← Back

Checkpoint

checkpoint

131 CVEs • 95 products

Products (95)

Click to collapse
Toggle
Firewall 1
firewall-1
Vpn 1
vpn-1
Zonealarm
zonealarm
Gaia Os
gaia_os
Provider 1
provider-1
Connectra Ngx
connectra_ngx
Smartconsole
smartconsole
Mobile Access
mobile_access
Gaia Portal
gaia_portal
Zonealarm Pro
zonealarm_pro
Ng Ai
ng-ai
Check Point
check_point
Express
express
Vpn 1 Utm Edge
vpn-1_utm_edge
Ipso Os
ipso_os
Ipsec Vpn
ipsec_vpn
Capsule Docs
capsule_docs
Harmony Browse
harmony_browse
Log Server
log_server
Harmony Sase
harmony_sase
Gaia Embedded
gaia_embedded
Gaia
gaia
Quantum Spark
quantum_spark
Clusterxl
clusterxl
Quantum 6700
quantum_6700

CVEs (131)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Checkpoint
1Endpoint Security
Apr 29, 2026
Nov 30, 2013
N/A· v4
N/A· v3
3.3 LOW· v2
Unlock.exe in Media Encryption EPM Explorer in Check Point Endpoint Security through E80.50 does not associate password failures with a device ID, which makes it easier for physically proximate attackers to bypass the de...Show more
Unlock.exe in Media Encryption EPM Explorer in Check Point Endpoint Security through E80.50 does not associate password failures with a device ID, which makes it easier for physically proximate attackers to bypass the device-locking protection mechanism by overwriting DVREM.EPM with a copy of itself after each few password guesses.Show less
1Checkpoint
1Endpoint Security
Apr 29, 2026
Nov 30, 2013
N/A· v4
N/A· v3
3.3 LOW· v2
Media Encryption EPM Explorer in Check Point Endpoint Security through E80.50 does not properly maintain the state of password failures, which makes it easier for physically proximate attackers to bypass the device-locki...Show more
Media Encryption EPM Explorer in Check Point Endpoint Security through E80.50 does not properly maintain the state of password failures, which makes it easier for physically proximate attackers to bypass the device-locking protection mechanism by entering password guesses within multiple Unlock.exe processes that are running simultaneously.Show less
1Checkpoint
1Zonealarm Extreme Security
Apr 29, 2026
Aug 25, 2012
N/A· v4
N/A· v3
6.2 MEDIUM· v2
Race condition in ZoneAlarm Extreme Security 9.1.507.000 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by si...Show more
Race condition in ZoneAlarm Extreme Security 9.1.507.000 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to executeShow less
1Checkpoint
4Endpoint Connect
Endpoint SecurityEndpoint Security Vpn+1 more
Apr 29, 2026
Jun 19, 2012
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Untrusted search path vulnerability in TrGUI.exe in the Endpoint Connect (aka EPC) GUI in Check Point Endpoint Security R73.x and E80.x on the VPN blade platform, Endpoint Security VPN R75, Endpoint Connect R73.x, and Re...Show more
Untrusted search path vulnerability in TrGUI.exe in the Endpoint Connect (aka EPC) GUI in Check Point Endpoint Security R73.x and E80.x on the VPN blade platform, Endpoint Security VPN R75, Endpoint Connect R73.x, and Remote Access Clients E75.x allows local users to gain privileges via a Trojan horse DLL in the current working directory.Show less
1Checkpoint
3Connectra Ngx
Vpn 1Vpn 1 Firewall 1 Vsx
Apr 29, 2026
Oct 5, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
Multiple unspecified vulnerabilities in Check Point SSL Network Extender (SNX), SecureWorkSpace, and Endpoint Security On-Demand, as distributed by SecurePlatform, IPSO6, Connectra, and VSX, allow remote attackers to exe...Show more
Multiple unspecified vulnerabilities in Check Point SSL Network Extender (SNX), SecureWorkSpace, and Endpoint Security On-Demand, as distributed by SecurePlatform, IPSO6, Connectra, and VSX, allow remote attackers to execute arbitrary code via vectors involving a (1) ActiveX control or (2) Java applet.Show less
1Checkpoint
1Multi Domain Management/provider 1
Apr 29, 2026
Jul 8, 2011
N/A· v4
N/A· v3
3.6 LOW· v2
Unspecified vulnerability in Check Point Multi-Domain Management / Provider-1 NGX R65, R70, R71, and R75, and SmartCenter during installation on non-Windows machines, allows local users on the MDS system to overwrite arb...Show more
Unspecified vulnerability in Check Point Multi-Domain Management / Provider-1 NGX R65, R70, R71, and R75, and SmartCenter during installation on non-Windows machines, allows local users on the MDS system to overwrite arbitrary files via unknown vectors.Show less
