FortiGuard Advisories
2008.January.02
Facebook Widget Installing Spyware
Fortinet Global Security Research Team discovered a malicious Facebook Widget actively spreading on the social networking site.
2006.July.28
FortiReporter Vulnerability
Fortinet advises that a recently discovered vulnerability has been found in the FortiReporter product . The Fortinet Engineering team has reviewed it and provided a fix for it.
2006.May.29
Buffer Overflow Vulnerability on WinAmp
Fortinet Security Research Team found a buffer overflow vunerability of winamp, and this vulnerability affects the newest version of winamp v5.21.
2006.March.15
MSIL/Overcross.A
Fortinet advises that its FortiGate security appliances, FortiMail secure messaging appliances and FortiClient Host Security software protect against MSIL/Overcross.A Microsoft Intermediate Language t
2006.January.26
W32/Grew.A!wm (Updated)
W32/Grew.A!wm is a mass-mailing worm that attempts to spread through network shares and lower security settings. Fortinet rates it as a level 4 threat. It accounted for approximately 15% of malware ac
2006.January.18
BitComet URI Buffer Overflow Vulnerability
Fortinet Security Research Team (FSRT) has discovered a URI buffer overflow Vulnerability in the BitComet P2P Client software. It indicates a possible exploit of buffer overflow vulnerability in BitComet.
2006.January.12
Apple QuickTime Player Improper Memory Access Vulnerability
Fortinet Security Research Team (FSRT) has discovered a Improper Memory Access Vulnerability in the Apple QuickTime Player. Apple QuickTime has Improper Memory Access vulnerability in parsing the specially crafted TGA image files.
2005.December.08
IKE ISAKMP (VU#226364) vulnerabilities
Fortinet advises that its FortiGate security appliances, FortiManager systems, and FortiClient Host Security software products are vulnerable against the recent IKE ISAKMP (VU#226364) vulnerabilities.
2005.November.22
Microsoft Internet Explorer
Fortinet advises that its FortiGate security appliances protect against the latest Microsoft Internet Explorer
2005.November.10
Sony DRM - W32/BrepiBot.D!tr
W32/BrepiBot.D!tr is a Trojan that attempts to make use of the security flaws introduced in Sony's customer's systems by way of its DRM technology by installing a bot, which tries to connect to a list
2005.November.09
Microsoft Windows Vulnerability MS05-053
Fortinet advises that its FortiGate security appliances protect against the latest Microsoft Windows Vulnerability MS05-053, a vulnerability in the Graphics Rendering Engine that could allow code exec
2005.October.14
W32/MyTob.MY@mm
W32/MyTob.MY-mm is a mass-mailing worm, similar to the previous MyTob variants, and spreads to other systems using its own SMTP engine.
2005.September.19
W32/Bagle.CJ@mm
A new Trojan, W32/Bagle.CJ-mm is received via an email with .exe or .zip file attachments that contain a malicious executable file, which injects itself into Windows Explorer processes and stays resid
2005.August.17
HTML/Msdds-exploit
Fortinet advises that its FortiGate security appliances, FortiMail antispam appliances and FortiClient Host Security software protect against possible malwares exploiting Microsoft Internet Explorer's
2005.July.02
HTML/Ebay-phish
Fortinet received the first sample of this new Phishing scam in Israel and detected 46,902 samples thus far, including 12,000 samples of this new Phishing attempt within two hours of releasing the det
2005.May.02
W32/Sober.P-mm
On Monday 2 May (PDT) Fortinet received the first samples of Sober.P, a Mass-mailer that sends itself to addresses harvested from the infected system.
2005.April.14
W32/Zotob worm
Fortinet advises that its FortiGate security appliances, FortiMail antispam appliances and FortiClient Host Security software protect against all known variants of the W32/Zotob worm. This network wor
2005.February.05
Foxmail MAIL-FROM Remote Buffer Overflow Vulnerability
Multiple remote buffer overflow vulnerabilities reportedly affect the command response functionality of GlobalScape CuteFTP. These issues are due to a failure of the application to properly validate the length of user-supplied strings prior to copying them into finite process buffers.