Fortinet / FortiMail
46 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-36166 | An improper authentication vulnerability in FortiMail before 7.0.1 may allow a remote attacker to efficiently guess one administrative account's authentication… | CRITICAL | 9.8 | Mar 1, 2022 |
| CVE-2021-36193 | Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may allow an authenticated attacker to achieve arbitrary code ex… | HIGH | 7.2 | Feb 2, 2022 |
| CVE-2021-43062 | A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 and below,… | MEDIUM | 6.1 | Feb 2, 2022 |
| CVE-2020-15933 | A exposure of sensitive information to an unauthorized actor in Fortinet FortiMail versions 6.0.9 and below, FortiMail versions 6.2.4 and below FortiMail versi… | MEDIUM | 5.3 | Jan 5, 2022 |
| CVE-2021-32591 | A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSandbox before 4.0.1, FortiWeb before 6.3.… | MEDIUM | 5.3 | Dec 8, 2021 |
| CVE-2021-42757 | A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to ac… | MEDIUM | 6.7 | Dec 8, 2021 |
| CVE-2021-26095 | The combination of various cryptographic issues in the session management of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6, including the encryption co… | HIGH | 8.8 | Jul 20, 2021 |
| CVE-2021-24013 | Multiple Path traversal vulnerabilities in the Webmail of FortiMail before 6.4.4 may allow a regular user to obtain unauthorized access to files and data via s… | HIGH | 8.8 | Jul 12, 2021 |
| CVE-2021-24015 | An improper neutralization of special elements used in an OS Command vulnerability in the administrative interface of FortiMail before 6.4.4 may allow an authe… | HIGH | 8.8 | Jul 12, 2021 |
| CVE-2021-26090 | A missing release of memory after its effective lifetime vulnerability in the Webmail of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6 may allow an una… | HIGH | 7.5 | Jul 12, 2021 |
| CVE-2021-26099 | Missing cryptographic steps in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an attacker who comes in possession of the encrypted m… | MEDIUM | 4.9 | Jul 12, 2021 |
| CVE-2021-24007 | Multiple improper neutralization of special elements of SQL commands vulnerabilities in FortiMail before 6.4.4 may allow a non-authenticated attacker to execut… | CRITICAL | 9.8 | Jul 9, 2021 |
| CVE-2021-22129 | Multiple instances of incorrect calculation of buffer size in the Webmail and Administrative interface of FortiMail before 6.4.5 may allow an authenticated att… | HIGH | 8.8 | Jul 9, 2021 |
| CVE-2021-26100 | A missing cryptographic step in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an unauthenticated attacker who intercepts the encryp… | HIGH | 7.5 | Jul 9, 2021 |
| CVE-2021-24020 | A missing cryptographic step in the implementation of the hash digest algorithm in FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthen… | CRITICAL | 9.8 | Jul 9, 2021 |
| CVE-2020-9294 | An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthentica… | CRITICAL | 9.8 | Apr 27, 2020 |
| CVE-2019-15707 | An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow administrators to perform system backup con… | MEDIUM | 4.9 | Jan 23, 2020 |
| CVE-2019-15712 | An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow administrators to access web console they s… | HIGH | 7.2 | Jan 23, 2020 |
| CVE-2017-7732 | A reflected Cross-Site Scripting (XSS) vulnerability in Fortinet FortiMail 5.1 and earlier, 5.2.0 through 5.2.9, and 5.3.0 through 5.3.9 customized pre-authent… | MEDIUM | 6.1 | Oct 26, 2017 |
| CVE-2017-3125 | An unauthenticated XSS vulnerability with FortiMail 5.0.0 - 5.2.9 and 5.3.0 - 5.3.8 could allow an attacker to execute arbitrary scripts in the security contex… | MEDIUM | 6.1 | Apr 12, 2017 |
| CVE-2015-3293 | FortiMail 5.0.3 through 5.2.3 allows remote administrators to obtain credentials via the "diag debug application httpd" command. | MEDIUM | 4.0 | Apr 14, 2015 |
| CVE-2014-8617 | Cross-site scripting (XSS) vulnerability in the Web Action Quarantine Release feature in the WebGUI in Fortinet FortiMail before 4.3.9, 5.0.x before 5.0.8, 5.1… | MEDIUM | 4.3 | Mar 4, 2015 |
| CVE-2013-1471 | Multiple cross-site scripting (XSS) vulnerabilities in admin/FEAdmin.html in Fortinet FortiMail before 4.3.4 on FortiMail Identity-Based Encryption (IBE) appli… | MEDIUM | 4.3 | Feb 4, 2013 |
Showing 26 to 46 of 46 CVEs