Zonealarm

Vendor:

First CVE: Feb 24, 2000 · Active for 26 years

20
Total CVEs
More Total CVEs than 95% of tracked products
2.9
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Zonealarm over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 24, 2000
26 years ago
Most Recent CVE
Sep 24, 2007
6,882 days ago

CVE Severity & Scoring

Zonealarm20 CVEs
All CVEs353,240 CVEs
LowMediumHigh
Attack Vector
Local1 (5.0%)
Network0 (0.0%)
Unknown19 (95.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (5.0%)
High0 (0.0%)
Unknown19 (95.0%)
User Interaction
None1 (5.0%)
Unknown19 (95.0%)
Required0 (0.0%)
Privileges Required
Low1 (5.0%)
High0 (0.0%)
None0 (0.0%)
Unknown19 (95.0%)

Top CVEs

Signals from CVEs in this product scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Zone Labs (1) ZoneAlarm Pro 6.0, (2) ZoneAlarm Internet Security Suite 6.0, (3) ZoneAlarm Anti-Virus 6.0, (4) ZoneAlarm Anti-Spyware 6.0 through 6.1, and (5) ZoneAlarm 6.0 allow re
Nov 16, 20057.534NOYES
Stack-based buffer overflow in the SMTP service support in vsmon.exe in Zone Labs ZoneAlarm before 4.5.538.001, ZoneLabs Integrity client 4.0 before 4.0.146.046, and 4.5 before 4.5
Nov 23, 200410.034NONO
ZoneAlarm 2.1.10 and earlier does not filter UDP packets with a source port of 67, which allows remote attackers to bypass the firewall rules.
Apr 24, 20007.531NOYES
Integer overflow in Computer Associates Vet Antivirus library, as used by CA InoculateIT 6.0, eTrust Antivirus r6.0 through 7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTr
May 24, 200510.030NONO
vsdatant.sys in Check Point Zone Labs ZoneAlarm Pro before 7.0.302.000 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local
Apr 18, 20076.926NOYES
The DeviceIoControl function in the TrueVector Device Driver (VSDATANT) in ZoneAlarm before 3.7.211, Pro before 4.0.146.029, and Plus before 4.0.146.029 allows local users to gain
Dec 31, 200310.025NONO
ZoneAlarm Pro 3.0 MailSafe allows remote attackers to bypass filtering and possibly execute arbitrary code via email attachments containing a trailing dot after the file extension.
Dec 31, 20027.525NONO
ZoneAlarm Pro 3.0 and 3.1, when configured to block all traffic, allows remote attackers to cause a denial of service (CPU and memory consumption) via a large number of SYN packets
Dec 31, 20025.023NOYES
ZoneAlarm and ZoneAlarm Pro before 5.5.062, with ad-blocking enabled, allows remote web sites to cause a denial of service (application instability or system hang) via certain Java
Dec 31, 20045.019NONO
ZoneAlarm Pro 4.5.538.001 and possibly other versions allows remote attackers to bypass e-mail protection via attachments whose names contain certain non-English characters.
Apr 14, 20047.519NONO

Exploit Exposure

Signals from CVEs in this product scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
20.0% of CVEs· 87th percentile

Social Chatter

Signals from CVEs in this product scope (20 CVEs).

Media Mentions

Signals from CVEs in this product scope (20 CVEs).

Top CNAs Publishing CVEs For Zonealarm

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.0.362.00016.90.3%00
6.5.737.00014.90.3%00
6.1.744.00114.90.3%00
6.017.513.6%01
5.5.062.01112.10.3%00
5.515.01.8%00
5.0.590.01525.01.6%00
4.5.538.00126.71.7%00
4.537.54.1%00
4.038.35.3%00
3.7.211110.02.3%00
3.7.202110.02.3%00
3.126.32.4%01
3.036.72.5%01
2.634.31.1%00
2.523.51.0%00
2.434.31.1%00
2.323.51.0%00
2.223.51.0%00
2.123.51.0%00