Lucene search

K

Checkpoint Security Vulnerabilities

cve
cve

CVE-2007-0471

sre/params.php in the Integrity Clientless Security (ICS) component in Check Point Connectra NGX R62 3.x and earlier before Security Hotfix 5, and possibly VPN-1 NGX R62, allows remote attackers to bypass security requirements via a crafted Report parameter, which returns a valid ICSCookie authenti...

7AI Score

0.553EPSS

2007-01-24 01:28 AM
73
cve
cve

CVE-2007-2174

The IOCTL handling in srescan.sys in the ZoneAlarm Spyware Removal Engine (SRE) in Check Point ZoneAlarm before 5.0.156.0 allows local users to execute arbitrary code via certain IOCTL lrp parameter addresses.

7.2AI Score

0.001EPSS

2007-04-24 04:19 PM
24
cve
cve

CVE-2007-2689

Check Point Web Intelligence does not properly handle certain full-width and half-width Unicode character encodings, which might allow remote attackers to evade detection of HTTP traffic.

6.7AI Score

0.013EPSS

2007-05-16 01:19 AM
24
cve
cve

CVE-2007-2730

Check Point ZoneAlarm Pro before 6.5.737.000 does not properly test for equivalence of process identifiers for certain Microsoft Windows API functions in the NT kernel 5.0 and greater, which allows local users to call these functions, and bypass firewall rules or gain privileges, via a modified ide...

6.5AI Score

0.0004EPSS

2007-05-16 10:30 PM
35
cve
cve

CVE-2007-3489

Cross-site request forgery (CSRF) vulnerability in pop/WizU.html in the management interface in Check Point VPN-1 Edge X Embedded NGX 7.0.33x on the Check Point VPN-1 UTM Edge allows remote attackers to perform privileged actions as administrators, as demonstrated by a request with the swuuser and ...

6.8AI Score

0.011EPSS

2007-06-29 06:30 PM
64
cve
cve

CVE-2007-4216

vsdatant.sys 6.5.737.0 in Check Point Zone Labs ZoneAlarm before 7.0.362 allows local users to gain privileges via a crafted Interrupt Request Packet (Irp) in a METHOD_NEITHER (1) IOCTL 0x8400000F or (2) IOCTL 0x84000013 request, which can be used to overwrite arbitrary memory locations.

6.5AI Score

0.0004EPSS

2007-08-21 05:17 PM
29
cve
cve

CVE-2008-0662

The Auto Local Logon feature in Check Point VPN-1 SecuRemote/SecureClient NGX R60 and R56 for Windows caches credentials under the Checkpoint\SecuRemote registry key, which has Everyone/Full Control permissions, which allows local users to gain privileges by reading and reusing the credentials.

7.8CVSS

7.7AI Score

0.0004EPSS

2008-02-08 02:00 AM
62
cve
cve

CVE-2008-1208

Cross-site scripting (XSS) vulnerability in the login page in Check Point VPN-1 UTM Edge W Embedded NGX 7.0.48x allows remote attackers to inject arbitrary web script or HTML via the user parameter.

5.7AI Score

0.004EPSS

2008-03-08 12:44 AM
63
cve
cve

CVE-2008-1397

Check Point VPN-1 Power/UTM, with NGX R60 through R65 and NG AI R55 software, allows remote authenticated users to cause a denial of service (site-to-site VPN tunnel outage), and possibly intercept network traffic, by configuring the local RFC1918 IP address to be the same as one of this tunnel's e...

6.3AI Score

0.007EPSS

2008-03-20 12:44 AM
19
cve
cve

CVE-2008-5849

Check Point VPN-1 R55, R65, and other versions, when Port Address Translation (PAT) is used, allows remote attackers to discover intranet IP addresses via a packet with a small TTL, which triggers an ICMP_TIMXCEED_INTRANS (aka ICMP time exceeded in-transit) response containing an encapsulated IP pa...

