Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
checkpoint check point vulnerabilities and exploits
(subscribe to this query)
4
CVSSv2
CVE-2014-1672
Check Point R75.47 Security Gateway and Management Server does not properly enforce Anti-Spoofing when the routing table is modified and the "Get - Interfaces with Topology" action is performed, which allows malicious users to bypass intended access restrictions.
Checkpoint Security Gateway R75.47
Checkpoint Management Server R75.47
3.6
CVSSv2
CVE-2020-6022
Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to delete arbitrary files while restoring files in Anti-Ransomware.
Checkpoint Zonealarm
3.6
CVSSv2
CVE-2019-8455
A hard-link created from the log file of Check Point ZoneAlarm up to 15.4.062 to any file on the system will get its permission changed so that all users can access that linked file. Doing this on files with limited access gains the local attacker higher privileges to the file.
Checkpoint Zonealarm
3.6
CVSSv2
CVE-2011-2664
Unspecified vulnerability in Check Point Multi-Domain Management / Provider-1 NGX R65, R70, R71, and R75, and SmartCenter during installation on non-Windows machines, allows local users on the MDS system to overwrite arbitrary files via unknown vectors.
Checkpoint Multi-domain Management\\/provider-1 Ngx Smartcenter
Checkpoint Multi-domain Management\\/provider-1 Ngx R71
Checkpoint Multi-domain Management\\/provider-1 Ngx R75
Checkpoint Multi-domain Management\\/provider-1 Ngx R65
Checkpoint Multi-domain Management\\/provider-1 Ngx R70
3.5
CVSSv2
CVE-2019-8458
Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to load a non-existent DLL during an update initiated by the UI. An attacker with administrator privileges can leverage this to gain code execution within a Check Poi...
Checkpoint Endpoint Security Clients
Checkpoint Remote Access Clients
Checkpoint Capsule Docs
3.3
CVSSv2
CVE-2013-5636
Unlock.exe in Media Encryption EPM Explorer in Check Point Endpoint Security through E80.50 does not associate password failures with a device ID, which makes it easier for physically proximate malicious users to bypass the device-locking protection mechanism by overwriting DVREM...
Checkpoint Endpoint Security E80.40
Checkpoint Endpoint Security E80.41
Checkpoint Endpoint Security E80.50
Checkpoint Endpoint Security E80
Checkpoint Endpoint Security E80.10
Checkpoint Endpoint Security E80.30
Checkpoint Endpoint Security E80.20
3.3
CVSSv2
CVE-2013-5635
Media Encryption EPM Explorer in Check Point Endpoint Security through E80.50 does not properly maintain the state of password failures, which makes it easier for physically proximate malicious users to bypass the device-locking protection mechanism by entering password guesses w...
Checkpoint Endpoint Security E80.40
Checkpoint Endpoint Security E80.41
Checkpoint Endpoint Security E80.50
Checkpoint Endpoint Security E80
Checkpoint Endpoint Security E80.20
Checkpoint Endpoint Security E80.10
Checkpoint Endpoint Security E80.30
2.1
CVSSv2
CVE-2022-23744
Check Point Endpoint before version E86.50 failed to protect against specific registry change which allowed to disable endpoint protection by a local administrator.
Checkpoint Endpoint Security E83
Checkpoint Endpoint Security E86.40
Checkpoint Endpoint Security E86.30
Checkpoint Endpoint Security E86.20
Checkpoint Endpoint Security E86.10
Checkpoint Endpoint Security E85
Checkpoint Endpoint Security E84
Checkpoint Harmony Endpoint E84
Checkpoint Harmony Endpoint E85
Checkpoint Harmony Endpoint E86.10
Checkpoint Harmony Endpoint E86.20
Checkpoint Harmony Endpoint E86.30
Checkpoint Harmony Endpoint E86.40
Checkpoint Harmony Endpoint E83
2.1
CVSSv2
CVE-2020-6015
Check Point Endpoint Security for Windows before E84.10 can reach denial of service during clean install of the client which will prevent the storage of service log files in non-standard locations.
Checkpoint Endpoint Security E84.10
2.1
CVSSv2
CVE-2019-8453
Some of the DLLs loaded by Check Point ZoneAlarm up to 15.4.062 are taken from directories where all users have write permissions. This can allow a local malicious user to replace a DLL file with a malicious one and cause Denial of Service to the client.
Checkpoint Zonealarm
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
firewall
CVE-2024-35649
stored XSS
CVE-2022-28654
CVE-2020-35153
CVE-2024-27348
CVE-2022-28652
local users
CVE-2017-3506
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »