Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2860▼ 336 respecto a la semana anterior
Críticas / altas1383▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 214 respecto a la semana anterior
–

157 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5)1.6%—Checkpoint Firewall-111/3/200016/6/2026
Firewall-1 3.0 and 4.0 leaks packets with private IP address information, which could allow remote attackers to determine the real IP address of the host that is making the connection.
ModificadaAlta (7.5)2.2%—Checkpoint Firewall-1Cisco PIX Firewall Software12/2/200016/6/2026
Check Point Firewall-1 allows remote attackers to bypass port access restrictions on an FTP server by forcing it to send malicious packets that Firewall-1 misinterprets as a valid 227 response to a client's PASV attempt.
ModificadaAlta (7.5)2.5%💥 ExploitCheckpoint Firewall-129/1/200016/6/2026
Firewall-1 does not properly filter script tags, which allows remote attackers to bypass the "Strip Script Tags" restriction by including an extra < in front of the SCRIPT tag.
ModificadaAlta (7.5)1.3%—Checkpoint Firewall-120/10/199916/6/2026
Firewall-1 does not properly restrict access to LDAP attributes.
ModificadaMedia (5)1.4%—Checkpoint Firewall-19/8/199916/6/2026
Check Point FireWall-1 can be subjected to a denial of service via UDP packets that are sent through VPN-1 to port 0 of a host.
ModificadaBaja (2.1)1.1%💥 ExploitCheckpoint Firewall-129/7/199916/6/2026
Firewall-1 sets a long timeout for connections that begin with ACK or other packets except SYN, allowing an attacker to conduct a denial of service via a large number of connection attempts to unresponsive systems.
ModificadaAlta (7.5)1.4%—Checkpoint Firewall-111/5/199816/6/2026
Check Point Firewall-1 does not properly handle certain restricted keywords (e.g., Mail, auth, time) in user-defined objects, which could produce a rule with a default "ANY" address and result in access to more systems than intended by the administrator.
Orbitaley — Vulnerabilidades