Записи checkpoint
135 опубликованных записей вендора checkpoint.
Профиль для исследователя
- Попали в KEV
- 7 · 5,2 %
- С эксплойтом
- 7 · 5,2 %
- Pre-auth RCE
- 12
- С записью об исправлении
- 4,4 %
- Медиана: публикация → KEV
- 2 дн.
Повторяющиеся классы
- CWE-264 Permissions, Privileges, and Access Controls6
- CWE-65 Windows Hard Link5
- CWE-732 Incorrect Permission Assignment for Critical Resource5
- CWE-59 Improper Link Resolution Before File Access ('Link Following')5
- CWE-114 Process Control5
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
135 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2014-6271Готовый эксплойт | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Критическая9,8 | KEV | 100,0 % | 24 сент. 2014 г. |
99Срочно | CVE-2014-7169Готовый эксплойт | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Критическая9,8 | KEV | 99,9 % | 24 сент. 2014 г. |
94Срочно | CVE-2024-24919Готовый эксплойт | Information disclosurecheckpoint · quantum spark firmware · CWE-200 | Высокая8,6 | KEV | 100,0 % | 28 мая 2024 г. |
90Срочно | CVE-2026-16232Готовый эксплойт | Authentication Bypass in the SmartConsole Login Process Using an Application Tokencheckpoint · multi-domain security management · CWE-287 | Критическая9,3 | KEV | 78,0 % | 22 июл. 2026 г. |
75На этой неделе | CVE-2026-93616Готовый эксплойт | Directory Traversal and File upload allows execution of arbitrary script on the Management Servercheckpoint · multi-domain security management · CWE-22 | Критическая9,8 | KEV | 19,7 % | 22 сент. 2026 г. |
71На этой неделе | CVE-2026-85102Готовый эксплойт | Improper Certificate Validation in Quantum Security Gatewaycheckpoint · gaia embedded · CWE-295 | Критическая9,8 | KEV | 7,5 % | 9 сент. 2026 г. |
69На этой неделе | CVE-2026-50751Готовый эксплойт | User Authentication Bypass in VPN Remote Access and Mobile Accesscheckpoint · gaia os · CWE-287 | Критическая9,3 | KEV | 6,3 % | 8 июн. 2026 г. |
43В плане | CVE-2004-0039Эксплойта нет | Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Checcheckpoint · firewall-1 | Критическая10,0 | — | 9,3 % | 3 мар. 2004 г. |
42В плане | CVE-2021-3449Proof of concept | NULL pointer deref in signature_algorithms processingopenssl · openssl · CWE-476 | Средняя5,9 | — | 63,5 % | 25 мар. 2021 г. |
42В плане | CVE-2004-0040Эксплойта нет | Stack-based buffer overflow in Check Point VPN-1 Server 4.1 through 4.1 SP6 and Check Point SecuRemote/SecureClient 4.1 through 4.1 build 42checkpoint · firewall-1 | Критическая10,0 | — | 7,6 % | 3 мар. 2004 г. |
42В плане | CVE-2009-1227Proof of concept | NOTE: this issue has been disputed by the vendor.checkpoint · firewall-1 pki web service · CWE-119 | Критическая10,0 | — | 7,2 % | 2 апр. 2009 г. |
41В плане | CVE-2004-0469Эксплойта нет | Buffer overflow in the ISAKMP functionality for Check Point VPN-1 and FireWall-1 NG products, before VPN-1/FireWall-1 R55 HFA-03, R54 HFA-41checkpoint · firewall-1 | Критическая10,0 | — | 5,0 % | 7 июл. 2004 г. |
40В плане | CVE-2013-7350Эксплойта нет | Multiple unspecified vulnerabilities in Check Point Security Gateway 80 R71.x before R71.45 (730159141) and R75.20.x before R75.20.4 and 600checkpoint · security gateway | Критическая10,0 | — | 1,4 % | 1 апр. 2014 г. |
39Наблюдать | CVE-2019-8459Эксплойта нет | Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the pacheckpoint · jumbo hotfix for endpoint security server · CWE-428 | Критическая9,8 | — | 1,2 % | 20 июн. 2019 г. |
