CVE-2023-45582
- EPSS 0.21%
- Published 14.11.2023 18:15:55
- Last modified 21.11.2024 08:27:00
An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0 through 7.0.6 and before 6.4.8 may allow an unauthenticated attacker to perform a brute force attack on the ...
CVE-2023-36633
- EPSS 0.2%
- Published 14.11.2023 18:15:49
- Last modified 21.11.2024 08:10:08
An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders of other users via crafted HTTP or HTTPs requests...
CVE-2023-36637
- EPSS 0.27%
- Published 10.10.2023 17:15:12
- Last modified 21.11.2024 08:10:08
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiMail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to inject HTML tags in FortiMail's calendar via input fields.
CVE-2023-36556
- EPSS 0.28%
- Published 10.10.2023 17:15:12
- Last modified 21.11.2024 08:09:55
An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.5 and below 6.4.7 allows an authenticated attacker to login on other users accounts from the same web domain via crafted HT...
CVE-2022-29056
- EPSS 6.95%
- Published 09.03.2023 15:15:09
- Last modified 21.11.2024 06:58:25
A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiMail version 6.4.0, version 6.2.0 through 6.2.4 and before 6.0.9 allows a remote unauthenticated attacker to partially exhaust CPU and memory via se...
CVE-2022-39945
- EPSS 0.14%
- Published 02.11.2022 12:15:54
- Last modified 21.11.2024 07:18:32
An improper access control vulnerability [CWE-284] in FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all versions, 6.2 all versions, 6.0 all versions may allow an authenticated admin user assigned to a specific domain to access and modify other domains in...
CVE-2022-26122
- EPSS 0.11%
- Published 02.11.2022 12:15:52
- Last modified 21.11.2024 06:53:28
An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient, FortiMail and FortiOS AV engines version 6.2.168 and below and version 6.4.274 and below may allow an attacker to bypass the AV engine via manipulating MIME att...
CVE-2022-26114
- EPSS 0.83%
- Published 06.09.2022 16:15:08
- Last modified 21.11.2024 06:53:27
An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before 7.2.0 may allow an unauthenticated attacker to trigger a cross-site scripting (XSS) attack via sending specially crafted mail mes...
CVE-2022-22299
- EPSS 0.04%
- Published 05.08.2022 20:15:08
- Last modified 21.11.2024 06:46:35
A format string vulnerability [CWE-134] in the command line interpreter of FortiADC version 6.0.0 through 6.0.4, FortiADC version 6.1.0 through 6.1.5, FortiADC version 6.2.0 through 6.2.1, FortiProxy version 1.0.0 through 1.0.7, FortiProxy version 1....
CVE-2021-32586
- EPSS 0.44%
- Published 01.03.2022 19:15:08
- Last modified 21.11.2024 06:07:19
An improper input validation vulnerability in the web server CGI facilities of FortiMail before 7.0.1 may allow an unauthenticated attacker to alter the environment of the underlying script interpreter via specifically crafted HTTP requests.