checkpoint kayıtları
checkpoint üreticisine ait 135 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 7 · %5,2
- Silahlaştırılmış
- 7 · %5,2
- Pre-auth RCE
- 12
- Düzeltme kaydı olan
- %4,4
- Yayından KEV’e ortanca
- 2 gün
Tekrar eden sınıflar
- CWE-264 Permissions, Privileges, and Access Controls6
- CWE-65 Windows Hard Link5
- CWE-732 Incorrect Permission Assignment for Critical Resource5
- CWE-59 Improper Link Resolution Before File Access ('Link Following')5
- CWE-114 Process Control5
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
135 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2014-6271Silahlaştırılmış | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Kritik9,8 | KEV | %100,0 | 24 Eyl 2014 |
99Hemen | CVE-2014-7169Silahlaştırılmış | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Kritik9,8 | KEV | %99,9 | 24 Eyl 2014 |
94Hemen | CVE-2024-24919Silahlaştırılmış | Information disclosurecheckpoint · quantum spark firmware · CWE-200 | Yüksek8,6 | KEV | %100,0 | 28 May 2024 |
90Hemen | CVE-2026-16232Silahlaştırılmış | Authentication Bypass in the SmartConsole Login Process Using an Application Tokencheckpoint · multi-domain security management · CWE-287 | Kritik9,3 | KEV | %78,0 | 22 Tem 2026 |
75Bu hafta | CVE-2026-93616Silahlaştırılmış | Directory Traversal and File upload allows execution of arbitrary script on the Management Servercheckpoint · multi-domain security management · CWE-22 | Kritik9,8 | KEV | %19,7 | 22 Eyl 2026 |
71Bu hafta | CVE-2026-85102Silahlaştırılmış | Improper Certificate Validation in Quantum Security Gatewaycheckpoint · gaia embedded · CWE-295 | Kritik9,8 | KEV | %7,5 | 9 Eyl 2026 |
69Bu hafta | CVE-2026-50751Silahlaştırılmış | User Authentication Bypass in VPN Remote Access and Mobile Accesscheckpoint · gaia os · CWE-287 | Kritik9,3 | KEV | %6,3 | 8 Haz 2026 |
43Planlayın | CVE-2004-0039İstismar yok | Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Checcheckpoint · firewall-1 | Kritik10,0 | — | %9,3 | 3 Mar 2004 |
42Planlayın | CVE-2021-3449Kavram kanıtı | NULL pointer deref in signature_algorithms processingopenssl · openssl · CWE-476 | Orta5,9 | — | %63,5 | 25 Mar 2021 |
42Planlayın | CVE-2004-0040İstismar yok | Stack-based buffer overflow in Check Point VPN-1 Server 4.1 through 4.1 SP6 and Check Point SecuRemote/SecureClient 4.1 through 4.1 build 42checkpoint · firewall-1 | Kritik10,0 | — | %7,6 | 3 Mar 2004 |
42Planlayın | CVE-2009-1227Kavram kanıtı | NOTE: this issue has been disputed by the vendor.checkpoint · firewall-1 pki web service · CWE-119 | Kritik10,0 | — | %7,2 | 2 Nis 2009 |
41Planlayın | CVE-2004-0469İstismar yok | Buffer overflow in the ISAKMP functionality for Check Point VPN-1 and FireWall-1 NG products, before VPN-1/FireWall-1 R55 HFA-03, R54 HFA-41checkpoint · firewall-1 | Kritik10,0 | — | %5,0 | 7 Tem 2004 |
40Planlayın | CVE-2013-7350İstismar yok | Multiple unspecified vulnerabilities in Check Point Security Gateway 80 R71.x before R71.45 (730159141) and R75.20.x before R75.20.4 and 600checkpoint · security gateway | Kritik10,0 | — | %1,4 | 1 Nis 2014 |
39İzleyin | CVE-2019-8459İstismar yok | Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the pacheckpoint · jumbo hotfix for endpoint security server · CWE-428 | Kritik9,8 | — | %1,2 | 20 Haz 2019 |
39İzleyin | CVE-2025-3831İstismar yok | Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.checkpoint · harmony sase · CWE-200 | Kritik9,8 | — | %0,4 | 12 Ağu 2025 |
38İzleyin | CVE-2011-1827İstismar yok | Multiple unspecified vulnerabilities in Check Point SSL Network Extender (SNX), SecureWorkSpace, and Endpoint Security On-Demand, as distribcheckpoint · connectra ngx | Kritik9,3 | — | %4,5 | 4 Eki 2011 |
