← Vulnerability feed

Vulnerability record · CVE-2012-4956 · published 18 November 2012

CVE-2012-4956: Novell file reporter memory buffer overflow vulnerability

Novell · File Reporter

Heap-based buffer overflow in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to execute arbitrary code via a large number of VOL elements in an SRS record.

10.0 CVSS 2.0 High EPSS 38% · top 1.5% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
38%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to execute arbitrary code via a large number of VOL elements in an SRS record.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-4956 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-4959Novell File Reporter NFRAgent.exe path traversal allows remote file upload and executionNFRAgent.exe in Novell File Reporter 1.0.2 is vulnerable to directory traversal. A remote attacker can send a crafted 130 /FSF/CMD request containing…EPSS 71%analysed10.0CVE-2011-2220Novell file reporter engine memory buffer overflow vulnerabilityStack-based buffer overflow in NFREngine.exe in Novell File Reporter Engine before 1.0.2.53, as used in Novell File Reporter and other products, allo…EPSS 16%10.0CVE-2011-0994Novell file reporter memory buffer overflow vulnerabilityStack-based buffer overflow in NFRAgent.exe in Novell File Reporter (NFR) before 1.0.2 allows remote attackers to execute arbitrary code via unspecif…EPSS 18%7.8CVE-2012-4957Novell File Reporter NFRAgent.exe path traversal arbitrary file readNFRAgent.exe in Novell File Reporter 1.0.2 contains an absolute path traversal flaw (CWE-22). A remote attacker can send a /FSF/CMD request with a fu…EPSS 68%analysed7.8CVE-2012-4958Novell File Reporter NFRAgent.exe directory traversal file readNFRAgent.exe in Novell File Reporter 1.0.2 mishandles a 126 /FSF/CMD request containing a .. (dot dot) sequence in the FILE element of an FSFUI recor…EPSS 74%analysed5.0CVE-2011-2750Novell file reporter vulnerabilityNFRAgent.exe in Novell File Reporter 1.0.4.2 and earlier allows remote attackers to delete arbitrary files via a full pathname in an SRS OPERATION 4 …EPSS 17%8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2009-3459Adobe Reader and Acrobat heap buffer overflow via crafted PDFAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted…KEVEPSS 87%analysed

Source: NIST National Vulnerability Database (record CVE-2012-4956), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.