CVE-2021-26100
- EPSS 0.11%
- Published 09.07.2021 19:15:08
- Last modified 21.11.2024 05:55:52
A missing cryptographic step in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an unauthenticated attacker who intercepts the encrypted messages to manipulate them in such a way that makes the tampering and the recovery of ...
CVE-2021-22129
- EPSS 0.45%
- Published 09.07.2021 19:15:08
- Last modified 21.11.2024 05:49:33
Multiple instances of incorrect calculation of buffer size in the Webmail and Administrative interface of FortiMail before 6.4.5 may allow an authenticated attacker with regular webmail access to trigger a buffer overflow and to possibly execute unau...
CVE-2021-24007
- EPSS 0.71%
- Published 09.07.2021 19:15:08
- Last modified 21.11.2024 05:52:11
Multiple improper neutralization of special elements of SQL commands vulnerabilities in FortiMail before 6.4.4 may allow a non-authenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.
CVE-2021-24020
- EPSS 0.17%
- Published 09.07.2021 19:15:08
- Last modified 21.11.2024 05:52:13
A missing cryptographic step in the implementation of the hash digest algorithm in FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthenticated attacker to tamper with signed URLs by appending further data which allows bypass o...
CVE-2020-9294
- EPSS 80.13%
- Published 27.04.2020 17:15:13
- Last modified 21.11.2024 05:40:22
An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to access the system as a legitimate user by requesting a password change via ...
CVE-2019-15712
- EPSS 0.54%
- Published 23.01.2020 18:15:13
- Last modified 21.11.2024 04:29:18
An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow administrators to access web console they should not be authorized for.
CVE-2019-15707
- EPSS 0.87%
- Published 23.01.2020 18:15:13
- Last modified 21.11.2024 04:29:17
An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow administrators to perform system backup config download they should not be authorized for.
CVE-2017-7732
- EPSS 0.85%
- Published 26.10.2017 13:29:00
- Last modified 20.04.2025 01:37:25
A reflected Cross-Site Scripting (XSS) vulnerability in Fortinet FortiMail 5.1 and earlier, 5.2.0 through 5.2.9, and 5.3.0 through 5.3.9 customized pre-authentication webmail login page allows attacker to inject arbitrary web script or HTML via craft...
CVE-2017-3125
- EPSS 0.59%
- Published 12.04.2017 15:59:00
- Last modified 20.04.2025 01:37:25
An unauthenticated XSS vulnerability with FortiMail 5.0.0 - 5.2.9 and 5.3.0 - 5.3.8 could allow an attacker to execute arbitrary scripts in the security context of the browser of a victim logged in FortiMail, assuming the victim is social engineered ...
- EPSS 0.24%
- Published 14.04.2015 18:59:07
- Last modified 12.04.2025 10:46:40
FortiMail 5.0.3 through 5.2.3 allows remote administrators to obtain credentials via the "diag debug application httpd" command.