Vulnerabilities > Checkpoint

DATE CVE VULNERABILITY TITLE RISK
2007-01-24 CVE-2007-0471 Permissions, Privileges, and Access Controls vulnerability in Checkpoint Connectra NGX R60/R62
sre/params.php in the Integrity Clientless Security (ICS) component in Check Point Connectra NGX R62 3.x and earlier before Security Hotfix 5, and possibly VPN-1 NGX R62, allows remote attackers to bypass security requirements via a crafted Report parameter, which returns a valid ICSCookie authentication token.
network
low complexity
checkpoint CWE-264
7.5
2006-07-27 CVE-2006-3885 Directory Traversal vulnerability in Checkpoint Firewall-1 R55W
Directory traversal vulnerability in Check Point Firewall-1 R55W before HFA03 allows remote attackers to read arbitrary files via an encoded ..
network
low complexity
checkpoint
5.0
2006-01-18 CVE-2006-0255 Local Privilege Escalation vulnerability in Checkpoint Vpn-1 4.1
Unquoted Windows search path vulnerability in Check Point VPN-1 SecureClient might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, which is run when SecureClient attempts to launch the Sr_GUI.exe program.
local
low complexity
checkpoint
7.2
2005-12-31 CVE-2005-2932 Permissions, Privileges, and Access Controls vulnerability in Checkpoint Zonealarm and Zonealarm Security Suite
Multiple Check Point Zone Labs ZoneAlarm products before 7.0.362, including ZoneAlarm Security Suite 5.5.062.004 and 6.5.737, use insecure default permissions for critical files, which allows local users to gain privileges or bypass security controls.
local
low complexity
checkpoint CWE-264
7.2
2005-11-18 CVE-2005-3673 Denial of Service vulnerability in Check Point Firewall-1 and VPN-1 ISAKMP IKE
The Internet Key Exchange version 1 (IKEv1) implementation in Check Point products allows remote attackers to cause a denial of service via certain crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1.
network
low complexity
checkpoint
7.8
2005-09-14 CVE-2005-2889 Security Bypass vulnerability in Checkpoint Connectra NGX R60
Check Point NGX R60 does not properly verify packets against the predefined service group "CIFS" rule, which allows remote attackers to bypass intended restrictions.
network
low complexity
checkpoint
7.5
2005-07-19 CVE-2005-2313 Local Information Disclosure vulnerability in Check Point SecuRemote NG
Check Point SecuRemote NG with Application Intelligence R54 allows attackers to obtain credentials and gain privileges via unknown attack vectors.
local
low complexity
checkpoint
7.2
2005-02-11 CVE-2005-0114 Local Denial of Service vulnerability in Zone Labs ZoneAlarm
vsdatant.sys in Zone Lab ZoneAlarm before 5.5.062.011, ZoneAlarm Wireless before 5.5.080.000, Check Point Integrity Client 4.x before 4.5.122.000 and 5.x before 5.1.556.166 do not properly verify that the ServerPortName argument to the NtConnectPort function is a valid memory address, which allows local users to cause a denial of service (system crash) when ZoneAlarm attempts to dereference an invalid pointer.
local
low complexity
checkpoint zonelabs
2.1
2004-12-31 CVE-2004-2679 Information Disclosure vulnerability in Checkpoint Firewall-1 4.0/4.1/R55
Check Point Firewall-1 4.1 up to NG AI R55 allows remote attackers to obtain potentially sensitive information by sending an Internet Key Exchange (IKE) with a certain Vendor ID payload that causes Firewall-1 to return a response containing version and other information.
network
low complexity
checkpoint
7.8
2004-11-23 CVE-2004-0081 OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool. 5.0