Breaking News
Top Protections
Check Point Update Services Overview
In a constantly changing threat environment, defenses must evolve with or ahead of threats. Check Point Update Services provide real-time defense updates and configuration advice for IPS, URL Filtering, Antivirus & Anti-Malware, Anti-Spam & Email Security Security Service Software Blades. Also covered by Update Services are SmartDefense in NGX VPN-1, VSX, IPS-1, Connectra, Endpoint Security On Demand, and Endpoint Security products.
Key Benefits
- Pre-emptive Protection - Keep your defenses current between your regularly-scheduled product upgrades and security patches.
- Easy Management - Update your whole system in minutes. Each update comes with full configuration instructions and information about the associated threat.
- IPS, Web security, Antivirus, Anti-Malware, Web filtering, and Anti-Spam protection - Get the latest signatures and detection methods.
- Program Advisor - Update Check Point Endpoint Security with recommendations for application control for your endpoint computers.
- 24x7 Threat Coverage - Check Point Security products are supported by multiple Check Point Research and Response Centers around the globe that provided the best Microsoft vulnerability threat coverage amongst leading security vendors.
Malware Resources
| Get the Rescue CD – designed to scan, disinfect and restore infected machines that can't be disinfected with conventional malware removal tools |
Latest Protections
| Severity | Date | Check Point Reference |
Industry Reference |
Description |
|---|---|---|---|---|
| CPAI-2012-235 | CVE-2012-0779 | Adobe Flash Player Object Confusion Code Execution (APSB12-09; CVE-2012-0779) | ||
| CPAI-2012-233 | CVE-2012-1823 | PHP php-cgi Query String Parameter Code Execution (CVE-2012-1823) | ||
| CPAI-2012-232 | CVE-2012-0499 | Oracle Java Runtime TTF Heap Buffer Overflow (CVE-2012-0499) | ||
| CPAI-2012-231 | CVE-2011-4191 | Novell Netware XNFS.NLM Caller Name xdrDecodeString Heap Buffer Overflow (CVE-2011-4191) | ||
| CPAI-2012-230 | CVE-2011-3319 | Cisco WebEx Player ATDL2006.dll Heap Memory Corruption (CVE-2011-3319) | ||
| CPAI-2012-227 | CVE-2011-3045 | libpng png_inflate Buffer Overflow (CVE-2011-3045) | ||
| CPAI-2012-224 | CVE-2011-4194 | Novell iPrint Server attributes-natural-language Buffer Overflow (CVE-2011-4194) | ||
| CPAI-2012-222 | CVE-2012-0395 | EMC NetWorker nsrindexd.exe Buffer Overflow (CVE-2012-0395) | ||
| CPAI-2012-221 | CVE-2012-0501 | Oracle Java zip_util readCEN Stack Overflow (CVE-2012-0501) | ||
| CPAI-2012-220 | Novell GroupWise Messenger nmma.exe Login Memory Corruption | |||
| CPAI-2012-219 | CVE-2010-2561 | Microsoft XML Core Services Response Handling Memory Corruption (MS10-051; CVE-2010-2561) | ||
| CPAI-2012-218 | PHP htmlspecialchars htmlentities Buffer Overflow | |||
| CPAI-2012-217 | CVE-2011-3923 | Apache Struts 2 ParametersInterceptor OGNL Command Execution (CVE-2011-3923) | ||
| CPAI-2012-216 | CVE-2012-0199 | IBM Tivoli Provisioning Manager Express User.updateUserValue SQL Injection (CVE-2012-0199) | ||
| CPAI-2012-214 | CVE-2012-0199 | IBM Tivoli Provisioning Manager Express Asset.getMimeType SQL Injection (CVE-2012-0199) | ||
| CPAI-2012-213 | CVE-2010-3269 | Cisco WebEx Player Malformed .WRF File Code Execution (CVE-2010-3269) | ||
| CPAI-2012-212 | CVE-2009-2621 | Squid Proxy Invalid HTTP Request Denial of Service (CVE-2009-2621) | ||
| CPAI-2012-211 | CVE-2011-3478 | Symantec pcAnywhere Host Services Login Remote Code Execution (CVE-2011-3478) | ||
