CVE-2024-56497
- EPSS 0.11%
- Veröffentlicht 14.01.2025 14:15:34
- Zuletzt bearbeitet 03.02.2025 20:49:01
An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail versions 7.2.0 through 7.2.4 and 7.0.0 through 7.0.6 and 6.4.0 through 6.4.7, FortiRecorder versions 7.0.0 and 6.4.0 through 6.4.4 all...
CVE-2022-27488
- EPSS 0.44%
- Veröffentlicht 13.12.2023 07:15:10
- Zuletzt bearbeitet 21.11.2024 06:55:49
A cross-site request forgery (CSRF) in Fortinet FortiVoiceEnterprise version 6.4.x, 6.0.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4.10, 6.2.0 through 6.2.7, 6.0.x, FortiMail version 7.0.0 through 7.0.3, 6.4.0 through 6.4.6, 6.2.x, 6...
CVE-2023-45582
- EPSS 0.21%
- Veröffentlicht 14.11.2023 18:15:55
- Zuletzt bearbeitet 21.11.2024 08:27:00
An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0 through 7.0.6 and before 6.4.8 may allow an unauthenticated attacker to perform a brute force attack on the ...
CVE-2023-36633
- EPSS 0.2%
- Veröffentlicht 14.11.2023 18:15:49
- Zuletzt bearbeitet 21.11.2024 08:10:08
An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders of other users via crafted HTTP or HTTPs requests...
CVE-2023-36637
- EPSS 0.27%
- Veröffentlicht 10.10.2023 17:15:12
- Zuletzt bearbeitet 21.11.2024 08:10:08
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiMail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to inject HTML tags in FortiMail's calendar via input fields.
CVE-2023-36556
- EPSS 0.28%
- Veröffentlicht 10.10.2023 17:15:12
- Zuletzt bearbeitet 21.11.2024 08:09:55
An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.5 and below 6.4.7 allows an authenticated attacker to login on other users accounts from the same web domain via crafted HT...
CVE-2022-29056
- EPSS 8.5%
- Veröffentlicht 09.03.2023 15:15:09
- Zuletzt bearbeitet 21.11.2024 06:58:25
A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiMail version 6.4.0, version 6.2.0 through 6.2.4 and before 6.0.9 allows a remote unauthenticated attacker to partially exhaust CPU and memory via se...
CVE-2022-39945
- EPSS 0.19%
- Veröffentlicht 02.11.2022 12:15:54
- Zuletzt bearbeitet 21.11.2024 07:18:32
An improper access control vulnerability [CWE-284] in FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all versions, 6.2 all versions, 6.0 all versions may allow an authenticated admin user assigned to a specific domain to access and modify other domains in...
CVE-2022-26122
- EPSS 0.07%
- Veröffentlicht 02.11.2022 12:15:52
- Zuletzt bearbeitet 21.11.2024 06:53:28
An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient, FortiMail and FortiOS AV engines version 6.2.168 and below and version 6.4.274 and below may allow an attacker to bypass the AV engine via manipulating MIME att...
CVE-2022-26114
- EPSS 0.83%
- Veröffentlicht 06.09.2022 16:15:08
- Zuletzt bearbeitet 21.11.2024 06:53:27
An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before 7.2.0 may allow an unauthenticated attacker to trigger a cross-site scripting (XSS) attack via sending specially crafted mail mes...