Checkpoint
checkpoint
131 CVEs • 95 products
Products (95)
Click to collapseToggle
Products (95)
Click to collapse
CVEs (131)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Checkpoint 2Endpoint Security Harmony EndpointJun 17, 2026 Jul 7, 2022 N/A· v4 2.3 LOW· v3 2.1 LOW· v2 Check Point Endpoint before version E86.50 failed to protect against specific registry change which allowed to disable endpoint protection by a local administrator. |
1Checkpoint 1Endpoint Security Jun 17, 2026 May 12, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those files with malicious or linked content, s...Show more |
1Checkpoint 2Gaia Os Gaia PortalJun 17, 2026 May 11, 2022 N/A· v4 6.7 MEDIUM· v3 6.9 MEDIUM· v2 The Check Point Gaia Portal's GUI Clients allowed authenticated administrators with permission for the GUI Clients settings to inject a command that would run on the Gaia OS. |
Check Point ZoneAlarm before version 15.8.200.19118 allows a local actor to escalate privileges during the upgrade process. In addition, weak permissions in the ProgramData\CheckPoint\ZoneAlarm\Data\Updates directory all...Show more |
Users have access to the directory where the installation repair occurs. Since the MS Installer allows regular users to run the repair, an attacker can initiate the installation repair and place a specially crafted EXE i...Show more |
1Checkpoint 2Harmony Browse Sandblast Agent For BrowsersJun 17, 2026 Oct 22, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The Harmony Browse and the SandBlast Agent for Browsers installers must have admin privileges to execute some steps during the installation. Because the MS Installer allows regular users to repair their installation, an...Show more |
1Checkpoint 1Mobile Access Portal Agent Jun 17, 2026 Oct 19, 2021 N/A· v4 7.2 HIGH· v3 6.0 MEDIUM· v2 Mobile Access Portal Native Applications who's path is defined by the administrator with environment variables may run applications from other locations by the Mobile Access Portal Agent. |
1Checkpoint 1Ssl Network Extender Jun 17, 2026 Jun 8, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 SSL Network Extender Client for Linux before build 800008302 reveals part of the contents of the configuration file supplied, which allows partially disclosing files to which the user did not have access. |
A denial of service vulnerability was reported in Check Point Identity Agent before R81.018.0000, which could allow low privileged users to overwrite protected system files. |
12Checkpoint DebianFedoraproject+9 more106Active Iq Unified Manager Capture ClientCloud Volumes Ontap Mediator+103 moreJun 17, 2026 Mar 25, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the...Show more |
Check Point SmartConsole before R80.10 Build 185, R80.20 Build 119, R80.30 before Build 94, R80.40 before Build 415, and R81 before Build 548 were vulnerable to a possible local privilege escalation due to running execut...Show more |
Check Point Endpoint Security Client for Windows before version E84.20 allows write access to the directory from which the installation repair takes place. Since the MS Installer allows regular users to run the repair, a...Show more |
Check Point Endpoint Security for Windows before E84.10 can reach denial of service during clean install of the client which will prevent the storage of service log files in non-standard locations. |
1Checkpoint 1Endpoint Security Jun 17, 2026 Nov 2, 2020 N/A· v4 6.5 MEDIUM· v3 4.4 MEDIUM· v2 Check Point Endpoint Security Client for Windows, with Anti-Bot or Threat Emulation blades installed, before version E83.20, tries to load a non-existent DLL during a query for the Domain Name. An attacker with administr...Show more |
Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to escalate privileges while restoring files in Anti-Ransomware. |
Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to delete arbitrary files while restoring files in Anti-Ransomware. |
1Checkpoint 1Ica Management Portal Jun 17, 2026 Sep 24, 2020 N/A· v4 6.4 MEDIUM· v3 7.4 HIGH· v2 Check Point Security Management's Internal CA web management before Jumbo HFAs R80.10 Take 278, R80.20 Take 160, R80.30 Take 210, and R80.40 Take 38, can be manipulated to run commands as a high privileged user or crash,...Show more |
1Checkpoint 1Zonealarm Anti Ransomware Jun 17, 2026 Aug 4, 2020 N/A· v4 7.4 HIGH· v3 4.4 MEDIUM· v2 ZoneAlarm Anti-Ransomware before version 1.0.713 copies files for the report from a directory with low privileges. A sophisticated timed attacker can replace those files with malicious or linked content, such as exploiti...Show more |
1Checkpoint 1Zonealarm Extreme Security Jun 17, 2026 Jul 6, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the system to execute code at elevated privileges through a combination of file permission manipulation...Show more |
1Checkpoint 1Endpoint Security Clients Jun 17, 2026 Dec 23, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A denial of service vulnerability was reported in Check Point Endpoint Security Client for Windows before E82.10, that could allow service log file to be written to non-standard locations. |