| CPAI-2012-210 | CVE-2012-0110 | Oracle Outside In Lotus 1-2-3 Heap Buffer Overflow (CVE-2012-0110) | ||
| CPAI-2012-209 | CVE-2012-0830 | PHP php_register_variable_ex Function Code Execution (CVE-2012-0830) | ||
| CPAI-2012-208 | CVE-2011-4189 | Novell GroupWise Address Book Heap Buffer Overflow (CVE-2011-4189) | ||
| CPAI-2012-207 | CVE-2011-3026 | libpng png_decompress_chunk Integer Overflow (CVE-2011-3026) | ||
| CPAI-2012-206 | CVE-2011-4789 | HP Diagnostics magentservice.exe Code Execution (CVE-2011-4789) | ||
| CPAI-2012-205 | CVE-2012-0870 | Samba smbd Packets Infinite Loop Code Execution (CVE-2012-0870) | ||
| CPAI-2012-203 | Novell eDirectory Unchecked Length Denial of Service | |||
| CPAI-2012-202 | CVE-2011-3000 | Mozilla Multiple Products Multiple Location Headers CRLF Injection (CVE-2011-3000) | ||
| CPAI-2012-201 | CVE-2011-3167 | HP OpenView Network Node Manager ov.dll Buffer Overflow (CVE-2011-3167) | ||
| CPAI-2012-196 | CVE-2011-2131 | Adobe Photoshop CS5 Malformed GIF File Code Execution (APSB11-22; CVE-2011-2131) | ||
| CPAI-2012-192 | CVE-2011-3834 | Nullsoft Winamp RIFF INFO Record Heap Buffer Overflow (CVE-2011-3834) | ||
| CPAI-2012-191 | CVE-2011-0609 | Adobe Flash Player Malformed SWF Memory Corruption (APSA11-01; CVE-2011-0609) | ||
| CPAI-2012-188 | CVE-2012-0189 | IBM SPSS VsVIEW6.ocx ActiveX control Code Execution (CVE-2012-0189) | ||
| CPAI-2012-187 | ASUS Net4Switch ipswcom.dll ActiveX Control Stack Buffer Overflow | |||
| CPAI-2012-186 | CVE-2011-4786 | HP Easy Printer Care ActiveX Control Directory Traversal (CVE-2011-4786) | ||
| CPAI-2012-185 | Citrix Provisioning Services streamprocess.exe Integer Underflow | |||
| CPAI-2012-184 | IBM solidDB ROWNUM Subquery Denial of Service | |||
| CPAI-2012-183 | Oracle Outside In OOXML Relationship Tag Parsing Stack Buffer Overflow | |||
| CPAI-2012-182 | CVE-2012-0247 | ImageMagick EXIF ResolutionUnit Handling Memory Corruption (CVE-2012-0247) | ||
| CPAI-2012-181 | CVE-2012-0444 | Mozilla Multiple Products Ogg Vorbis Decoding Memory Corruption (CVE-2012-0444) | ||
| CPAI-2012-177 | CVE-2011-4862 | Multiple Vendors BSD telnetd Encryption Key Buffer Overflow (CVE-2011-4862) | ||
| CPAI-2012-176 | CVE-2011-1388 | IBM Rational Rhapsody BBFlashBack.Recorder.dll Multiple Code Execution (CVE-2011-1388) | ||
| CPAI-2012-175 | CVE-2012-0053 | Apache HTTPD Error Code 400 httpOnly Cookie Handling Information Disclosure (CVE-2012-0053) | ||
| CPAI-2012-174 | Novell GroupWise Messenger nmma.exe createsearch Memory Corruption | |||
| CPAI-2012-172 | CVE-2011-3205 | Squid Proxy Gopher Response Processing Denial of Service (CVE-2011-3205) | ||
| CPAI-2012-171 | CVE-2011-3210 | OpenSSL Handshake Sequence Cipher Suite Use-After-Free (CVE-2011-3210) | ||
| CPAI-2012-170 | CVE-2011-3179 | Novell Groupwise Messenger Server Process Memory Information Disclosure (CVE-2011-3179) | ||
| CPAI-2012-169 | CVE-2011-4536 | WellinTech Kingview SCADA Heap Buffer Overflow (CVE-2011-4536) | ||
| CPAI-2012-168 | CVE-2011-3250 | Apple QuickTime JPEG 2000 COD Length Integer Underflow (CVE-2011-3250) | ||
| CPAI-2012-167 | CVE-2012-0021 | Apache HTTPD mod_log_config Cookie Handling Denial of Service (CVE-2012-0021) | ||
| CPAI-2012-166 | CVE-2012-0200 | IBM solidDB Redundant WHERE Clause Denial Of Service (CVE-2012-0200) | ||
| CPAI-2012-165 | CVE-2011-3166 | HP OpenView Network Node Manager webappmon.exe Buffer Overflow (CVE-2011-3166) | ||
