Fortinet

Fortimail

42 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 14.11.2023 18:15:55
  • Zuletzt bearbeitet 21.11.2024 08:27:00

An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0 through 7.0.6 and before 6.4.8 may allow an unauthenticated attacker to  perform a brute force attack on the ...

  • EPSS 0.2%
  • Veröffentlicht 14.11.2023 18:15:49
  • Zuletzt bearbeitet 21.11.2024 08:10:08

An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders of other users via crafted HTTP or HTTPs requests...

  • EPSS 0.27%
  • Veröffentlicht 10.10.2023 17:15:12
  • Zuletzt bearbeitet 21.11.2024 08:10:08

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiMail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to inject HTML tags in FortiMail's calendar via input fields.

  • EPSS 0.28%
  • Veröffentlicht 10.10.2023 17:15:12
  • Zuletzt bearbeitet 21.11.2024 08:09:55

An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.5 and below 6.4.7 allows an authenticated attacker to login on other users accounts from the same web domain via crafted HT...

  • EPSS 6.95%
  • Veröffentlicht 09.03.2023 15:15:09
  • Zuletzt bearbeitet 21.11.2024 06:58:25

A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiMail version 6.4.0, version 6.2.0 through 6.2.4 and before 6.0.9 allows a remote unauthenticated attacker to partially exhaust CPU and memory via se...

  • EPSS 0.14%
  • Veröffentlicht 02.11.2022 12:15:54
  • Zuletzt bearbeitet 21.11.2024 07:18:32

An improper access control vulnerability [CWE-284] in FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all versions, 6.2 all versions, 6.0 all versions may allow an authenticated admin user assigned to a specific domain to access and modify other domains in...

  • EPSS 0.11%
  • Veröffentlicht 02.11.2022 12:15:52
  • Zuletzt bearbeitet 21.11.2024 06:53:28

An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient, FortiMail and FortiOS AV engines version 6.2.168 and below and version 6.4.274 and below may allow an attacker to bypass the AV engine via manipulating MIME att...

  • EPSS 0.83%
  • Veröffentlicht 06.09.2022 16:15:08
  • Zuletzt bearbeitet 21.11.2024 06:53:27

An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before 7.2.0 may allow an unauthenticated attacker to trigger a cross-site scripting (XSS) attack via sending specially crafted mail mes...

  • EPSS 0.04%
  • Veröffentlicht 05.08.2022 20:15:08
  • Zuletzt bearbeitet 21.11.2024 06:46:35

A format string vulnerability [CWE-134] in the command line interpreter of FortiADC version 6.0.0 through 6.0.4, FortiADC version 6.1.0 through 6.1.5, FortiADC version 6.2.0 through 6.2.1, FortiProxy version 1.0.0 through 1.0.7, FortiProxy version 1....

  • EPSS 0.44%
  • Veröffentlicht 01.03.2022 19:15:08
  • Zuletzt bearbeitet 21.11.2024 06:07:19

An improper input validation vulnerability in the web server CGI facilities of FortiMail before 7.0.1 may allow an unauthenticated attacker to alter the environment of the underlying script interpreter via specifically crafted HTTP requests.