6.8AI Score

0.007EPSS

2009-01-06 05:30 PM
81
cve
cve

CVE-2008-5994

Cross-site scripting (XSS) vulnerability in index.php in Check Point Connectra NGX R62 HFA_01 allows remote attackers to inject arbitrary web script or HTML via the dir parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

5.7AI Score

0.002EPSS

2009-01-28 03:30 PM
64
cve
cve

CVE-2008-7009

Buffer overflow in multiscan.exe in Check Point ZoneAlarm Security Suite 7.0.483.000 and 8.0.020.000 allows local users to execute arbitrary code via a file or directory with a long path. NOTE: some of these details are obtained from third party information.

7.7AI Score

0.001EPSS

2009-08-19 10:30 AM
26
cve
cve

CVE-2008-7025

TrueVector in Check Point ZoneAlarm 8.0.020.000, with vsmon.exe running, allows remote HTTP proxies to cause a denial of service (crash) and disable the HIDS module via a crafted response.

6.7AI Score

0.002EPSS

2009-08-21 02:30 PM
31
cve
cve

CVE-2009-1227

NOTE: this issue has been disputed by the vendor. Buffer overflow in the PKI Web Service in Check Point Firewall-1 PKI Web Service allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) Authorization or (2) Referer HTTP header to TCP port 186...

8.3AI Score

0.12EPSS

2009-04-02 03:30 PM
68
cve
cve

CVE-2010-5184

Race condition in ZoneAlarm Extreme Security 9.1.507.000 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during h...

6.9AI Score

0.0004EPSS

2012-08-25 09:55 PM
22
cve
cve

CVE-2011-1827

Multiple unspecified vulnerabilities in Check Point SSL Network Extender (SNX), SecureWorkSpace, and Endpoint Security On-Demand, as distributed by SecurePlatform, IPSO6, Connectra, and VSX, allow remote attackers to execute arbitrary code via vectors involving a (1) ActiveX control or (2) Java app...

7.9AI Score

0.047EPSS

2011-10-05 02:56 AM
85
cve
cve

CVE-2011-2664

Unspecified vulnerability in Check Point Multi-Domain Management / Provider-1 NGX R65, R70, R71, and R75, and SmartCenter during installation on non-Windows machines, allows local users on the MDS system to overwrite arbitrary files via unknown vectors.

6.4AI Score

0.0004EPSS

2011-07-08 08:55 PM
57
cve
cve

CVE-2012-2753

Untrusted search path vulnerability in TrGUI.exe in the Endpoint Connect (aka EPC) GUI in Check Point Endpoint Security R73.x and E80.x on the VPN blade platform, Endpoint Security VPN R75, Endpoint Connect R73.x, and Remote Access Clients E75.x allows local users to gain privileges via a Trojan ho...

6.7AI Score

0.0004EPSS

2012-06-19 08:55 PM
69
cve
cve

CVE-2013-5635

Media Encryption EPM Explorer in Check Point Endpoint Security through E80.50 does not properly maintain the state of password failures, which makes it easier for physically proximate attackers to bypass the device-locking protection mechanism by entering password guesses within multiple Unlock.exe...

6.9AI Score

0.001EPSS

2013-11-30 11:43 AM
65
cve
cve

CVE-2013-5636

Unlock.exe in Media Encryption EPM Explorer in Check Point Endpoint Security through E80.50 does not associate password failures with a device ID, which makes it easier for physically proximate attackers to bypass the device-locking protection mechanism by overwriting DVREM.EPM with a copy of itsel...

6.8AI Score

0.001EPSS

2013-11-30 11:43 AM
61
cve
cve

CVE-2013-7304

Check Point Endpoint Security MI Server through R73 3.0.0 HFA2.5 does not configure X.509 certificate validation for client devices, which allows man-in-the-middle attackers to spoof SSL servers by presenting an arbitrary certificate during a session established by a client.

6.8AI Score

0.001EPSS

2014-01-22 07:55 PM
23
cve
cve

CVE-2013-7311

The OSPF implementation in Check Point Gaia OS R75.X and R76 and IPSO OS 6.2 R75.X and R76 does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial ...

6.3AI Score

0.005EPSS

2014-01-23 05:55 PM
78
cve
cve

CVE-2013-7350

Multiple unspecified vulnerabilities in Check Point Security Gateway 80 R71.x before R71.45 (730159141) and R75.20.x before R75.20.4 and 600 and 1100 appliances R75.20.x before R75.20.42 have unknown impact and attack vectors related to "important security fixes."

