VYPR

Vendor CVEs

Checkpoint

All CVEs

152 total · sorted by risk
  • CVE-2020-6020MedSep 24, 2020
    risk 0.42cvss 6.4epss 0.01

    Check Point Security Management's Internal CA web management before Jumbo HFAs R80.10 Take 278, R80.20 Take 160, R80.30 Take 210, and R80.40 Take 38, can be manipulated to run commands as a high privileged user or crash, due to weak input validation on inputs by a trusted…

  • CVE-2024-24915MedJun 29, 2025
    risk 0.40cvss 6.1epss 0.00

    Credentials are not cleared from memory after being used. A user with Administrator permissions can execute memory dump for SmartConsole process and fetch them.

  • CVE-2019-8456MedApr 9, 2019
    risk 0.40cvss 5.9epss 0.20

    Check Point IKEv2 IPsec VPN up to R80.30, in some less common conditions, may allow an attacker with knowledge of the internal configuration and setup to successfully connect to a site-to-site VPN server.

  • CVE-2026-48134MedMay 26, 2026
    risk 0.37cvss 5.6epss 0.04

    When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific conditions, an attacker who can access the UserCheck Ask page could attempt to manipulate the Security Gateway's stored DLP/UserCheck incident information.…

  • CVE-2021-30357MedJun 8, 2021
    risk 0.36cvss 5.3epss 0.23

    SSL Network Extender Client for Linux before build 800008302 reveals part of the contents of the configuration file supplied, which allows partially disclosing files to which the user did not have access.

  • CVE-2020-6015MedNov 5, 2020
    risk 0.36cvss 5.5epss 0.00

    Check Point Endpoint Security for Windows before E84.10 can reach denial of service during clean install of the client which will prevent the storage of service log files in non-standard locations.

  • CVE-2020-6022MedOct 27, 2020
    risk 0.36cvss 5.5epss 0.00

    Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to delete arbitrary files while restoring files in Anti-Ransomware.

  • CVE-2019-8453MedApr 17, 2019
    risk 0.36cvss 5.5epss 0.00

    Some of the DLLs loaded by Check Point ZoneAlarm up to 15.4.062 are taken from directories where all users have write permissions. This can allow a local attacker to replace a DLL file with a malicious one and cause Denial of Service to the client.

  • CVE-2001-0682MedAug 29, 2001
    risk 0.36cvss 5.5epss 0.00

    ZoneAlarm and ZoneAlarm Pro allows a local attacker to cause a denial of service by running a trojan to initialize a ZoneAlarm mutex object which prevents ZoneAlarm from starting.

  • CVE-2026-48135MedMay 26, 2026
    risk 0.35cvss 5.3epss 0.03

    A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request parsing and validation.

  • CVE-2024-52888MedApr 27, 2025
    risk 0.35cvss 5.4epss 0.00

    For an authenticated end-user the portal may run a script while attempting to display a directory or some file's properties.

  • CVE-2024-24911MedFeb 6, 2025
    risk 0.34cvss 5.3epss 0.00

    In rare scenarios, the cpca process on the Security Management Server / Domain Management Server may exit unexpectedly, creating a core dump file. When the cpca process is down, VPN and SIC connectivity issues may occur if the CRL is not present in the Security Gateway's CRL…

  • CVE-2024-52885MedAug 6, 2025
    risk 0.33cvss 5.0epss 0.00

    The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File Share application) to list the file names of 'nobody'-accessible directories on the Mobile Access…

  • CVE-2019-8458MedJun 20, 2019
    risk 0.29cvss 4.4epss 0.01

    Check Point Endpoint Security Client for Windows, with Anti-Malware blade installed, before version E81.00, tries to load a non-existent DLL during an update initiated by the UI. An attacker with administrator privileges can leverage this to gain code execution within a Check…

  • CVE-2026-48136MedMay 26, 2026
    risk 0.27cvss 4.1epss 0.04

    When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has…

  • CVE-2024-52887LowApr 27, 2025
    risk 0.23cvss 3.5epss 0.00

    Authenticated end-user may set a specially crafted SNX bookmark that can make their browser run a script while accessing their own bookmark list.

  • CVE-2022-23744LowJul 7, 2022
    risk 0.15cvss 2.3epss 0.04

    Check Point Endpoint before version E86.50 failed to protect against specific registry change which allowed to disable endpoint protection by a local administrator.

