Filtered by vendor Fortinet Subscriptions
Filtered by product Fortimail Subscriptions
Total 45 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-22129 1 Fortinet 1 Fortimail 2024-11-21 8.8 High
Multiple instances of incorrect calculation of buffer size in the Webmail and Administrative interface of FortiMail before 6.4.5 may allow an authenticated attacker with regular webmail access to trigger a buffer overflow and to possibly execute unauthorized code or commands via specifically crafted HTTP requests.
CVE-2020-9294 1 Fortinet 2 Fortimail, Fortivoice 2024-11-21 9.8 Critical
An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to access the system as a legitimate user by requesting a password change via the user interface.
CVE-2020-15933 1 Fortinet 1 Fortimail 2024-11-21 5.3 Medium
A exposure of sensitive information to an unauthorized actor in Fortinet FortiMail versions 6.0.9 and below, FortiMail versions 6.2.4 and below FortiMail versions 6.4.1 and 6.4.0 allows attacker to obtain potentially sensitive software-version information via client-side resources inspection.
CVE-2019-15712 1 Fortinet 1 Fortimail 2024-11-21 7.2 High
An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow administrators to access web console they should not be authorized for.
CVE-2019-15707 1 Fortinet 1 Fortimail 2024-11-21 4.9 Medium
An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow administrators to perform system backup config download they should not be authorized for.