39Наблюдать | CVE-2025-3831Эксплойта нет | Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.checkpoint · harmony sase · CWE-200 | Критическая9,8 | — | 0,4 % | 12 авг. 2025 г. |
38Наблюдать | CVE-2011-1827Эксплойта нет | Multiple unspecified vulnerabilities in Check Point SSL Network Extender (SNX), SecureWorkSpace, and Endpoint Security On-Demand, as distribcheckpoint · connectra ngx | Критическая9,3 | — | 4,5 % | 4 окт. 2011 г. |
38Наблюдать | CVE-2007-3489Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in pop/WizU.html in the management interface in Check Point VPN-1 Edge X Embedded NGX 7.0.33checkpoint · vpn-1 utm edge | Критическая9,3 | — | 3,3 % | 29 июн. 2007 г. |
36Наблюдать | CVE-2021-30358Эксплойта нет | Mobile Access Portal Native Applications who's path is defined by the administrator with environment variables may run applications from othcheckpoint · mobile access portal agent · CWE-78 | Высокая7,2 | — | 27,5 % | 19 окт. 2021 г. |
35Наблюдать | CVE-2002-1623Эксплойта нет | The design of the Internet Key Exchange (IKE) protocol, when using Aggressive Mode for shared secret authentication, does not encrypt initiacheckpoint · vpn-1 firewall-1 | Средняя5,0 | — | 48,6 % | 31 дек. 2002 г. |
35Наблюдать | CVE-2022-23745Эксплойта нет | A potential memory corruption issue was found in Capsule Workspace Android app (running on GrapheneOS).checkpoint · capsule workspace · CWE-1218 | Высокая7,5 | — | 16,5 % | 18 июл. 2022 г. |
35Наблюдать | CVE-2020-6013Эксплойта нет | ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the system to execute cocheckpoint · zonealarm extreme security · CWE-65 | Высокая8,8 | — | 1,6 % | 6 июл. 2020 г. |
35Наблюдать | CVE-2022-41604Эксплойта нет | Check Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges.checkpoint · zonealarm · CWE-269 | Высокая8,8 | — | 0,6 % | 27 сент. 2022 г. |
34Наблюдать | CVE-2023-28130Эксплойта нет | Local user may lead to privilege escalation using Gaia Portal hostnames page.checkpoint · gaia portal · CWE-20 | Высокая7,2 | — | 20,9 % | 26 июл. 2023 г. |
33Наблюдать | CVE-2004-0079Эксплойта нет | The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (openssl · openssl · CWE-476 | Высокая7,5 | — | 9,5 % | 23 нояб. 2004 г. |
33Наблюдать | CVE-2023-28133Эксплойта нет | Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration filecheckpoint · endpoint security · CWE-732 | Высокая7,8 | — | 5,7 % | 23 июл. 2023 г. |
- CVE-2014-627199Срочно
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2014-716999Срочно
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %gnu · bash24 сент. 2014 г.
- CVE-2024-2491994Срочно
Information disclosure
ВысокаяCVSS 8,6KEVГотовый эксплойтEPSS 100 %checkpoint · quantum spark firmware28 мая 2024 г.
- CVE-2026-1623290Срочно
Authentication Bypass in the SmartConsole Login Process Using an Application Token
КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 78 %checkpoint · multi-domain security management22 июл. 2026 г.
- CVE-2026-9361675На этой неделе
Directory Traversal and File upload allows execution of arbitrary script on the Management Server
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 20 %checkpoint · multi-domain security management22 сент. 2026 г.
- CVE-2026-8510271На этой неделе
Improper Certificate Validation in Quantum Security Gateway
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 8 %checkpoint · gaia embedded9 сент. 2026 г.
- CVE-2026-5075169На этой неделе
User Authentication Bypass in VPN Remote Access and Mobile Access
КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 6 %checkpoint · gaia os8 июн. 2026 г.