  • CVE-2009-1227Apr 2, 2009
    risk 0.04cvss epss 0.07

    NOTE: this issue has been disputed by the vendor. Buffer overflow in the PKI Web Service in Check Point Firewall-1 PKI Web Service allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) Authorization or (2) Referer HTTP…

  • CVE-2002-1623Dec 31, 2002
    risk 0.04cvss epss 0.49

    The design of the Internet Key Exchange (IKE) protocol, when using Aggressive Mode for shared secret authentication, does not encrypt initiator or responder identities during negotiation, which may allow remote attackers to determine valid usernames by (1) monitoring responses…

  • CVE-2001-1303Jul 18, 2001
    risk 0.04cvss epss 0.09

    The default configuration of SecuRemote for Check Point Firewall-1 allows remote attackers to obtain sensitive configuration information for the protected network without authentication.

  • CVE-2000-0582Jun 30, 2000
    risk 0.04cvss epss 0.07

    Check Point FireWall-1 4.0 and 4.1 allows remote attackers to cause a denial of service by sending a stream of invalid commands (such as binary zeros) to the SMTP Security Server proxy.

  • CVE-2000-0482Jun 6, 2000
    risk 0.04cvss epss 0.06

    Check Point Firewall-1 allows remote attackers to cause a denial of service by sending a large number of malformed fragmented IP packets.

  • CVE-2008-7025Aug 21, 2009
    risk 0.03cvss epss 0.02

    TrueVector in Check Point ZoneAlarm 8.0.020.000, with vsmon.exe running, allows remote HTTP proxies to cause a denial of service (crash) and disable the HIDS module via a crafted response.

  • CVE-2008-7009Aug 19, 2009
    risk 0.03cvss epss 0.01

    Buffer overflow in multiscan.exe in Check Point ZoneAlarm Security Suite 7.0.483.000 and 8.0.020.000 allows local users to execute arbitrary code via a file or directory with a long path. NOTE: some of these details are obtained from third party information.

  • CVE-2008-1208Mar 8, 2008
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in the login page in Check Point VPN-1 UTM Edge W Embedded NGX 7.0.48x allows remote attackers to inject arbitrary web script or HTML via the user parameter.

  • CVE-2007-2083Apr 18, 2007
    risk 0.03cvss epss 0.01

    vsdatant.sys in Check Point Zone Labs ZoneAlarm Pro before 7.0.302.000 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local users to cause a denial of service (system crash) or possibly execute arbitrary code via crafted…

  • CVE-2005-4093Dec 8, 2005
    risk 0.03cvss epss 0.03

    Check Point VPN-1 SecureClient NG with Application Intelligence R56, NG FP1, 4.0, and 4.1 allows remote attackers to bypass security policies by modifying the local copy of the local.scv policy file after it has been downloaded from the VPN Endpoint.

  • CVE-2003-0757Oct 20, 2003
    risk 0.03cvss epss 0.03

    Check Point FireWall-1 4.0 and 4.1 before SP5 allows remote attackers to obtain the IP addresses of internal interfaces via certain SecuRemote requests to TCP ports 256 or 264, which leaks the IP addresses in a reply packet.

  • CVE-2001-0082Feb 12, 2001
    risk 0.03cvss epss 0.02

    Check Point VPN-1/FireWall-1 4.1 SP2 with Fastmode enabled allows remote attackers to bypass access restrictions via malformed, fragmented packets.

  • CVE-2000-1037Dec 11, 2000
    risk 0.03cvss epss 0.03

    Check Point Firewall-1 session agent 3.0 through 4.1 generates different error messages for invalid user names versus invalid passwords, which allows remote attackers to determine valid usernames and guess a password via a brute force attack.

  • CVE-2000-0116Jan 29, 2000
    risk 0.03cvss epss 0.02

    Firewall-1 does not properly filter script tags, which allows remote attackers to bypass the "Strip Script Tags" restriction by including an extra < in front of the SCRIPT tag.

  • CVE-1999-0770Jul 29, 1999
    risk 0.03cvss epss 0.01

    Firewall-1 sets a long timeout for connections that begin with ACK or other packets except SYN, allowing an attacker to conduct a denial of service via a large number of connection attempts to unresponsive systems.

  • CVE-2026-62144CriJul 22, 2026
    risk 0.02cvss 9.1epss 0.21

    An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on…

  • CVE-2026-62145HigJul 22, 2026
    risk 0.01cvss 7.5epss 0.08

    A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.

  • CVE-2004-0112Nov 23, 2004
    risk 0.01cvss epss 0.10

    The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake…

  • CVE-2004-0081Nov 23, 2004
    risk 0.01cvss epss 0.07

    OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool.