1Checkpoint
1Zonealarm
Apr 23, 2026
Aug 21, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
TrueVector in Check Point ZoneAlarm 8.0.020.000, with vsmon.exe running, allows remote HTTP proxies to cause a denial of service (crash) and disable the HIDS module via a crafted response.
1Checkpoint
1Zonealarm
Apr 23, 2026
Aug 19, 2009
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Buffer overflow in multiscan.exe in Check Point ZoneAlarm Security Suite 7.0.483.000 and 8.0.020.000 allows local users to execute arbitrary code via a file or directory with a long path. NOTE: some of these details are...Show more
Buffer overflow in multiscan.exe in Check Point ZoneAlarm Security Suite 7.0.483.000 and 8.0.020.000 allows local users to execute arbitrary code via a file or directory with a long path. NOTE: some of these details are obtained from third party information.Show less
1Checkpoint
1Firewall 1 Pki Web Service
Apr 23, 2026
Apr 2, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
NOTE: this issue has been disputed by the vendor. Buffer overflow in the PKI Web Service in Check Point Firewall-1 PKI Web Service allows remote attackers to cause a denial of service (crash) and possibly execute arbitr...Show more
NOTE: this issue has been disputed by the vendor. Buffer overflow in the PKI Web Service in Check Point Firewall-1 PKI Web Service allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) Authorization or (2) Referer HTTP header to TCP port 18624. NOTE: the vendor has disputed this issue, stating "Check Point Security Alert Team has analyzed this report. We've tried to reproduce the attack on all VPN-1 versions from NG FP2 and above with and without HFAs. The issue was not reproduced. We have conducted a thorough analysis of the relevant code and verified that we are secure against this attack. We consider this attack to pose no risk to Check Point customers." In addition, the original researcher, whose reliability is unknown as of 20090407, also states that the issue "was discovered during a pen-test where the client would not allow further analysis.Show less
1Checkpoint
1Connectra Ngx
Apr 23, 2026
Jan 28, 2009
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in index.php in Check Point Connectra NGX R62 HFA_01 allows remote attackers to inject arbitrary web script or HTML via the dir parameter. NOTE: the provenance of this informatio...Show more
Cross-site scripting (XSS) vulnerability in index.php in Check Point Connectra NGX R62 HFA_01 allows remote attackers to inject arbitrary web script or HTML via the dir parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.Show less
1Checkpoint
1Vpn 1
Apr 23, 2026
Jan 6, 2009
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Check Point VPN-1 R55, R65, and other versions, when Port Address Translation (PAT) is used, allows remote attackers to discover intranet IP addresses via a packet with a small TTL, which triggers an ICMP_TIMXCEED_INTRAN...Show more
Check Point VPN-1 R55, R65, and other versions, when Port Address Translation (PAT) is used, allows remote attackers to discover intranet IP addresses via a packet with a small TTL, which triggers an ICMP_TIMXCEED_INTRANS (aka ICMP time exceeded in-transit) response containing an encapsulated IP packet with an intranet address, as demonstrated by a TCP packet to the firewall management server on port 18264.Show less
1Checkpoint
5Check Point Vpn 1 Pro
Vpn 1Vpn 1 Firewall 1+2 more
Apr 23, 2026
Mar 20, 2008
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Check Point VPN-1 Power/UTM, with NGX R60 through R65 and NG AI R55 software, allows remote authenticated users to cause a denial of service (site-to-site VPN tunnel outage), and possibly intercept network traffic, by co...Show more
Check Point VPN-1 Power/UTM, with NGX R60 through R65 and NG AI R55 software, allows remote authenticated users to cause a denial of service (site-to-site VPN tunnel outage), and possibly intercept network traffic, by configuring the local RFC1918 IP address to be the same as one of this tunnel's endpoint RFC1918 IP addresses, and then using SecuRemote to connect to a network interface at the other endpoint.Show less
