Skip to content
Noroxi

checkpoint records

135 published records for vendor checkpoint.

All records

135 records
  • GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    gnu · bashSep 24, 2014

  • Information disclosure

    HighCVSS 8.6KEVWeaponizedEPSS 100%

    checkpoint · quantum spark firmwareMay 28, 2024

  • Authentication Bypass in the SmartConsole Login Process Using an Application Token

    CriticalCVSS 9.3KEVWeaponizedEPSS 78%

    checkpoint · multi-domain security managementJul 22, 2026

  • CVE-2026-93616
    75This week

    Directory Traversal and File upload allows execution of arbitrary script on the Management Server

    CriticalCVSS 9.8KEVWeaponizedEPSS 20%

    checkpoint · multi-domain security managementSep 22, 2026

  • CVE-2026-85102
    71This week

    Improper Certificate Validation in Quantum Security Gateway

    CriticalCVSS 9.8KEVWeaponizedEPSS 8%

    checkpoint · gaia embeddedSep 9, 2026

  • CVE-2026-50751
    69This week

    User Authentication Bypass in VPN Remote Access and Mobile Access

    CriticalCVSS 9.3KEVWeaponizedEPSS 6%

    checkpoint · gaia osJun 8, 2026

  • Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Chec

    CriticalCVSS 10.0No exploitEPSS 9%

    checkpoint · firewall-1Mar 3, 2004

  • NULL pointer deref in signature_algorithms processing

    MediumCVSS 5.9Proof of conceptEPSS 64%

    openssl · opensslMar 25, 2021

  • Stack-based buffer overflow in Check Point VPN-1 Server 4.1 through 4.1 SP6 and Check Point SecuRemote/SecureClient 4.1 through 4.1 build 42

    CriticalCVSS 10.0No exploitEPSS 8%

    checkpoint · firewall-1Mar 3, 2004

  • NOTE: this issue has been disputed by the vendor.

    CriticalCVSS 10.0Proof of conceptEPSS 7%

    checkpoint · firewall-1 pki web serviceApr 2, 2009

  • Buffer overflow in the ISAKMP functionality for Check Point VPN-1 and FireWall-1 NG products, before VPN-1/FireWall-1 R55 HFA-03, R54 HFA-41

    CriticalCVSS 10.0No exploitEPSS 5%

    checkpoint · firewall-1Jul 7, 2004

  • Multiple unspecified vulnerabilities in Check Point Security Gateway 80 R71.x before R71.45 (730159141) and R75.20.x before R75.20.4 and 600

    CriticalCVSS 10.0No exploitEPSS 1%

    checkpoint · security gatewayApr 1, 2014

  • CVE-2019-8459
    39Monitor

    Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the pa

    CriticalCVSS 9.8No exploitEPSS 1%

    checkpoint · jumbo hotfix for endpoint security serverJun 20, 2019

  • CVE-2025-3831
    39Monitor

    Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.

    CriticalCVSS 9.8No exploitEPSS 0%

    checkpoint · harmony saseAug 12, 2025

  • CVE-2011-1827
    38Monitor

    Multiple unspecified vulnerabilities in Check Point SSL Network Extender (SNX), SecureWorkSpace, and Endpoint Security On-Demand, as distrib

    CriticalCVSS 9.3No exploitEPSS 5%

    checkpoint · connectra ngxOct 4, 2011

  • CVE-2007-3489
    38Monitor

    Cross-site request forgery (CSRF) vulnerability in pop/WizU.html in the management interface in Check Point VPN-1 Edge X Embedded NGX 7.0.33

    CriticalCVSS 9.3No exploitEPSS 3%

    checkpoint · vpn-1 utm edgeJun 29, 2007

  • Mobile Access Portal Native Applications who's path is defined by the administrator with environment variables may run applications from oth

    HighCVSS 7.2No exploitEPSS 27%

    checkpoint · mobile access portal agentOct 19, 2021

  • CVE-2002-1623
    35Monitor

    The design of the Internet Key Exchange (IKE) protocol, when using Aggressive Mode for shared secret authentication, does not encrypt initia

    MediumCVSS 5.0No exploitEPSS 49%

    checkpoint · vpn-1 firewall-1Dec 31, 2002

  • A potential memory corruption issue was found in Capsule Workspace Android app (running on GrapheneOS).

    HighCVSS 7.5No exploitEPSS 16%

    checkpoint · capsule workspaceJul 18, 2022

  • CVE-2020-6013
    35Monitor

    ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the system to execute co

    HighCVSS 8.8No exploitEPSS 2%

    checkpoint · zonealarm extreme securityJul 6, 2020

  • Check Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges.

    HighCVSS 8.8No exploitEPSS 1%

    checkpoint · zonealarmSep 27, 2022

  • Local user may lead to privilege escalation using Gaia Portal hostnames page.

    HighCVSS 7.2No exploitEPSS 21%

    checkpoint · gaia portalJul 26, 2023

  • CVE-2004-0079
    33Monitor

    The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (

    HighCVSS 7.5No exploitEPSS 10%

    openssl · opensslNov 23, 2004

  • Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration file

    HighCVSS 7.8No exploitEPSS 6%

    checkpoint · endpoint securityJul 23, 2023