38İzleyin | CVE-2007-3489İstismar yok | Cross-site request forgery (CSRF) vulnerability in pop/WizU.html in the management interface in Check Point VPN-1 Edge X Embedded NGX 7.0.33checkpoint · vpn-1 utm edge | Kritik9,3 | — | %3,3 | 29 Haz 2007 |
36İzleyin | CVE-2021-30358İstismar yok | Mobile Access Portal Native Applications who's path is defined by the administrator with environment variables may run applications from othcheckpoint · mobile access portal agent · CWE-78 | Yüksek7,2 | — | %27,5 | 19 Eki 2021 |
35İzleyin | CVE-2002-1623İstismar yok | The design of the Internet Key Exchange (IKE) protocol, when using Aggressive Mode for shared secret authentication, does not encrypt initiacheckpoint · vpn-1 firewall-1 | Orta5,0 | — | %48,6 | 31 Ara 2002 |
35İzleyin | CVE-2022-23745İstismar yok | A potential memory corruption issue was found in Capsule Workspace Android app (running on GrapheneOS).checkpoint · capsule workspace · CWE-1218 | Yüksek7,5 | — | %16,5 | 18 Tem 2022 |
35İzleyin | CVE-2020-6013İstismar yok | ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the system to execute cocheckpoint · zonealarm extreme security · CWE-65 | Yüksek8,8 | — | %1,6 | 6 Tem 2020 |
35İzleyin | CVE-2022-41604İstismar yok | Check Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges.checkpoint · zonealarm · CWE-269 | Yüksek8,8 | — | %0,6 | 27 Eyl 2022 |
34İzleyin | CVE-2023-28130İstismar yok | Local user may lead to privilege escalation using Gaia Portal hostnames page.checkpoint · gaia portal · CWE-20 | Yüksek7,2 | — | %20,9 | 26 Tem 2023 |
33İzleyin | CVE-2004-0079İstismar yok | The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (openssl · openssl · CWE-476 | Yüksek7,5 | — | %9,5 | 23 Kas 2004 |
33İzleyin | CVE-2023-28133İstismar yok | Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration filecheckpoint · endpoint security · CWE-732 | Yüksek7,8 | — | %5,7 | 23 Tem 2023 |
- CVE-2014-627199Hemen
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100gnu · bash24 Eyl 2014
- CVE-2014-716999Hemen
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100gnu · bash24 Eyl 2014
- CVE-2024-2491994Hemen
Information disclosure
YüksekCVSS 8,6KEVSilahlaştırılmışEPSS %100checkpoint · quantum spark firmware28 May 2024
- CVE-2026-1623290Hemen
Authentication Bypass in the SmartConsole Login Process Using an Application Token
KritikCVSS 9,3KEVSilahlaştırılmışEPSS %78checkpoint · multi-domain security management22 Tem 2026
- CVE-2026-9361675Bu hafta
Directory Traversal and File upload allows execution of arbitrary script on the Management Server
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %20checkpoint · multi-domain security management22 Eyl 2026
- CVE-2026-8510271Bu hafta
Improper Certificate Validation in Quantum Security Gateway
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %8checkpoint · gaia embedded9 Eyl 2026
- CVE-2026-5075169Bu hafta
User Authentication Bypass in VPN Remote Access and Mobile Access
KritikCVSS 9,3KEVSilahlaştırılmışEPSS %6checkpoint · gaia os8 Haz 2026
- CVE-2004-003943Planlayın
Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Chec
KritikCVSS 10,0İstismar yokEPSS %9checkpoint · firewall-13 Mar 2004
- CVE-2021-344942Planlayın
NULL pointer deref in signature_algorithms processing
OrtaCVSS 5,9Kavram kanıtıEPSS %64openssl · openssl25 Mar 2021
- CVE-2004-004042Planlayın
Stack-based buffer overflow in Check Point VPN-1 Server 4.1 through 4.1 SP6 and Check Point SecuRemote/SecureClient 4.1 through 4.1 build 42
KritikCVSS 10,0İstismar yokEPSS %8checkpoint · firewall-13 Mar 2004
- CVE-2009-122742Planlayın
NOTE: this issue has been disputed by the vendor.