1Checkpoint
1Vpn 1 Utm Edge W Embedded Ngx
Apr 23, 2026
Mar 8, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the login page in Check Point VPN-1 UTM Edge W Embedded NGX 7.0.48x allows remote attackers to inject arbitrary web script or HTML via the user parameter.
1Checkpoint
1Vpn 1 Secureclient
Apr 23, 2026
Feb 8, 2008
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The Auto Local Logon feature in Check Point VPN-1 SecuRemote/SecureClient NGX R60 and R56 for Windows caches credentials under the Checkpoint\SecuRemote registry key, which has Everyone/Full Control permissions, which al...Show more
The Auto Local Logon feature in Check Point VPN-1 SecuRemote/SecureClient NGX R60 and R56 for Windows caches credentials under the Checkpoint\SecuRemote registry key, which has Everyone/Full Control permissions, which allows local users to gain privileges by reading and reusing the credentials.Show less
1Checkpoint
1Zonealarm
Apr 23, 2026
Aug 21, 2007
N/A· v4
N/A· v3
7.2 HIGH· v2
vsdatant.sys 6.5.737.0 in Check Point Zone Labs ZoneAlarm before 7.0.362 allows local users to gain privileges via a crafted Interrupt Request Packet (Irp) in a METHOD_NEITHER (1) IOCTL 0x8400000F or (2) IOCTL 0x84000013...Show more
vsdatant.sys 6.5.737.0 in Check Point Zone Labs ZoneAlarm before 7.0.362 allows local users to gain privileges via a crafted Interrupt Request Packet (Irp) in a METHOD_NEITHER (1) IOCTL 0x8400000F or (2) IOCTL 0x84000013 request, which can be used to overwrite arbitrary memory locations.Show less
1Checkpoint
1Vpn 1 Utm Edge
Apr 23, 2026
Jun 29, 2007
N/A· v4
N/A· v3
9.3 HIGH· v2
Cross-site request forgery (CSRF) vulnerability in pop/WizU.html in the management interface in Check Point VPN-1 Edge X Embedded NGX 7.0.33x on the Check Point VPN-1 UTM Edge allows remote attackers to perform privilege...Show more
Cross-site request forgery (CSRF) vulnerability in pop/WizU.html in the management interface in Check Point VPN-1 Edge X Embedded NGX 7.0.33x on the Check Point VPN-1 UTM Edge allows remote attackers to perform privileged actions as administrators, as demonstrated by a request with the swuuser and swupass parameters, which adds an administrator account. NOTE: the CSRF attack has no timing window because there is no logout capability in the management interface.Show less
2Checkpoint
Comodo
3Comodo Firewall Pro
Comodo Personal FirewallZonealarm
Apr 23, 2026
May 16, 2007
N/A· v4
N/A· v3
7.2 HIGH· v2
Check Point ZoneAlarm Pro before 6.5.737.000 does not properly test for equivalence of process identifiers for certain Microsoft Windows API functions in the NT kernel 5.0 and greater, which allows local users to call th...Show more
Check Point ZoneAlarm Pro before 6.5.737.000 does not properly test for equivalence of process identifiers for certain Microsoft Windows API functions in the NT kernel 5.0 and greater, which allows local users to call these functions, and bypass firewall rules or gain privileges, via a modified identifier that is one, two, or three greater than the canonical identifier.Show less
1Checkpoint
1Web Intelligence
Apr 23, 2026
May 16, 2007
N/A· v4
N/A· v3
7.8 HIGH· v2
Check Point Web Intelligence does not properly handle certain full-width and half-width Unicode character encodings, which might allow remote attackers to evade detection of HTTP traffic.
1Checkpoint
1Zonealarm
Apr 23, 2026
Apr 24, 2007
N/A· v4
N/A· v3
7.2 HIGH· v2
The IOCTL handling in srescan.sys in the ZoneAlarm Spyware Removal Engine (SRE) in Check Point ZoneAlarm before 5.0.156.0 allows local users to execute arbitrary code via certain IOCTL lrp parameter addresses.
1Checkpoint
1Connectra Ngx
Apr 23, 2026
Jan 24, 2007
N/A· v4
N/A· v3
7.5 HIGH· v2
sre/params.php in the Integrity Clientless Security (ICS) component in Check Point Connectra NGX R62 3.x and earlier before Security Hotfix 5, and possibly VPN-1 NGX R62, allows remote attackers to bypass security requir...Show more
sre/params.php in the Integrity Clientless Security (ICS) component in Check Point Connectra NGX R62 3.x and earlier before Security Hotfix 5, and possibly VPN-1 NGX R62, allows remote attackers to bypass security requirements via a crafted Report parameter, which returns a valid ICSCookie authentication token.Show less