6.9AI Score

0.003EPSS

2014-04-01 06:35 AM
27
cve
cve

CVE-2014-1672

Check Point R75.47 Security Gateway and Management Server does not properly enforce Anti-Spoofing when the routing table is modified and the "Get - Interfaces with Topology" action is performed, which allows attackers to bypass intended access restrictions.

6.8AI Score

0.001EPSS

2014-01-26 01:55 AM
21
cve
cve

CVE-2014-1673

Check Point Session Authentication Agent allows remote attackers to obtain sensitive information (user credentials) via unspecified vectors.

6.4AI Score

0.005EPSS

2014-01-26 01:55 AM
20
cve
cve

CVE-2014-6271

GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cg...

9.8CVSS

9.9AI Score

0.974EPSS

2014-09-24 06:48 PM
2417
In Wild
12
cve
cve

CVE-2014-7169

GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the F...

9.8CVSS

8.4AI Score

0.974EPSS

2014-09-25 01:55 AM
1078
In Wild
3
cve
cve

CVE-2014-8950

Unspecified vulnerability in Check Point Security Gateway R77 and R77.10, when the (1) URL Filtering or (2) Identity Awareness blade is used, allows remote attackers to cause a denial of service (crash) via vectors involving an HTTPS request.

6.8AI Score

0.007EPSS

2014-11-16 05:59 PM
20
cve
cve

CVE-2014-8951

Unspecified vulnerability in Check Point Security Gateway R75, R76, R77, and R77.10, when UserCheck is enabled and the (1) Application Control, (2) URL Filtering, (3) DLP, (4) Threat Emulation, (5) Anti-Bot, or (6) Anti-Virus blade is used, allows remote attackers to cause a denial of service (fwk0...

6.9AI Score

0.007EPSS

2014-11-16 05:59 PM
28
cve
cve

CVE-2014-8952

Multiple unspecified vulnerabilities in Check Point Security Gateway R75.40VS, R75.45, R75.46, R75.47, R76, R77, and R77.10, when the (1) IPS blade, (2) IPsec Remote Access, (3) Mobile Access / SSL VPN blade, (4) SSL Network Extender, (5) Identify Awareness blade, (6) HTTPS Inspection, (7) UserChec...

7.2AI Score

0.007EPSS

2014-11-16 05:59 PM
29
cve
cve

CVE-2018-8790

Check Point ZoneAlarm version 15.3.064.17729 and below expose a WCF service that can allow a local low privileged user to execute arbitrary code as SYSTEM.

7.8CVSS

7.7AI Score

0.0004EPSS

2019-03-01 04:29 PM
32
cve
cve

CVE-2019-8452

A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security client for Windows before E80.96 to any file on the system will get its permission changed so that all users can access that linked file. Doing this on files with limited access gains ...

7.8CVSS

7.4AI Score

0.001EPSS

2019-04-22 10:29 PM
82
cve
cve

CVE-2019-8453

Some of the DLLs loaded by Check Point ZoneAlarm up to 15.4.062 are taken from directories where all users have write permissions. This can allow a local attacker to replace a DLL file with a malicious one and cause Denial of Service to the client.

5.5CVSS

5.4AI Score

0.0004EPSS

2019-04-17 03:29 PM
25
cve
cve

CVE-2019-8454

A local attacker can create a hard-link between a file to which the Check Point Endpoint Security client for Windows before E80.96 writes and another BAT file, then by impersonating the WPAD server, the attacker can write BAT commands into that file that will later be run by the user or the system.

7CVSS

6.8AI Score

0.0004EPSS

2019-04-29 04:29 PM
31
cve
cve

CVE-2019-8455

A hard-link created from the log file of Check Point ZoneAlarm up to 15.4.062 to any file on the system will get its permission changed so that all users can access that linked file. Doing this on files with limited access gains the local attacker higher privileges to the file.

7.1CVSS

6.7AI Score

0.0004EPSS

2019-04-17 03:29 PM
21
cve
cve

CVE-2019-8456

Check Point IKEv2 IPsec VPN up to R80.30, in some less common conditions, may allow an attacker with knowledge of the internal configuration and setup to successfully connect to a site-to-site VPN server.