| CPAI-2012-164 | CVE-2011-3210 | OpenSSL Handshake Requests ECDH Use-After-Free (CVE-2011-3210) | ||
| CPAI-2012-151 | CVE-2011-4259 | RealNetworks RealPlayer MPG Width Integer Underflow Memory Corruption (CVE-2011-4259) | ||
| CPAI-2012-096 | Microsoft Excel Window2 Record Use-After-Free | |||
| CPAI-2012-215 | CVE-2012-1847 | Microsoft Excel SERIES Record Parsing Code Execution (MS12-030; CVE-2012-1847) | ||
| CPAI-2012-200 | CVE-2012-0162 | Microsoft .NET Framework XBAP Buffer Allocation Code Execution (MS12-034; CVE-2012-0162) | ||
| CPAI-2012-199 | CVE-2012-0176 | Microsoft Silverlight Double-Free Remote Code Execution (MS12-034; CVE-2012-0176) | ||
| CPAI-2012-198 | CVE-2012-0159 | Microsoft Windows Malformed TrueType Font Remote Code Execution (MS12-034; CVE-2012-0159) | ||
| CPAI-2012-197 | CVE-2012-0184 | Microsoft Excel SXLI Record Memory Corruption (MS12-030; CVE-2012-0184) | ||
| CPAI-2012-195 | CVE-2012-0143 | Microsoft Excel Record Structure Memory Corruption (MS12-030; CVE-2012-0143) | ||
| CPAI-2012-194 | CVE-2012-0141 | Microsoft Excel File Format Code Execution (MS12-030; CVE-2012-0141) |
Archives
Product Updates
Security Gateway
VSX
IPS-1
Microsoft Security
Microsoft Security Bulletins 2012 in Check Point Advisories
Microsoft Security Bulletin MS12-002
- CPAI-2012-016
Microsoft Windows Object Packager Insecure Executable Launching (MS12-002; CVE-2012-0009)
Microsoft Security Bulletin MS12-004
- CPAI-2012-014
Microsoft Windows Media Player MIDI Code Execution (MS12-004; CVE-2012-0003) - CPAI-2012-019
Microsoft Windows DirectShow Filters Remote Code Execution (MS12-004; CVE-2012-0004)
Microsoft Security Bulletin MS12-005
- CPAI-2012-018
Microsoft Windows Assembly Execution Vulnerability (MS12-005; CVE-2012-0013)
Microsoft Security Bulletin MS12-006
- CPAI-2012-020
Preemptive Protection against SSL and TLS Protocols Information Disclosure (MS12-006; CVE-2011-3389)
Microsoft Security Bulletin MS12-007
- CPAI-2012-017
Microsoft AntiXSS Library Bypass Information Disclosure (MS12-007; CVE-2012-0007)
Microsoft Security Bulletin MS12-008
- CPAI-2012-013
Microsoft Windows Win32k.sys Malformed IFrame Memory Corruption (MS12-008; CVE-2011-5046)
Microsoft Security Bulletin MS12-010
- CPAI-2012-050
Internet Explorer Null Byte Information Disclosure (MS12-010; CVE-2012-0012) - CPAI-2012-053
Internet Explorer HtmlLayout Remote Code Execution (MS12-010; CVE-2012-0011) - CPAI-2012-054
Internet Explorer VML Remote Code Execution (MS12-010; CVE-2012-0155)
Microsoft Security Bulletin MS12-011
- CPAI-2012-047
Microsoft SharePoint inplview.aspx Cross-Site Scripting (MS12-011; CVE-2012-0017) - CPAI-2012-048
Microsoft SharePoint themeweb.aspx Cross-Site Scripting (MS12-011; CVE-2012-0144) - CPAI-2012-049
Microsoft SharePoint wizardlist.aspx Cross-Site Scripting (MS12-011; CVE-2012-0145)
Microsoft Security Bulletin MS12-012
- CPAI-2012-051
Microsoft Color Control Panel Insecure Library Loading (MS12-012; CVE-2010-5082)
Microsoft Security Bulletin MS12-013
- CPAI-2012-060
Microsoft Windows msvcrt.dll Media File Code Execution (MS12-013; CVE-2012-0150)
Microsoft Security Bulletin MS12-014
- CPAI-2012-061
Microsoft Windows Indeo Codec Insecure Library Loading (MS12-014; CVE-2010-3138)
Microsoft Security Bulletin MS12-015
- CPAI-2012-052
Microsoft Visio Viewer File Format Code Execution (MS12-015; CVE-2012-0020) - CPAI-2012-055
Microsoft Visio Viewer VSD File Format Memory Corruption (MS12-015; CVE-2012-0019) - CPAI-2012-057
