FortiGuard Center
Level

FortiGuard Advisories



2008.January.02
Facebook Widget Installing Spyware
Fortinet Global Security Research Team discovered a malicious Facebook Widget actively spreading on the social networking site.

2007.November.15
“November 2007, Cumulative Patch” Virus
Fortinet Global Security Research Team Provides Protection Against Swen Email Virus

2007.November.14
Vulnerability in Windows URI Handling Could Allow Remote Code Execution (943460)
Fortinet Global Security Research Team Delivers Protection Against A Vulnerability in Windows URI Handling.

2007.November.14
Vulnerability Affecting CA Host-Based Intrusion Prevention System Server
Fortinet Global Security Research Team Discovers a Vulnerability Affecting CA Host Based Intrusion Prevention System Server.

2007.November.08
eBay Phish Using AOL Open Redirect
Fortinet Global Security Research Team Discovers Phish Using AOLSearch Redirection

2007.October.11
Vulnerability Affecting CA BrightStor ARCServe BackUp
Fortinet Global Security Research Team Discovers A Vulnerability Affecting CA BrightStor ARCServe BackUp.

2007.July.27
A Vulnerability Affecting Baidu Soba Search Bar
A Vulnerability Affecting Baidu Soba Search Bar.

2007.July.18
Thailand in the eye of the Storm
Tibs in Thailand

2007.June.12
Multiple Vulnerabilities Affecting Microsoft Speech Control.
Multiple Vulnerabilities Affecting Microsoft Speech Control.

2007.May.09
An Arbitrary File Rewrite Vulnerability Affecting Microsoft Internet Explorer
An Arbitrary File Rewrite Vulnerability Affecting Microsoft Internet Explorer

2007.April.19
Malware Exploiting Microsoft RPC Vulnerability on Windows DNS Server
Malware Exploiting Microsoft RPC Vulnerability on Windows DNS Server

2007.April.17
A Remote Buffer Overflow Vulnerability exists in Akamai Download Manager
A Remote Buffer Overflow Vulnerability exists in Akamai Download ManagerFortinet Security Research Team (FSRT) Discovers A Vulnerability Affecting Akamai Download Manager.

2007.March.14
Multiple Vulnerabilities Affecting McAfee ePolicy Orchestrator and ProtectionPilot
Fortinet Security Research Team (FSRT) Discovers Multiple Vulnerabilities Affecting McAfee ePolicy Orchestrator and ProtectionPilot.

2007.March.14
Malicious Code Appears on Blogger.com
Malicious Code Appears on Blogger.com

2007.February.22
Anniversary? 4 easy steps to multimedia Social Engineering attack
multimedia Social Engineering attack W32/VB.FT!tr.bdr

2007.January.09
Critical Vulnerability Affecting Microsoft Excel (927198)
Fortinet Security Research Team (FSRT) has discovered an Improper Memory Access Vulnerability in Microsoft Excel.

2006.October.20
Fortinet Continues to Protect Against Stration Threat
The Fortinet Response Team has discovered another variant of the mass-mailer Stration; unexpectedly, overpassing Grew.A and Netsky.P.

2006.October.12
Fortinet Protects Against MySpace Social Engineering Threat
The Fortinet Response Team has discovered another social engineering and phishing threat that is related to MySpace, the popular social networking website.

2006.October.10
Critical Vulnerabilities Affecting Microsoft PowerPoint, Microsoft Office and Microsoft Server Service
Fortinet Security Research Team (FSRT) has discovered multiple Microsoft vulnerabilities

2006.October.06
Fortinet Protects Against Volksbanken Phishing Threat
A massive phishing threat targeted to clients of Volksbanken Raiffeisenbanken, a bank based in Germany, has been detected by FortiGate security systems.

2006.September.19
Microsoft Internet Explorer VML Code Execution Vulnerability
Fortinet advises that its FortiGate security appliances, FortiMail secure messaging appliances and FortiClient Host Security software protect against JS/MS06.XMLNS!exploit.

2006.August.08
Critical Vulnerability Affecting Microsoft Powerpoint
Fortinet Security Research Team (FSRT) has discovered a Remote Code Execution vulnerability in Microsoft Powerpoint.

2006.July.28
FortiReporter Vulnerability
Fortinet advises that a recently discovered vulnerability has been found in the FortiReporter product . The Fortinet Engineering team has reviewed it and provided a fix for it.

2006.July.11
Critical Vulnerability Affecting Multiple Microsoft Office Products
Fortinet Security Research Team (FSRT) has discovered a critical vulnerability affecting multiple Microsoft Office products.

