Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Single Sign On HIGH 7.5
CVE-2015-2281EPSS 10%

Stack-based buffer overflow in collectoragent.exe in Fortinet Single Sign On (FSSO) before build 164 allows remote attackers to execute arbitrary cod…

No fix yet
Fix from $1,950 2015-03-19
Fortiauthenticator MEDIUM 6.9
CVE-2015-1458

Fortinet FortiAuthenticator 3.0.0 allows local users to bypass intended restrictions and gain privileges by creating /tmp/privexec/dbgcore_enable_she…

No fix yet
Fix from $1,600 2015-02-03
Fortiauthenticator HIGH 7.5
CVE-2015-1455

Fortinet FortiAuthenticator 3.0.0 has a password of (1) slony for the slony PostgreSQL user and (2) www-data for the www-data PostgreSQL user, which …

No fix yet
Fix from $1,950 2015-02-03
Forticlient MEDIUM 5.0
CVE-2015-1453

The qm class in Fortinet FortiClient 5.2.3.091 for Android uses a hardcoded encryption key of FoRtInEt!AnDrOiD, which makes it easier for attackers t…

Fix: after 5.2.3.091
Fix from $1,600 2015-02-02
Fortios HIGH 7.8
CVE-2015-1452

The Control and Provisioning of Wireless Access Points (CAPWAP) daemon in Fortinet FortiOS 5.0 Patch 7 build 4457 allows remote attackers to cause a …

Mitigation only
Fix from $1,950 2015-02-02
Coyote Point Equalizer Firmware MEDIUM 6.4
CVE-2014-8582

FortiNet FortiADC-E with firmware 3.1.1 before 4.0.5 and Coyote Point Equalizer with firmware 10.2.0a allows remote attackers to obtain access to arb…

Mitigation only
Fix from $1,600 2014-11-01
Fortios MEDIUM 5.4
CVE-2014-0351

The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.x before 5.0.8 on FortiGate devices does not prevent use of anonymous ciphe…

Fix: after 4.3.15
Fix from $1,600 2014-09-10
Fortios HIGH 7.5
CVE-2014-2216EPSS 5%

The FortiManager protocol service in Fortinet FortiOS before 4.3.16 and 5.0.0 before 5.0.8 on FortiGate devices allows remote attackers to cause a de…

Fix: after 4.3.15
Fix from $1,950 2014-08-25
Fortiweb MEDIUM 6.8
CVE-2014-3115

Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Fortinet FortiWeb before 5.2.0 allow remote attackers…

Fix: after 5.1.4
Fix from $1,600 2014-05-08
Fortiweb MEDIUM 6.5
CVE-2014-1957

FortiGuard FortiWeb before 5.0.3 allows remote authenticated users to gain privileges via unspecified vectors.

Fix: after 5.0.2
Fix from $1,600 2014-04-30
Fortiweb MEDIUM 5.0
CVE-2014-1956

CRLF injection vulnerability in FortiGuard FortiWeb before 5.0.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response s…

Fix: after 5.0.2
Fix from $1,600 2014-04-30
Fortiauthenticator HIGH 9.0
CVE-2013-6990

FortiGuard FortiAuthenticator before 3.0 allows remote administrators to gain privileges via the command line interface.

Fix: after 2.2
Fix from $1,950 2014-04-30
Fortianalyzer Firmware MEDIUM 6.8
CVE-2013-6826

cgi-bin/module//sysmanager/admin/SYSAdminUserDialog in Fortinet FortiAnalyzer before 5.0.5 does not properly validate the csrf_token parameter, which…

Fix: after 5.0.4
Fix from $1,600 2013-11-20
Fortios MEDIUM 5.1
CVE-2013-1414

Multiple cross-site request forgery (CSRF) vulnerabilities in Fortinet FortiOS on FortiGate firewall devices before 4.3.13 and 5.x before 5.0.2 allow…

Fix: after 4.3.12
Fix from $1,600 2013-07-08
Fortios MEDIUM 6.5
CVE-2013-4604

Fortinet FortiOS before 5.0.3 on FortiGate devices does not properly restrict Guest capabilities, which allows remote authenticated users to read, mo…

Fix: after 5.0.2
Fix from $1,600 2013-06-25
Forticlient MEDIUM 5.4
CVE-2013-4669

FortiClient before 4.3.5.472 on Windows, before 4.0.3.134 on Mac OS X, and before 4.0 on Android; FortiClient Lite before 4.3.4.461 on Windows; Forti…

Fix: after 4.3.3.445
Fix from $1,600 2013-06-25
Fortigate 1000c MEDIUM 5.3
CVE-2012-4948

The default configuration of Fortinet Fortigate UTM appliances uses the same Certification Authority certificate and same private key across differen…

Mitigation only
Fix from $1,600 2012-11-14
Fortigate 1000 HIGH 7.5
CVE-2008-7161EPSS 6%

Fortinet FortiGuard Fortinet FortiGate-1000 3.00 build 040075,070111 allows remote attackers to bypass URL filtering via fragmented GET or POST reque…

No fix yet
Fix from $1,950 2009-09-04
Forticlient HIGH 7.2
CVE-2009-1262

Format string vulnerability in Fortinet FortiClient 3.0.614, and possibly earlier, allows local users to execute arbitrary code via format string spe…

Mitigation only
Fix from $1,950 2009-04-07
Fortiguard Antivirus HIGH 9.3
CVE-2008-5531

Fortinet Antivirus 3.113.0.0, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by pl…

Mitigation only
Fix from $1,950 2008-12-12
Forticlient Host Security HIGH 7.2
CVE-2008-0779

The fortimon.sys device driver in Fortinet FortiClient Host Security 3.0 MR5 Patch 3 and earlier does not properly initialize its DeviceExtension, wh…

Fix: after 3.0
Fix from $1,950 2008-02-14
Fortios MEDIUM 5.0
CVE-2006-3222

The FTP proxy module in Fortinet FortiOS (FortiGate) before 2.80 MR12 and 3.0 MR2 allows remote attackers to bypass anti-virus scanning via the Enhan…

Patch available
Fix from $1,600 2006-06-24
Fortinet28 MEDIUM 5.0
CVE-2006-1966

An unspecified Fortinet product, possibly Fortinet28, allows remote attackers to cause a denial of service via a "small synflood" to the SMTP port (T…

No fix yet
Fix from $1,600 2006-04-21
Fortios HIGH 10.0
CVE-2005-3057

The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and other versions before 3.0 MR1, allows remote attackers to bypass the Forti…

Fix: after 3_beta
Fix from $1,950 2005-12-31
Fortios HIGH 7.5
CVE-2005-3058

Interpretation conflict in Fortinet FortiGate 2.8, running FortiOS 2.8MR10 and v3beta, allows remote attackers to bypass the URL blocker via an (1) H…

Fix: after 3_beta
Fix from $1,950 2005-12-31
Fortinet MEDIUM 5.0
CVE-2005-3400

Multiple interpretation error in Fortinet 2.48.0.0 allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ…

Mitigation only
Fix from $1,600 2005-11-01
Fortinet Antivirus MEDIUM 5.1
CVE-2005-3221

Multiple interpretation error in unspecified versions of Fortinet Antivirus allows remote attackers to bypass virus detection via a malicious executa…

No fix yet
Fix from $1,600 2005-10-14
Fortinet Firewall HIGH 7.5
CVE-2005-1837

Fortinet firewall running FortiOS 2.x contains a hardcoded username with the password set to the serial number, which allows local users with console…

Mitigation only
Fix from $1,950 2005-06-01