CVE-2005-3560 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 15.5% (pctl 97)
Patch early
A public exploit exists.
Description
Zone Labs (1) ZoneAlarm Pro 6.0, (2) ZoneAlarm Internet Security Suite 6.0, (3) ZoneAlarm Anti-Virus 6.0, (4) ZoneAlarm Anti-Spyware 6.0 through 6.1, and (5) ZoneAlarm 6.0 allow remote attackers to bypass the "Advanced Program Control and OS Firewall filters" setting via URLs in "HTML Modal Dialogs" (window.location.href) contained within JavaScript tags.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 15.53% — more likely to be exploited than 97% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-11-16 |
| Last modified | 2026-06-16 |
Affected (4)
| Vendor | Product |
|---|---|
| zonelabs | zonealarm |
| zonelabs | zonealarm anti-spyware |
| zonelabs | zonealarm antivirus |
| zonelabs | zonealarm security suite |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Zone Labs Zone Alarm 6.0 - Advance Program Control Bypass | 2005-11-07 |
References
- http://secunia.com/advisories/17450
- http://securityreason.com/securityalert/155
- http://www.osvdb.org/20677
- http://www.securityfocus.com/archive/1/415968
- http://www.securityfocus.com/bid/15347
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22971
- http://secunia.com/advisories/17450
- http://securityreason.com/securityalert/155
- http://www.osvdb.org/20677
- http://www.securityfocus.com/archive/1/415968
- http://www.securityfocus.com/bid/15347
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22971
→ the Explorer · watch your stack · NVD