Zonealarm
Vendor:
First CVE: Feb 24, 2000 · Active for 26 years
20
Total CVEs
More Total CVEs than 95% of tracked products
2.9
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Zonealarm over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 24, 2000
26 years ago
Most Recent CVE
Sep 24, 2007
6,882 days ago
CVE Severity & Scoring
Zonealarm20 CVEs
15%
50%
35%
All CVEs353,240 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (5.0%)
Network0 (0.0%)
Unknown19 (95.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (5.0%)
High0 (0.0%)
Unknown19 (95.0%)
User Interaction
None1 (5.0%)
Unknown19 (95.0%)
Required0 (0.0%)
Privileges Required
Low1 (5.0%)
High0 (0.0%)
None0 (0.0%)
Unknown19 (95.0%)
Top CVEs
Signals from CVEs in this product scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-3560HIGH Zone Labs (1) ZoneAlarm Pro 6.0, (2) ZoneAlarm Internet Security Suite 6.0, (3) ZoneAlarm Anti-Virus 6.0, (4) ZoneAlarm Anti-Spyware 6.0 through 6.1, and (5) ZoneAlarm 6.0 allow re | Nov 16, 2005 | 7.5 | 34 | NO | YES |
CVE-2004-0309HIGH Stack-based buffer overflow in the SMTP service support in vsmon.exe in Zone Labs ZoneAlarm before 4.5.538.001, ZoneLabs Integrity client 4.0 before 4.0.146.046, and 4.5 before 4.5 | Nov 23, 2004 | 10.0 | 34 | NO | NO |
CVE-2000-0339HIGH ZoneAlarm 2.1.10 and earlier does not filter UDP packets with a source port of 67, which allows remote attackers to bypass the firewall rules. | Apr 24, 2000 | 7.5 | 31 | NO | YES |
CVE-2005-1693HIGH Integer overflow in Computer Associates Vet Antivirus library, as used by CA InoculateIT 6.0, eTrust Antivirus r6.0 through 7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTr | May 24, 2005 | 10.0 | 30 | NO | NO |
CVE-2007-2083MEDIUM vsdatant.sys in Check Point Zone Labs ZoneAlarm Pro before 7.0.302.000 does not validate certain arguments before being passed to hooked SSDT function handlers, which allows local | Apr 18, 2007 | 6.9 | 26 | NO | YES |
CVE-2003-1309HIGH The DeviceIoControl function in the TrueVector Device Driver (VSDATANT) in ZoneAlarm before 3.7.211, Pro before 4.0.146.029, and Plus before 4.0.146.029 allows local users to gain | Dec 31, 2003 | 10.0 | 25 | NO | NO |
CVE-2002-1997HIGH ZoneAlarm Pro 3.0 MailSafe allows remote attackers to bypass filtering and possibly execute arbitrary code via email attachments containing a trailing dot after the file extension. | Dec 31, 2002 | 7.5 | 25 | NO | NO |
CVE-2002-1911MEDIUM ZoneAlarm Pro 3.0 and 3.1, when configured to block all traffic, allows remote attackers to cause a denial of service (CPU and memory consumption) via a large number of SYN packets | Dec 31, 2002 | 5.0 | 23 | NO | YES |
CVE-2004-1534MEDIUM ZoneAlarm and ZoneAlarm Pro before 5.5.062, with ad-blocking enabled, allows remote web sites to cause a denial of service (application instability or system hang) via certain Java | Dec 31, 2004 | 5.0 | 19 | NO | NO |
CVE-2004-1936HIGH ZoneAlarm Pro 4.5.538.001 and possibly other versions allows remote attackers to bypass e-mail protection via attachments whose names contain certain non-English characters. | Apr 14, 2004 | 7.5 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (20 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
20.0% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (20 CVEs).
Media Mentions
Signals from CVEs in this product scope (20 CVEs).
Top CNAs Publishing CVEs For Zonealarm
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.0.362.000 | 1 | 6.9 | 0.3% | 0 | 0 |
| 6.5.737.000 | 1 | 4.9 | 0.3% | 0 | 0 |
| 6.1.744.001 | 1 | 4.9 | 0.3% | 0 | 0 |
| 6.0 | 1 | 7.5 | 13.6% | 0 | 1 |
| 5.5.062.011 | 1 | 2.1 | 0.3% | 0 | 0 |
| 5.5 | 1 | 5.0 | 1.8% | 0 | 0 |
| 5.0.590.015 | 2 | 5.0 | 1.6% | 0 | 0 |
| 4.5.538.001 | 2 | 6.7 | 1.7% | 0 | 0 |
| 4.5 | 3 | 7.5 | 4.1% | 0 | 0 |
| 4.0 | 3 | 8.3 | 5.3% | 0 | 0 |
| 3.7.211 | 1 | 10.0 | 2.3% | 0 | 0 |
| 3.7.202 | 1 | 10.0 | 2.3% | 0 | 0 |
| 3.1 | 2 | 6.3 | 2.4% | 0 | 1 |
| 3.0 | 3 | 6.7 | 2.5% | 0 | 1 |
| 2.6 | 3 | 4.3 | 1.1% | 0 | 0 |
| 2.5 | 2 | 3.5 | 1.0% | 0 | 0 |
| 2.4 | 3 | 4.3 | 1.1% | 0 | 0 |
| 2.3 | 2 | 3.5 | 1.0% | 0 | 0 |
| 2.2 | 2 | 3.5 | 1.0% | 0 | 0 |
| 2.1 | 2 | 3.5 | 1.0% | 0 | 0 |