR

File Reporter

by Novell

CVEs (7)

  • CVE-2012-4959Nov 18, 2012
    risk 0.09cvss epss 0.74

    Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and execute files via a 130 /FSF/CMD request with a .. (dot dot) in a FILE element of an FSFUI record.

  • CVE-2012-4958Nov 18, 2012
    risk 0.09cvss epss 0.74

    Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrary files via a 126 /FSF/CMD request with a .. (dot dot) in a FILE element of an FSFUI record.

  • CVE-2012-4957Nov 18, 2012
    risk 0.09cvss epss 0.76

    Absolute path traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrary files via a /FSF/CMD request with a full pathname in a PATH element of an SRS record.

  • CVE-2011-2750Jul 17, 2011
    risk 0.09cvss epss 0.71

    NFRAgent.exe in Novell File Reporter 1.0.4.2 and earlier allows remote attackers to delete arbitrary files via a full pathname in an SRS OPERATION 4 CMD 5 request to /FSF/CMD.

  • CVE-2012-4956Nov 18, 2012
    risk 0.08cvss epss 0.69

    Heap-based buffer overflow in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to execute arbitrary code via a large number of VOL elements in an SRS record.

  • CVE-2011-2220Jul 14, 2011
    risk 0.02cvss epss 0.29

    Stack-based buffer overflow in NFREngine.exe in Novell File Reporter Engine before 1.0.2.53, as used in Novell File Reporter and other products, allows remote attackers to execute arbitrary code via a crafted RECORD element.

  • CVE-2011-0994Apr 10, 2011
    risk 0.02cvss epss 0.29

    Stack-based buffer overflow in NFRAgent.exe in Novell File Reporter (NFR) before 1.0.2 allows remote attackers to execute arbitrary code via unspecified XML data.