Show filters
28 Total Results
Displaying 11-20 of 28
Sort by:
Attacker Value
Unknown

CVE-2001-1171

Disclosure Date: April 01, 2002 (last updated February 22, 2025)
Check Point Firewall-1 3.0b through 4.0 SP1 follows symlinks and creates a world-writable temporary .cpp file when compiling Policy rules, which could allow local users to gain privileges or modify the firewall policy.
0
Attacker Value
Unknown

CVE-2001-1101

Disclosure Date: September 08, 2001 (last updated February 22, 2025)
The Log Viewer function in the Check Point FireWall-1 GUI for Solaris 3.0b through 4.1 SP2 does not check for the existence of '.log' files when saving files, which allows (1) remote authenticated users to overwrite arbitrary files ending in '.log', or (2) local users to overwrite arbitrary files via a symlink attack.
0
Attacker Value
Unknown

CVE-2001-1102

Disclosure Date: September 08, 2001 (last updated February 22, 2025)
Check Point FireWall-1 3.0b through 4.1 for Solaris allows local users to overwrite arbitrary files via a symlink attack on temporary policy files that end in a .cpp extension, which are set world-writable.
0
Attacker Value
Unknown

CVE-2000-1032

Disclosure Date: December 11, 2000 (last updated February 22, 2025)
The client authentication interface for Check Point Firewall-1 4.0 and earlier generates different error messages for invalid usernames versus invalid passwords, which allows remote attackers to identify valid usernames on the firewall.
0
Attacker Value
Unknown

CVE-2000-1037

Disclosure Date: December 11, 2000 (last updated February 22, 2025)
Check Point Firewall-1 session agent 3.0 through 4.1 generates different error messages for invalid user names versus invalid passwords, which allows remote attackers to determine valid usernames and guess a password via a brute force attack.
0
Attacker Value
Unknown

CVE-2000-0807

Disclosure Date: November 14, 2000 (last updated February 22, 2025)
The OPSEC communications authentication mechanism (fwn1) in Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to spoof connections, aka the "OPSEC Authentication Vulnerability."
0
Attacker Value
Unknown

CVE-2000-0813

Disclosure Date: November 14, 2000 (last updated February 22, 2025)
Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to redirect FTP connections to other servers ("FTP Bounce") via invalid FTP commands that are processed improperly by FireWall-1, aka "FTP Connection Enforcement Bypass."
0
Attacker Value
Unknown

CVE-2000-0805

Disclosure Date: November 14, 2000 (last updated February 22, 2025)
Check Point VPN-1/FireWall-1 4.1 and earlier improperly retransmits encapsulated FWS packets, even if they do not come from a valid FWZ client, aka "Retransmission of Encapsulated Packets."
0
Attacker Value
Unknown

CVE-2000-0809

Disclosure Date: November 14, 2000 (last updated February 22, 2025)
Buffer overflow in Getkey in the protocol checker in the inter-module communication mechanism in Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to cause a denial of service.
0
Attacker Value
Unknown

CVE-2000-0804

Disclosure Date: November 14, 2000 (last updated February 22, 2025)
Check Point VPN-1/FireWall-1 4.1 and earlier allows remote attackers to bypass the directionality check via fragmented TCP connection requests or reopening closed TCP connection requests, aka "One-way Connection Enforcement Bypass."
0