Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Zonelabs

First CVE: Feb 24, 2000Active for: 26 yearsTotal CVEs: 23
32.4
VTI Score
Medium

Zonelabs maintains a personal security software portfolio centered on endpoint protection products such as ZoneAlarm, ZoneAlarm Security Suite, and ZoneAlarm Antivirus, which have occupied a notable presence in the consumer and small-business firewall and antivirus market. The vendor's vulnerability footprint is modest in volume but concentrated enough to merit tracking, with public exploit code frequently becoming available for disclosed flaws. The recurring weakness classes—including improper locking and a range of implementation-level issues—reflect the complexity of kernel-level and system-integration code required for real-time threat monitoring and access control. Defenders running Zonelabs endpoint products should remain attentive to patching cycles, particularly where exploit tooling has surfaced; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
23
Total CVEs
More Total CVEs than 96% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Zonelabs over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 24, 2000
26 years ago
Most Recent CVE
Sep 24, 2007
6,878 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2005-3560HIGH
Zone Labs (1) ZoneAlarm Pro 6.0, (2) ZoneAlarm Internet Security Suite 6.0, (3) ZoneAlarm Anti-Virus 6.0, (4) ZoneAlarm Anti-Spyware 6.0 through 6.1, and (5) ZoneAlarm 6.0 allow re
Nov 16, 20057.534NOYES
CVE-2004-0309HIGH
Stack-based buffer overflow in the SMTP service support in vsmon.exe in Zone Labs ZoneAlarm before 4.5.538.001, ZoneLabs Integrity client 4.0 before 4.0.146.046, and 4.5 before 4.5
Nov 23, 200410.034NONO
CVE-2000-0339HIGH
ZoneAlarm 2.1.10 and earlier does not filter UDP packets with a source port of 67, which allows remote attackers to bypass the firewall rules.
Apr 24, 20007.531NOYES
CVE-2005-1693HIGH
Integer overflow in Computer Associates Vet Antivirus library, as used by CA InoculateIT 6.0, eTrust Antivirus r6.0 through 7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTr
May 24, 200510.030NONO
CVE-2007-2083MEDIUM
vsdatant.sys in Check Point Zone Labs ZoneAlarm Pro before 7.0.302.000 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local
Apr 18, 20076.926NOYES
CVE-2003-1309HIGH
The DeviceIoControl function in the TrueVector Device Driver (VSDATANT) in ZoneAlarm before 3.7.211, Pro before 4.0.146.029, and Plus before 4.0.146.029 allows local users to gain
Dec 31, 200310.025NONO
CVE-2002-1997HIGH
ZoneAlarm Pro 3.0 MailSafe allows remote attackers to bypass filtering and possibly execute arbitrary code via email attachments containing a trailing dot after the file extension.
Dec 31, 20027.525NONO
CVE-2004-1517HIGH
Zone Labs IMsecure and IMsecure Pro before 1.5 allow remote attackers to bypass Active Link Filtering via an instant message containing a URL with hex encoded file extensions.
Dec 31, 20047.524NONO
CVE-2002-1911MEDIUM
ZoneAlarm Pro 3.0 and 3.1, when configured to block all traffic, allows remote attackers to cause a denial of service (CPU and memory consumption) via a large number of SYN packets
Dec 31, 20025.023NOYES
CVE-2004-1534MEDIUM
ZoneAlarm and ZoneAlarm Pro before 5.5.062, with ad-blocking enabled, allows remote web sites to cause a denial of service (application instability or system hang) via certain Java
Dec 31, 20045.019NONO
View all 23 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products23 CVEs
13%
52%
35%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (4.3%)
Network0 (0.0%)
Unknown22 (95.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (4.3%)
High0 (0.0%)
Unknown22 (95.7%)
User Interaction
None1 (4.3%)
Unknown22 (95.7%)
Required0 (0.0%)
Privileges Required
Low1 (4.3%)
High0 (0.0%)
None0 (0.0%)
Unknown22 (95.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
17.4% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Zonelabs.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Zonelabs — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Zonelabs's Products

View all 1 CNAs →

Top CWEs