KritikCVSS 10,0Kavram kanıtıEPSS %7checkpoint · firewall-1 pki web service2 Nis 2009
- CVE-2004-046941Planlayın
Buffer overflow in the ISAKMP functionality for Check Point VPN-1 and FireWall-1 NG products, before VPN-1/FireWall-1 R55 HFA-03, R54 HFA-41
KritikCVSS 10,0İstismar yokEPSS %5checkpoint · firewall-17 Tem 2004
- CVE-2013-735040Planlayın
Multiple unspecified vulnerabilities in Check Point Security Gateway 80 R71.x before R71.45 (730159141) and R75.20.x before R75.20.4 and 600
KritikCVSS 10,0İstismar yokEPSS %1checkpoint · security gateway1 Nis 2014
- CVE-2019-845939İzleyin
Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the pa
KritikCVSS 9,8İstismar yokEPSS %1checkpoint · jumbo hotfix for endpoint security server20 Haz 2019
- CVE-2025-383139İzleyin
Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.
KritikCVSS 9,8İstismar yokEPSS %0checkpoint · harmony sase12 Ağu 2025
- CVE-2011-182738İzleyin
Multiple unspecified vulnerabilities in Check Point SSL Network Extender (SNX), SecureWorkSpace, and Endpoint Security On-Demand, as distrib
KritikCVSS 9,3İstismar yokEPSS %5checkpoint · connectra ngx4 Eki 2011
- CVE-2007-348938İzleyin
Cross-site request forgery (CSRF) vulnerability in pop/WizU.html in the management interface in Check Point VPN-1 Edge X Embedded NGX 7.0.33
KritikCVSS 9,3İstismar yokEPSS %3checkpoint · vpn-1 utm edge29 Haz 2007
- CVE-2021-3035836İzleyin
Mobile Access Portal Native Applications who's path is defined by the administrator with environment variables may run applications from oth
YüksekCVSS 7,2İstismar yokEPSS %27checkpoint · mobile access portal agent19 Eki 2021
- CVE-2002-162335İzleyin
The design of the Internet Key Exchange (IKE) protocol, when using Aggressive Mode for shared secret authentication, does not encrypt initia
OrtaCVSS 5,0İstismar yokEPSS %49checkpoint · vpn-1 firewall-131 Ara 2002
- CVE-2022-2374535İzleyin
A potential memory corruption issue was found in Capsule Workspace Android app (running on GrapheneOS).
YüksekCVSS 7,5İstismar yokEPSS %16checkpoint · capsule workspace18 Tem 2022
- CVE-2020-601335İzleyin
ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the system to execute co
YüksekCVSS 8,8İstismar yokEPSS %2checkpoint · zonealarm extreme security6 Tem 2020
- CVE-2022-4160435İzleyin
Check Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges.
YüksekCVSS 8,8İstismar yokEPSS %1checkpoint · zonealarm27 Eyl 2022
- CVE-2023-2813034İzleyin
Local user may lead to privilege escalation using Gaia Portal hostnames page.
YüksekCVSS 7,2İstismar yokEPSS %21checkpoint · gaia portal26 Tem 2023
- CVE-2004-007933İzleyin
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (
YüksekCVSS 7,5İstismar yokEPSS %10openssl · openssl23 Kas 2004
- CVE-2023-2813333İzleyin
Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration file
YüksekCVSS 7,8İstismar yokEPSS %6checkpoint · endpoint security23 Tem 2023