- CVE-2004-003943В плане
Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Chec
КритическаяCVSS 10,0Эксплойта нетEPSS 9 %checkpoint · firewall-13 мар. 2004 г.
- CVE-2021-344942В плане
NULL pointer deref in signature_algorithms processing
СредняяCVSS 5,9Proof of conceptEPSS 64 %openssl · openssl25 мар. 2021 г.
- CVE-2004-004042В плане
Stack-based buffer overflow in Check Point VPN-1 Server 4.1 through 4.1 SP6 and Check Point SecuRemote/SecureClient 4.1 through 4.1 build 42
КритическаяCVSS 10,0Эксплойта нетEPSS 8 %checkpoint · firewall-13 мар. 2004 г.
- CVE-2009-122742В плане
NOTE: this issue has been disputed by the vendor.
КритическаяCVSS 10,0Proof of conceptEPSS 7 %checkpoint · firewall-1 pki web service2 апр. 2009 г.
- CVE-2004-046941В плане
Buffer overflow in the ISAKMP functionality for Check Point VPN-1 and FireWall-1 NG products, before VPN-1/FireWall-1 R55 HFA-03, R54 HFA-41
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %checkpoint · firewall-17 июл. 2004 г.
- CVE-2013-735040В плане
Multiple unspecified vulnerabilities in Check Point Security Gateway 80 R71.x before R71.45 (730159141) and R75.20.x before R75.20.4 and 600
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %checkpoint · security gateway1 апр. 2014 г.
- CVE-2019-845939Наблюдать
Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the pa
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %checkpoint · jumbo hotfix for endpoint security server20 июн. 2019 г.
- CVE-2025-383139Наблюдать
Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %checkpoint · harmony sase12 авг. 2025 г.
- CVE-2011-182738Наблюдать
Multiple unspecified vulnerabilities in Check Point SSL Network Extender (SNX), SecureWorkSpace, and Endpoint Security On-Demand, as distrib
КритическаяCVSS 9,3Эксплойта нетEPSS 5 %checkpoint · connectra ngx4 окт. 2011 г.
- CVE-2007-348938Наблюдать
Cross-site request forgery (CSRF) vulnerability in pop/WizU.html in the management interface in Check Point VPN-1 Edge X Embedded NGX 7.0.33
КритическаяCVSS 9,3Эксплойта нетEPSS 3 %checkpoint · vpn-1 utm edge29 июн. 2007 г.
- CVE-2021-3035836Наблюдать
Mobile Access Portal Native Applications who's path is defined by the administrator with environment variables may run applications from oth
ВысокаяCVSS 7,2Эксплойта нетEPSS 27 %checkpoint · mobile access portal agent19 окт. 2021 г.
- CVE-2002-162335Наблюдать
The design of the Internet Key Exchange (IKE) protocol, when using Aggressive Mode for shared secret authentication, does not encrypt initia
СредняяCVSS 5,0Эксплойта нетEPSS 49 %checkpoint · vpn-1 firewall-131 дек. 2002 г.
- CVE-2022-2374535Наблюдать
A potential memory corruption issue was found in Capsule Workspace Android app (running on GrapheneOS).
ВысокаяCVSS 7,5Эксплойта нетEPSS 16 %checkpoint · capsule workspace18 июл. 2022 г.
- CVE-2020-601335Наблюдать
ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the system to execute co
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %checkpoint · zonealarm extreme security6 июл. 2020 г.
- CVE-2022-4160435Наблюдать
Check Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %checkpoint · zonealarm27 сент. 2022 г.
- CVE-2023-2813034Наблюдать
Local user may lead to privilege escalation using Gaia Portal hostnames page.
ВысокаяCVSS 7,2Эксплойта нетEPSS 21 %checkpoint · gaia portal26 июл. 2023 г.
- CVE-2004-007933Наблюдать
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (
ВысокаяCVSS 7,5Эксплойта нетEPSS 10 %openssl · openssl23 нояб. 2004 г.
- CVE-2023-2813333Наблюдать
Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration file
ВысокаяCVSS 7,8Эксплойта нетEPSS 6 %checkpoint · endpoint security23 июл. 2023 г.