Skip to main content

Vendor/product archive

zonelabs / zonealarm CVEs

Beta · best-effort

20 CVEs tagged to zonelabs / zonealarm3 Critical, 4 High, 10 Medium, 3 Low, 0 Unrated.

CVE-2007-5044

Published Sep 24, 2007

ZoneAlarm Pro 7.0.362.000 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2467

Published May 2, 2007

ZoneAlarm Pro 6.5.737.000, 6.1.744.001, and possibly earlier versions and other products, allows local users to cause a denial of service (system crash) by sending malformed data…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-2083

Published Apr 18, 2007

vsdatant.sys in Check Point Zone Labs ZoneAlarm Pro before 7.0.302.000 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-1534

Published Dec 31, 2004

ZoneAlarm and ZoneAlarm Pro before 5.5.062, with ad-blocking enabled, allows remote web sites to cause a denial of service (application instability or system hang) via certain Jav…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2713

Published Dec 31, 2004

Zone Alarm Pro 1.0 through 5.1 gives full access to %windir%\Internet Logs\* to the EVERYONE group, which allows local users to cause a denial of service by modifying the folder c…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2004-0612

Published Dec 6, 2004

The Mobile Code filter in ZoneAlarm Pro 5.0.590.015 does not filter mobile code within an SSL encrypted session, which could allow remote attackers to bypass the mobile code filte…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0309

Published Nov 23, 2004

Stack-based buffer overflow in the SMTP service support in vsmon.exe in Zone Labs ZoneAlarm before 4.5.538.001, ZoneLabs Integrity client 4.0 before 4.0.146.046, and 4.5 before 4.…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2004-1936

Published Apr 14, 2004

ZoneAlarm Pro 4.5.538.001 and possibly other versions allows remote attackers to bypass e-mail protection via attachments whose names contain certain non-English characters.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2003-1309

Published Dec 31, 2003

The DeviceIoControl function in the TrueVector Device Driver (VSDATANT) in ZoneAlarm before 3.7.211, Pro before 4.0.146.029, and Plus before 4.0.146.029 allows local users to gain…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-1911

Published Dec 31, 2002

ZoneAlarm Pro 3.0 and 3.1, when configured to block all traffic, allows remote attackers to cause a denial of service (CPU and memory consumption) via a large number of SYN packet…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1997

Published Dec 31, 2002

ZoneAlarm Pro 3.0 MailSafe allows remote attackers to bypass filtering and possibly execute arbitrary code via email attachments containing a trailing dot after the file extension.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2001-1548

Published Dec 31, 2001

ZoneAlarm 2.1 through 2.6 and ZoneAlarm Pro 2.4 and 2.6 allows local users to bypass filtering via non-standard TCP packets created with non-Windows protocol adapters.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2001-1373

Published Jul 18, 2001

MailSafe in Zone Labs ZoneAlarm 2.6 and earlier and ZoneAlarm Pro 2.6 and 2.4 does not block prohibited file types with long file names, which allows remote attackers to send pote…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0339

Published Apr 24, 2000

ZoneAlarm 2.1.10 and earlier does not filter UDP packets with a source port of 67, which allows remote attackers to bypass the firewall rules.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2000-0220

Published Feb 24, 2000

ZoneAlarm sends sensitive system and network information in cleartext to the Zone Labs server if a user requests more information about an event.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-20 of 20 CVEsPage 1 of 1