2006.July.05
Vulnerability in Macromedia Flash Player Could Allow Remote Code Execution
The Fortinet Security Research Team has discovered multiple improper memory access vulnerabilities in Macromedia Flash Player.

2006.July.05
Denial of Service Vulnerability in Macromedia Flash Player
The Fortinet Security Research Team has discovered a Denial of Service vulnerability in Macromedia Flash Player.

2006.June.13
Fortinet Protects Against Critical Microsoft Vulnerabilty Threatening PowerPoint Users
Vulnerability in Microsoft PowerPoint Could Allow Remote Code Execution (916768)

2006.May.30
Advisory – SMTP Sendmail Email Vulnerability (VU# 146718)
Fortinet advises that a recently discovered SMTP Sendmail email vulnerability was found and published by CERT.

2006.May.29
Buffer Overflow Vulnerability on WinAmp
Fortinet Security Research Team found a buffer overflow vunerability of winamp, and this vulnerability affects the newest version of winamp v5.21.

2006.May.29
Microsoft Internet Explorer Text File Extension Vulnerability
Fortinet Security Research Team has discovered a denial service vulnerability in Microsoft Internet Explorer.

2006.May.10
Advisory - FTP Anti-Virus scanning application bypass vulnerability
Fortinet advises that a recently discovered FTP Anti-Virus Scanning application bypass vulnerability was found to exist under certain conditions.

2006.March.31
Microsoft Internet Explorer CreateTextRange Remote Code Execution Vulnerability
Fortinet advises that its FortiGate security appliances, FortiMail secure messaging appliances and FortiClient Host Security software protect against JS/CreateTextRange.A!exploit and JS/CreateTextRang

2006.March.15
MSIL/Overcross.A
Fortinet advises that its FortiGate security appliances, FortiMail secure messaging appliances and FortiClient Host Security software protect against MSIL/Overcross.A Microsoft Intermediate Language t

2006.March.14
Microsoft Excel Column Index Improper Memory Access
Fortinet Security Research Team (FSRT) has discovered a Improper Memory Access Vulnerability in the Microsoft Excel software.

2006.March.14
Microsoft.Excel.Formula.Size.Stack.Overflow
Fortinet Security Research Team (FSRT) has discovered a Improper Stack Overflow Vulnerability in the Microsoft Excel software.

2006.February.24
URL Filtering Application Bypass Vulnerability
Fortinet advises that a recently discovered URL Filtering application bypass vulnerability was found and published on some public websites.

2006.February.24
FTP Anti-Virus Scanning Application Bypass Vulnerability
Fortinet advises that a recently discovered FTP Anti-Virus Scanning application bypass vulnerability was found and published on some public websites.

2006.January.26
W32/Grew.A!wm (Updated)
W32/Grew.A!wm is a mass-mailing worm that attempts to spread through network shares and lower security settings. Fortinet rates it as a level 4 threat. It accounted for approximately 15% of malware ac

2006.January.18
BitComet URI Buffer Overflow Vulnerability
Fortinet Security Research Team (FSRT) has discovered a URI buffer overflow Vulnerability in the BitComet P2P Client software. It indicates a possible exploit of buffer overflow vulnerability in BitComet.

2006.January.12
Apple QuickTime Player Color Map Entry Size Buffer Overflow
Fortinet Security Research Team (FSRT) has discovered a Buffer Overflow Vulnerability in the Apple QuickTime Player. Apple QuickTime has buffer overflow vulnerability in parsing the specially crafted

2006.January.12
Apple QuickTime Player StripByteCounts Buffer Overflow Vulnerability
Apple QuickTime has buffer overflow vulnerability in parsing the specially crafted TIFF image files. This is due to application failure to sanitize the parameters StripByteCounts and StripOffsets valu

2006.January.12
Apple QuickTime Player StripOffsets Improper Memory Access
Fortinet Security Research Team (FSRT) has discovered a Vulnerability in the Apple QuickTime Player. Apple QuickTime has a vulnerability in parsing the specially crafted TIFF image files.

2006.January.12
Apple QuickTime Player ImageWidth Denial of Service Vulnerability
Fortinet Security Research Team (FSRT) has discovered a Denial of Service Vulnerability in the Apple QuickTime Player. Apple QuickTime has Denial of Service vulnerability in parsing the specially crafted TIFF image files.

2006.January.12
Apple QuickTime Player Improper Memory Access Vulnerability
Fortinet Security Research Team (FSRT) has discovered a Improper Memory Access Vulnerability in the Apple QuickTime Player. Apple QuickTime has Improper Memory Access vulnerability in parsing the specially crafted TGA image files.