Microsoft Visio Viewer File Format Code Execution (MS12-015; CVE-2012-0136) - CPAI-2012-058
Microsoft Visio Viewer File Format Code Execution (MS12-015; CVE-2012-0137) - CPAI-2012-059
Microsoft Visio Viewer File Format Code Execution (MS12-015; CVE-2012-0138)
Microsoft Security Bulletin MS12-016
- CPAI-2012-046
Microsoft .NET Heap Corruption Code Execution (MS12-016; CVE-2012-0015) - CPAI-2012-056
Microsoft.NET and Silevrlight Unmanaged Objects Code Execution (MS12-016; CVE-2012-0014)
Microsoft Security Bulletin MS12-017
- CPAI-2012-087
Microsoft DNS Server Denial of Service (MS12-017; CVE-2012-0006)
Microsoft Security Bulletin MS12-020
- CPAI-2012-084
Microsoft Windows Remote Desktop Protocol Code Execution (MS12-020; CVE-2012-0002) - CPAI-2012-099
Preemptive Protection against Microsoft Terminal Server Denial of Service (MS12-020; CVE-2012-0152)
Microsoft Security Bulletin MS12-021
- CPAI-2012-085
Microsoft Visual Studio Add-In Insecure Library Loading (MS12-021; CVE-2012-0008)
Microsoft Security Bulletin MS12-022
- CPAI-2012-086
Microsoft Expression Design Insecure Library Loading (MS12-022; CVE-2012-0016)
Microsoft Security Bulletin MS12-023
- CPAI-2012-124
Internet Explorer OnReadyStateChange Remote Code Execution (MS12-023; CVE-2012-0170) - CPAI-2012-125
Internet Explorer SelectAll Remote Code Execution (MS12-023; CVE-2012-0171) - CPAI-2012-127
Internet Explorer VML Style Remote Code Execution (MS12-023; CVE-2012-0172)
Microsoft Security Bulletin MS12-024
- CPAI-2012-123
Microsoft Windows Signature Validation Remote Code Execution (MS12-024; CVE-2012-0151)
Microsoft Security Bulletin MS12-027
- CPAI-2012-129
Microsoft MSCOMCTL.OCX ActiveX Control Remote Code Execution (MS12-027; CVE-2012-0158) - CPAI-2012-130
MSCOMCTL.OCX Killbit: 9181DC5F-E07D-418A-ACA6-8EEA1ECB8E9E (MS12-027; CVE-2012-0158) - CPAI-2012-131
MSCOMCTL.OCX Killbit: C74190B6-8589-11d1-B16A-00C0F0283628 (MS12-027; CVE-2012-0158) - CPAI-2012-132
MSCOMCTL.OCX Killbit: 996BF5E0-8044-4650-ADEB-0B013914E99C (MS12-027; CVE-2012-0158) - CPAI-2012-133
MSCOMCTL.OCX Killbit: bdd1f04b-858b-11d1-b16a-00c0f0283628 (MS12-027; CVE-2012-0158)
Microsoft Security Bulletin MS12-028
- CPAI-2012-128
Microsoft Office WPS Converter Heap Overflow (MS12-028; CVE-2012-0177)
Microsoft Security Bulletin MS12-029
- CPAI-2012-189
Microsoft Office RTF Mismatch Memory Corruption (MS12-029; CVE-2012-0183)
Microsoft Security Bulletin MS12-030
- CPAI-2012-178
Microsoft Excel MergeCells Record Heap Overflow (MS12-030; CVE-2012-0185) - CPAI-2012-179
Microsoft Excel File Format OBJECTLINK Record Memory Corruption (MS12-030; CVE-2012-0142) - CPAI-2012-194
Microsoft Excel File Format Code Execution (MS12-030; CVE-2012-0141) - CPAI-2012-195
Microsoft Excel Record Structure Memory Corruption (MS12-030; CVE-2012-0143) - CPAI-2012-197
Microsoft Excel SXLI Record Memory Corruption (MS12-030; CVE-2012-0184) - CPAI-2012-215
Microsoft Excel SERIES Record Parsing Code Execution (MS12-030; CVE-2012-1847)
Microsoft Security Bulletin MS12-034
- CPAI-2012-180
Microsoft Windows GDI+ Record Type Code Execution (MS12-034; CVE-2012-0165) - CPAI-2012-190
Microsoft Windows GDI+ EMF Heap Overflow (MS12-034; CVE-2012-0167) - CPAI-2012-198
Microsoft Windows Malformed TrueType Font Remote Code Execution (MS12-034; CVE-2012-0159) - CPAI-2012-199
Microsoft Silverlight Double-Free Remote Code Execution (MS12-034; CVE-2012-0176) - CPAI-2012-200
Microsoft .NET Framework XBAP Buffer Allocation Code Execution (MS12-034; CVE-2012-0162)
