Show filters
99 Total Results
Displaying 81-90 of 99
Sort by:
Attacker Value
Unknown
CVE-2008-6599
Disclosure Date: April 03, 2009 (last updated October 04, 2023)
cookiecheck.php in CookieCheck 1.0 stores tmp/cc_sessions under the web root with insufficient access control, which allows remote attackers to obtain session data via a direct request related to the "default session save path."
0
Attacker Value
Unknown
CVE-2008-5586
Disclosure Date: December 16, 2008 (last updated October 04, 2023)
SQL injection vulnerability in findoffice.php in Check Up New Generation (aka Check New) 4.52, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the search parameter.
0
Attacker Value
Unknown
CVE-2008-1397
Disclosure Date: March 20, 2008 (last updated October 04, 2023)
Check Point VPN-1 Power/UTM, with NGX R60 through R65 and NG AI R55 software, allows remote authenticated users to cause a denial of service (site-to-site VPN tunnel outage), and possibly intercept network traffic, by configuring the local RFC1918 IP address to be the same as one of this tunnel's endpoint RFC1918 IP addresses, and then using SecuRemote to connect to a network interface at the other endpoint.
0
Attacker Value
Unknown
CVE-2007-3906
Disclosure Date: July 19, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Kaspersky Anti-Virus for Check Point FireWall-1 before Critical Fix 1 (5.5.161.0) might allow attackers to cause a denial of service (kernel hang) via unspecified vectors. NOTE: it is not clear whether there is an attacker role.
0
Attacker Value
Unknown
CVE-2006-4461
Disclosure Date: August 31, 2006 (last updated October 04, 2023)
Paessler IPCheck Server Monitor before 5.3.3.639/640 does not properly implement a "list of acceptable host IP addresses in the probe settings," which has unknown impact and attack vectors.
0
Attacker Value
Unknown
CVE-2006-1321
Disclosure Date: March 20, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in webcheck before 1.9.6 allows remote attackers to inject arbitrary web script or HTML via the (1) url, (2) title, or (3) author name in a crawled page, which is not properly sanitized in the tooltips of a report.
0
Attacker Value
Unknown
CVE-2005-3673
Disclosure Date: November 18, 2005 (last updated February 22, 2025)
The Internet Key Exchange version 1 (IKEv1) implementation in Check Point products allows remote attackers to cause a denial of service via certain crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.
0
Attacker Value
Unknown
CVE-2005-0114
Disclosure Date: February 11, 2005 (last updated February 22, 2025)
vsdatant.sys in Zone Lab ZoneAlarm before 5.5.062.011, ZoneAlarm Wireless before 5.5.080.000, Check Point Integrity Client 4.x before 4.5.122.000 and 5.x before 5.1.556.166 do not properly verify that the ServerPortName argument to the NtConnectPort function is a valid memory address, which allows local users to cause a denial of service (system crash) when ZoneAlarm attempts to dereference an invalid pointer.
0
Attacker Value
Unknown
CVE-2004-1910
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
rufsi.dll in Symantec Virus Detection allows remote attackers to cause a denial of service (crash) via a long string to the GetPrivateProfileString function. NOTE: this issue was originally reported as a buffer overflow, but that specific claim is disputed by the vendor, although a crash is acknowledged.
0
Attacker Value
Unknown
CVE-2004-0404
Disclosure Date: July 07, 2004 (last updated February 22, 2025)
logcheck before 1.1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary directory in /var/tmp.
0