4.7

CVSS3.1

CVE-2023-46715 -

An origin validation error [CWE-346] vulnerability in Fortinet FortiOS IPSec VPN version 7.4.0 through 7.4.1 and version 7.2.6 and below allows an authenticated IPSec VPN user with dynamic IP addressing to send (but not receive) packets spoofing the IP of another user via crafted network packets.

πŸ“… Published: Jan. 14, 2025, 2:08 p.m. πŸ”„ Last Modified: Jan. 31, 2025, 5:20 p.m.

6.4

CVSS3.1

CVE-2023-42786 -

A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.0 all versions allows attacker to trigger a denial of service via a crafted http request.

πŸ“… Published: Jan. 14, 2025, 2:08 p.m. πŸ”„ Last Modified: Jan. 17, 2025, 8:42 p.m.

5

CVSS3.1

CVE-2024-35276 -

A stack-based buffer overflow in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager Cloud versions 7.4.1 throug…

πŸ“… Published: Jan. 14, 2025, 2:08 p.m. πŸ”„ Last Modified: Jan. 31, 2025, 5:04 p.m.

6.5

CVSS3.1

CVE-2024-35275 -

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, FortiManager version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http requests.

πŸ“… Published: Jan. 14, 2025, 2:08 p.m. πŸ”„ Last Modified: Jan. 31, 2025, 4:49 p.m.

6.4

CVSS3.1

CVE-2023-42785 -

A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.0 all versions allows attacker to trigger a denial of service via a crafted http request.

πŸ“… Published: Jan. 14, 2025, 2:08 p.m. πŸ”„ Last Modified: Jan. 17, 2025, 8:42 p.m.

7

CVSS3.1

CVE-2024-36512 -

An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer 7.4.0 through 7.4.3 and 7.2.0 through 7.2.5 and 7.0.2 through 7.0.12 and 6.2.10 through 6.2.13 allows attacker to execute unauthorized code or commands via crafted HTTP or HTTPS…

πŸ“… Published: Jan. 14, 2025, 2:08 p.m. πŸ”„ Last Modified: Jan. 31, 2025, 4:32 p.m.

7.5

CVSS3.1

CVE-2024-46670 -

AnΒ Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, version 7.2.9 and below and FortiSASE FortiOS tenant version 24.3.b IPsec IKE service may allow an unauthenticated remote attacker to trigger memory consumption leading to Denial of Service via crafted …

πŸ“… Published: Jan. 14, 2025, 2:08 p.m. πŸ”„ Last Modified: Jan. 31, 2025, 4:12 p.m.

3.2

CVSS3.1

CVE-2024-46669 -

AnΒ Integer Overflow or Wraparound vulnerability [CWE-190] in version 7.4.4 and below, version 7.2.10 and below; FortiSASE version 23.4.b FortiOS tenant IPsec IKE service may allow an authenticated attacker to crash the IPsec tunnel via crafted requests, resulting in potential denial of service.

πŸ“… Published: Jan. 14, 2025, 2:08 p.m. πŸ”„ Last Modified: Jan. 14, 2026, 9:15 a.m.

2.6

CVSS3.1

CVE-2024-55593 -

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3.17 through 7.6.1 allows attacker to gain information disclosure via crafted SQL queries

πŸ“… Published: Jan. 14, 2025, 2:08 p.m. πŸ”„ Last Modified: Feb. 3, 2025, 10:06 p.m.

7.2

CVSS3.1

CVE-2024-50566 -

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiManager Cloud 7.6.0 through 7.6.1, FortiManager Cloud 7.4.0 through 7.4.4, FortiManager Cloud 7.2.2 through 7.2.7, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.0 through…

πŸ“… Published: Jan. 14, 2025, 2:08 p.m. πŸ”„ Last Modified: Jan. 15, 2026, 3:05 p.m.
Total resulsts: 349182
Page 7150 of 34,919
Β« previous page Β» next page
Filters