VYPR
Vendor

ZoneAlarm

Products
6
CVEs
14
Across products
14
Status
Private

Products

6

Recent CVEs

14
  • CVE-2022-41604HigSep 27, 2022
    risk 0.57cvss 8.8epss 0.01

    Check Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges. This occurs because of weak permissions for the %PROGRAMDATA%\CheckPoint\ZoneAlarm\Data\Updates directory, and a self-protection driver bypass that allows creation of a…

  • CVE-2020-6013HigJul 6, 2020
    risk 0.57cvss 8.8epss 0.02

    ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the system to execute code at elevated privileges through a combination of file permission manipulation and exploitation of Windows CVE-2020-00896 on unpatched…

  • CVE-2020-6023HigOct 27, 2020
    risk 0.51cvss 7.8epss 0.00

    Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to escalate privileges while restoring files in Anti-Ransomware.

  • CVE-2020-6012HigAug 4, 2020
    risk 0.48cvss 7.4epss 0.01

    ZoneAlarm Anti-Ransomware before version 1.0.713 copies files for the report from a directory with low privileges. A sophisticated timed attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or using symbolic…

  • CVE-2020-6022MedOct 27, 2020
    risk 0.36cvss 5.5epss 0.00

    Check Point ZoneAlarm before version 15.8.139.18543 allows a local actor to delete arbitrary files while restoring files in Anti-Ransomware.

  • CVE-2001-0682MedAug 29, 2001
    risk 0.36cvss 5.5epss 0.00

    ZoneAlarm and ZoneAlarm Pro allows a local attacker to cause a denial of service by running a trojan to initialize a ZoneAlarm mutex object which prevents ZoneAlarm from starting.

  • CVE-2010-5184Aug 25, 2012
    risk 0.00cvss epss 0.00

    Race condition in ZoneAlarm Extreme Security 9.1.507.000 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space…

  • CVE-2007-5044Sep 24, 2007
    risk 0.00cvss epss 0.00

    ZoneAlarm Pro 7.0.362.000 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via the (1) NtCreatePort and (2) NtDeleteFile kernel…

  • CVE-2007-2467May 2, 2007
    risk 0.00cvss epss 0.00

    ZoneAlarm Pro 6.5.737.000, 6.1.744.001, and possibly earlier versions and other products, allows local users to cause a denial of service (system crash) by sending malformed data to the vsdatant device driver, which causes an invalid memory access.

  • CVE-2007-0351Jan 19, 2007
    risk 0.00cvss epss 0.00

    Microsoft Windows XP and Windows Server 2003 do not properly handle user logoff, which might allow local users to gain the privileges of a previous system user, possibly related to user profile unload failure. NOTE: it is not clear whether this is an issue in Windows itself, or…

  • CVE-2004-1534Dec 31, 2004
    risk 0.00cvss epss 0.02

    ZoneAlarm and ZoneAlarm Pro before 5.5.062, with ad-blocking enabled, allows remote web sites to cause a denial of service (application instability or system hang) via certain JavaScript.

  • CVE-2004-1936Apr 14, 2004
    risk 0.00cvss epss 0.02

    ZoneAlarm Pro 4.5.538.001 and possibly other versions allows remote attackers to bypass e-mail protection via attachments whose names contain certain non-English characters.

  • CVE-2002-1997Dec 31, 2002
    risk 0.00cvss epss 0.03

    ZoneAlarm Pro 3.0 MailSafe allows remote attackers to bypass filtering and possibly execute arbitrary code via email attachments containing a trailing dot after the file extension.

  • CVE-2001-1548Dec 31, 2001
    risk 0.00cvss epss 0.00

    ZoneAlarm 2.1 through 2.6 and ZoneAlarm Pro 2.4 and 2.6 allows local users to bypass filtering via non-standard TCP packets created with non-Windows protocol adapters.