2006.January.12
Apple QuickTime Player ImageWidth Integer Overflow Vulnerability
Fortinet Security Research Team (FSRT) has discovered a Buffer Overflow Vulnerability in the Apple QuickTime Player. Apple QuickTime has buffer overflow vulnerability in parsing the specially crafted TGA image files.

2005.December.28
Microsoft Windows WMF Handling Vulnerability
Fortinet advises that its FortiGate security appliances, FortiMail antispam appliances and FortiClient Host Security software protect against the

2005.December.08
IKE ISAKMP (VU#226364) vulnerabilities
Fortinet advises that its FortiGate security appliances, FortiManager systems, and FortiClient Host Security software products are vulnerable against the recent IKE ISAKMP (VU#226364) vulnerabilities.

2005.November.22
Microsoft Internet Explorer
Fortinet advises that its FortiGate security appliances protect against the latest Microsoft Internet Explorer

2005.November.14
W32/Sober.AC-mm and related variants (CME-157)
On Monday November 14, 2005 Fortinet received the first samples of Sober, a Mass-mailer that sends itself to addresses harvested from the infected system.

2005.November.10
Sony DRM - W32/BrepiBot.D!tr
W32/BrepiBot.D!tr is a Trojan that attempts to make use of the security flaws introduced in Sony's customer's systems by way of its DRM technology by installing a bot, which tries to connect to a list

2005.November.09
Microsoft Windows Vulnerability MS05-053
Fortinet advises that its FortiGate security appliances protect against the latest Microsoft Windows Vulnerability MS05-053, a vulnerability in the Graphics Rendering Engine that could allow code exec

2005.November.01
W32/Mitglieder.FY!tr, W32/Mitglieder.FZ!tr and W32/Mitglieder.GA!tr
W32/Mitglieder.FZ!tr is a Downloader type Trojan that is manually sent by hackers and/or mail proxies established by other viruses and Trojans, which attempts to connect to various Web sites to retrie

2005.October.17
W32/MyTob.NA@mm, W32/MyTob.MZ@mm and W32/MyTob.MY@mm
W32/MyTob.NA-mm (aka Doombot.b) is a mass-mailing virus that spreads via SMTP, and resides within a .ZIP file attachment inside emails received from a spoofed sender address.

2005.October.14
W32/MyTob.MY@mm
W32/MyTob.MY-mm is a mass-mailing worm, similar to the previous MyTob variants, and spreads to other systems using its own SMTP engine.

2005.September.19
W32/Bagle.CJ@mm
A new Trojan, W32/Bagle.CJ-mm is received via an email with .exe or .zip file attachments that contain a malicious executable file, which injects itself into Windows Explorer processes and stays resid

2005.August.17
HTML/Msdds-exploit
Fortinet advises that its FortiGate security appliances, FortiMail antispam appliances and FortiClient Host Security software protect against possible malwares exploiting Microsoft Internet Explorer's

2005.July.02
HTML/Ebay-phish
Fortinet received the first sample of this new Phishing scam in Israel and detected 46,902 samples thus far, including 12,000 samples of this new Phishing attempt within two hours of releasing the det

2005.May.02
W32/Sober.P-mm
On Monday 2 May (PDT) Fortinet received the first samples of Sober.P, a Mass-mailer that sends itself to addresses harvested from the infected system.

2005.April.14
W32/Zotob worm
Fortinet advises that its FortiGate security appliances, FortiMail antispam appliances and FortiClient Host Security software protect against all known variants of the W32/Zotob worm. This network wor

2005.April.12
Vulnerability in MSN Messenger Could Lead to Remote Code Execution
A remote code execution vulnerability exists in MSN Messenger that could allow an attacker who successfully exploited this vulnerability to take complete control of the affected system.

2005.March.17
Windows 2000 GDI32.DLL GetEnhMetaFilePaletteEntries() vulnerability
A denial of service vulnerability affects Microsoft Windows GDI library 'gdi32.dll'. This issue is due to a failure of the application to securely copy data from malformed EMF image files.

2005.February.05
Foxmail MAIL-FROM Remote Buffer Overflow Vulnerability
Multiple remote buffer overflow vulnerabilities reportedly affect the command response functionality of GlobalScape CuteFTP. These issues are due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into finite process buffers.

2004.December.14
RICOH Aficio 450/455 PCL 5e Printer ICMP DOS vulnerability
Ricoh 450/455 printers are susceptible to a remote denial of service vulnerability. This issue is due to a failure of the device to properly handle exceptional ICMP packets.

2004.November.24
GlobalScape CuteFTP Professional Multiple Command Response Buffer Overflow Vulnerabilities
Multiple remote buffer overflow vulnerabilities reportedly affect the command response functionality of GlobalScape CuteFTP. These issues are due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into finite process buffers.