5.9CVSS

5.6AI Score

0.001EPSS

2019-04-09 09:29 PM
83
cve
cve

CVE-2019-8458

Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to load a non-existent DLL during an update initiated by the UI. An attacker with administrator privileges can leverage this to gain code execution within a Check Point Software Technol...

4.4CVSS

5.2AI Score

0.001EPSS

2019-06-20 05:15 PM
105
cve
cve

CVE-2019-8459

Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executable with a name similar to the parts of the path, instead of the intended one.

9.8CVSS

9.2AI Score

0.002EPSS

2019-06-20 05:15 PM
109
cve
cve

CVE-2019-8461

Check Point Endpoint Security Initial Client for Windows before version E81.30 tries to load a DLL placed in any PATH location on a clean image without Endpoint Client installed. An attacker can leverage this to gain LPE using a specially crafted DLL placed in any PATH location accessible with writ...

7.8CVSS

7.7AI Score

0.001EPSS

2019-08-29 09:15 PM
91
cve
cve

CVE-2019-8462

In a rare scenario, Check Point R80.30 Security Gateway before JHF Take 50 managed by Check Point R80.30 Management crashes with a unique configuration of enhanced logging.

7.5CVSS

7.5AI Score

0.001EPSS

2019-10-02 05:15 PM
42
cve
cve

CVE-2019-8463

A denial of service vulnerability was reported in Check Point Endpoint Security Client for Windows before E82.10, that could allow service log file to be written to non-standard locations.

7.5CVSS

7.3AI Score

0.001EPSS

2019-12-23 07:15 PM
27
cve
cve

CVE-2020-6012

ZoneAlarm Anti-Ransomware before version 1.0.713 copies files for the report from a directory with low privileges. A sophisticated timed attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or using symbolic links. This allows an u...

7.4CVSS

7.5AI Score

0.001EPSS

2020-08-04 02:15 PM
39
cve
cve

CVE-2020-6013

ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the system to execute code at elevated privileges through a combination of file permission manipulation and exploitation of Windows CVE-2020-00896 on unpatched systems.

8.8CVSS

8.8AI Score

EPSS

2020-07-06 06:15 PM
28
cve
cve

CVE-2020-6014

Check Point Endpoint Security Client for Windows, with Anti-Bot or Threat Emulation blades installed, before version E83.20, tries to load a non-existent DLL during a query for the Domain Name. An attacker with administrator privileges can leverage this to gain code execution within a Check Point S...

6.5CVSS

6.9AI Score

0.0004EPSS

2020-11-02 09:15 PM
26
cve
cve

CVE-2020-6015

Check Point Endpoint Security for Windows before E84.10 can reach denial of service during clean install of the client which will prevent the storage of service log files in non-standard locations.

5.5CVSS

5.5AI Score

0.0004EPSS

2020-11-05 08:15 PM
21
cve
cve

CVE-2020-6020

Check Point Security Management's Internal CA web management before Jumbo HFAs R80.10 Take 278, R80.20 Take 160, R80.30 Take 210, and R80.40 Take 38, can be manipulated to run commands as a high privileged user or crash, due to weak input validation on inputs by a trusted management administrator.

6.4CVSS

6.3AI Score

0.0004EPSS

2020-09-24 02:15 PM
39
cve
cve

CVE-2020-6021

Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which the installation repair takes place. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted D...

7.8CVSS

7.5AI Score

0.0004EPSS

2020-12-03 02:15 PM
34
cve
cve

CVE-2020-6022

Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to delete arbitrary files while restoring files in Anti-Ransomware.

5.5CVSS

5.4AI Score

0.0004EPSS

2020-10-27 02:15 PM
23
cve
cve

CVE-2020-6023

Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to escalate privileges while restoring files in Anti-Ransomware.

7.8CVSS

7.5AI Score

0.0004EPSS

2020-10-27 02:15 PM
19
cve
cve

CVE-2020-6024

Check Point SmartConsole before R80.10 Build 185, R80.20 Build 119, R80.30 before Build 94, R80.40 before Build 415, and R81 before Build 548 were vulnerable to a possible local privilege escalation due to running executables from a directory with write access to all authenticated users.

7.8CVSS

7.6AI Score

0.0004EPSS

2021-01-20 07:15 PM
46
1
Total number of security vulnerabilities117