Loading HuntDB...

FOGProject

1 Product 11 CVEs

CVE Severity Distribution (All Time)

Critical
2
High
3
Medium
5
Low
0

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 0 CVEs

Recent CVEs

View all
CVE-2024-34477 UNKNOWN None

configureNFS in lib/common/functions.sh in FOG through 1.5.10 allows local users to gain privileges by mounting a crafted NFS share (because of no_ro…

CVE-2024-42349 MEDIUM 1 year, 1 month ago

FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.4 and earlier can leak authorized and rejected logins via log…

CVE-2024-42348 CRITICAL 1 year, 1 month ago

FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.2 can leak AD username and password when registering a comput…

CVE-2024-41954 MEDIUM 1 year, 1 month ago

FOG is a cloning/imaging/rescue suite/inventory management system. The application stores plaintext service account credentials in the "/opt/fog/.fog…

CVE-2024-41108 HIGH 1 year, 1 month ago

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. The hostinfo page has missing/improper access control since only …

CVE-2024-40645 HIGH 1 year, 1 month ago

FOG is a cloning/imaging/rescue suite/inventory management system. An improperly restricted file upload feature allows authenticated users to execute…

CVE-2024-39916 MEDIUM 1 year, 1 month ago

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. There is a security issue with the NFS configuration in /etc/expo…

CVE-2024-39914 CRITICAL 1 year, 1 month ago

FOG is a cloning/imaging/rescue suite/inventory management system. Prior to 1.5.10.34, packages/web/lib/fog/reportmaker.class.php in FOG was affected…

CVE-2023-46237 MEDIUM 1 year, 10 months ago

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10, an endpoint intended to offer limited en…

CVE-2023-46236 HIGH 1 year, 10 months ago

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to version 1.5.10, a server-side-request-forgery (SSRF) vul…

Related Security News

CVE-2024-39914 – Unauthenticated Command Injection in FOG Project’s export.php
2025-06-26 15:14 Offsec.com

Discover details about CVE-2024-39914, a critical unauthenticated command injection vulnerability in FOG Project ≤ 1.5.10.34. Learn how attackers can exploit export.php to execute system commands or …