← Vulnerability feed

Vulnerability record · CVE-2004-0039 · published 3 March 2004

CVE-2004-0039: Checkpoint firewall-1 vulnerability

Checkpoint · Firewall 1

Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Check Point Firewall-1 HTTP Security Server included with NG FP1, FP2, and FP3 allows remote attackers to execute arbitrary code via HTTP requests that cause format string specifiers to be used in an error message, as demonstrated using the scheme of a URI.

10.0 CVSS 2.0 High EPSS 9.3% · top 4.8%
10.0CVSS 2.0 base score
9.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Check Point Firewall-1 HTTP Security Server included with NG FP1, FP2, and FP3 allows remote attackers to execute arbitrary code via HTTP requests that cause format string specifiers to be used in an error message, as demonstrated using the scheme of a URI.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-0039 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-0469Checkpoint firewall-1 vulnerabilityBuffer overflow in the ISAKMP functionality for Check Point VPN-1 and FireWall-1 NG products, before VPN-1/FireWall-1 R55 HFA-03, R54 HFA-410 and NG …EPSS 5.0%10.0CVE-2004-0040Checkpoint firewall-1 vulnerabilityStack-based buffer overflow in Check Point VPN-1 Server 4.1 through 4.1 SP6 and Check Point SecuRemote/SecureClient 4.1 through 4.1 build 4200 allows…EPSS 7.6%7.8CVE-2005-3673Checkpoint check point vulnerabilityThe Internet Key Exchange version 1 (IKEv1) implementation in Check Point products allows remote attackers to cause a denial of service via certain c…EPSS 4.9%7.8CVE-2004-2679Checkpoint firewall-1 vulnerabilityCheck Point Firewall-1 4.1 up to NG AI R55 allows remote attackers to obtain potentially sensitive information by sending an Internet Key Exchange (I…EPSS 1.5%7.5CVE-2004-0079Cisco firewall services module null pointer dereference vulnerabilityThe do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) vi…EPSS 9.5%7.5CVE-2004-0699Checkpoint firewall-1 vulnerabilityHeap-based buffer overflow in ASN.1 decoding library in Check Point VPN-1 products, when Aggressive Mode IKE is implemented, allows remote attackers …EPSS 5.9%7.5CVE-2002-0428Checkpoint check point vpn vulnerabilityCheck Point FireWall-1 SecuRemote/SecuClient 4.0 and 4.1 allows clients to bypass the "authentication timeout" by modifying the to_expire or expire v…EPSS 1.6%7.5CVE-2001-0940Checkpoint firewall-1 vulnerabilityBuffer overflow in the GUI authentication code of Check Point VPN-1/FireWall-1 Management Server 4.0 and 4.1 allows remote attackers to execute arbit…EPSS 3.9%

Source: NIST National Vulnerability Database (record CVE-2004-0039), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.