  • CVE-2004-0040Mar 3, 2004
    risk 0.01cvss epss 0.08

    Stack-based buffer overflow in Check Point VPN-1 Server 4.1 through 4.1 SP6 and Check Point SecuRemote/SecureClient 4.1 through 4.1 build 4200 allows remote attackers to execute arbitrary code via an ISAKMP packet with a large Certificate Request packet.

  • CVE-2004-0039Mar 3, 2004
    risk 0.01cvss epss 0.09

    Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Check Point Firewall-1 HTTP Security Server included with NG FP1, FP2, and FP3 allows remote attackers to execute arbitrary code via HTTP…

  • CVE-2014-8952Nov 16, 2014
    risk 0.00cvss epss 0.02

    Multiple unspecified vulnerabilities in Check Point Security Gateway R75.40VS, R75.45, R75.46, R75.47, R76, R77, and R77.10, when the (1) IPS blade, (2) IPsec Remote Access, (3) Mobile Access / SSL VPN blade, (4) SSL Network Extender, (5) Identify Awareness blade, (6) HTTPS…

  • CVE-2014-8951Nov 16, 2014
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in Check Point Security Gateway R75, R76, R77, and R77.10, when UserCheck is enabled and the (1) Application Control, (2) URL Filtering, (3) DLP, (4) Threat Emulation, (5) Anti-Bot, or (6) Anti-Virus blade is used, allows remote attackers to cause a…

  • CVE-2014-8950Nov 16, 2014
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in Check Point Security Gateway R77 and R77.10, when the (1) URL Filtering or (2) Identity Awareness blade is used, allows remote attackers to cause a denial of service (crash) via vectors involving an HTTPS request.

  • CVE-2013-7350Apr 1, 2014
    risk 0.00cvss epss 0.01

    Multiple unspecified vulnerabilities in Check Point Security Gateway 80 R71.x before R71.45 (730159141) and R75.20.x before R75.20.4 and 600 and 1100 appliances R75.20.x before R75.20.42 have unknown impact and attack vectors related to "important security fixes."

  • CVE-2014-1673Jan 26, 2014
    risk 0.00cvss epss 0.02

    Check Point Session Authentication Agent allows remote attackers to obtain sensitive information (user credentials) via unspecified vectors.

  • CVE-2014-1672Jan 26, 2014
    risk 0.00cvss epss 0.01

    Check Point R75.47 Security Gateway and Management Server does not properly enforce Anti-Spoofing when the routing table is modified and the "Get - Interfaces with Topology" action is performed, which allows attackers to bypass intended access restrictions.

  • CVE-2013-7311Jan 23, 2014
    risk 0.00cvss epss 0.01

    The OSPF implementation in Check Point Gaia OS R75.X and R76 and IPSO OS 6.2 R75.X and R76 does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote…

  • CVE-2013-7304Jan 22, 2014
    risk 0.00cvss epss 0.01

    Check Point Endpoint Security MI Server through R73 3.0.0 HFA2.5 does not configure X.509 certificate validation for client devices, which allows man-in-the-middle attackers to spoof SSL servers by presenting an arbitrary certificate during a session established by a client.

  • CVE-2013-5636Nov 30, 2013
    risk 0.00cvss epss 0.00

    Unlock.exe in Media Encryption EPM Explorer in Check Point Endpoint Security through E80.50 does not associate password failures with a device ID, which makes it easier for physically proximate attackers to bypass the device-locking protection mechanism by overwriting DVREM.EPM…

  • CVE-2013-5635Nov 30, 2013
    risk 0.00cvss epss 0.00

    Media Encryption EPM Explorer in Check Point Endpoint Security through E80.50 does not properly maintain the state of password failures, which makes it easier for physically proximate attackers to bypass the device-locking protection mechanism by entering password guesses within…

  • CVE-2010-5184Aug 25, 2012
    risk 0.00cvss epss 0.00

    Race condition in ZoneAlarm Extreme Security 9.1.507.000 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space…

  • CVE-2012-2753Jun 19, 2012
    risk 0.00cvss epss 0.00

    Untrusted search path vulnerability in TrGUI.exe in the Endpoint Connect (aka EPC) GUI in Check Point Endpoint Security R73.x and E80.x on the VPN blade platform, Endpoint Security VPN R75, Endpoint Connect R73.x, and Remote Access Clients E75.x allows local users to gain…