Vulnerabilities > Checkpoint > Firewall 1

DATE CVE VULNERABILITY TITLE RISK
2006-07-27 CVE-2006-3885 Directory Traversal vulnerability in Checkpoint Firewall-1 R55W
Directory traversal vulnerability in Check Point Firewall-1 R55W before HFA03 allows remote attackers to read arbitrary files via an encoded ..
network
low complexity
checkpoint
5.0
2005-11-18 CVE-2005-3673 Denial of Service vulnerability in Check Point Firewall-1 and VPN-1 ISAKMP IKE
The Internet Key Exchange version 1 (IKEv1) implementation in Check Point products allows remote attackers to cause a denial of service via certain crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.
network
low complexity
checkpoint
7.8
2004-12-31 CVE-2004-2679 Information Disclosure vulnerability in Checkpoint Firewall-1 4.0/4.1/R55
Check Point Firewall-1 4.1 up to NG AI R55 allows remote attackers to obtain potentially sensitive information by sending an Internet Key Exchange (IKE) with a certain Vendor ID payload that causes Firewall-1 to return a response containing version and other information.
network
low complexity
checkpoint
7.8
2004-11-23 CVE-2004-0081 OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool. 5.0
2004-11-23 CVE-2004-0079 NULL Pointer Dereference vulnerability in multiple products
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference.
7.5
2004-09-28 CVE-2004-0699 Buffer Overflow vulnerability in Check Point VPN-1 ASN.1
Heap-based buffer overflow in ASN.1 decoding library in Check Point VPN-1 products, when Aggressive Mode IKE is implemented, allows remote attackers to execute arbitrary code by initiating an IKE negotiation and then sending an IKE packet with malformed ASN.1 data.
network
low complexity
checkpoint
7.5
2004-07-07 CVE-2004-0469 Remote Buffer Overflow vulnerability in Check Point VPN-1 ISAKMP
Buffer overflow in the ISAKMP functionality for Check Point VPN-1 and FireWall-1 NG products, before VPN-1/FireWall-1 R55 HFA-03, R54 HFA-410 and NG FP3 HFA-325, or VPN-1 SecuRemote/SecureClient R56, may allow remote attackers to execute arbitrary code during VPN tunnel negotiation.
network
low complexity
checkpoint
critical
10.0
2004-03-03 CVE-2004-0040 Buffer Overflow vulnerability in Check Point VPN-1/SecuRemote ISAKMP Large Certificate Request Payload
Stack-based buffer overflow in Check Point VPN-1 Server 4.1 through 4.1 SP6 and Check Point SecuRemote/SecureClient 4.1 through 4.1 build 4200 allows remote attackers to execute arbitrary code via an ISAKMP packet with a large Certificate Request packet.
network
low complexity
checkpoint
critical
10.0
2004-03-03 CVE-2004-0039 Remote Format String vulnerability in Multiple Check Point Firewall-1 HTTP Security Server
Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Check Point Firewall-1 HTTP Security Server included with NG FP1, FP2, and FP3 allows remote attackers to execute arbitrary code via HTTP requests that cause format string specifiers to be used in an error message, as demonstrated using the scheme of a URI.
network
low complexity
checkpoint
critical
10.0
2003-10-20 CVE-2003-0757 Unspecified vulnerability in Checkpoint Firewall-1 4.0/4.1
Check Point FireWall-1 4.0 and 4.1 before SP5 allows remote attackers to obtain the IP addresses of internal interfaces via certain SecuRemote requests to TCP ports 256 or 264, which leaks the IP addresses in a reply packet.
network
low complexity
checkpoint
5.0