peter bassill · operator
$ cve CVE-2005-3560 JSON

CVE-2005-3560 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 15.5% (pctl 97)

Patch early

A public exploit exists.

Description

Zone Labs (1) ZoneAlarm Pro 6.0, (2) ZoneAlarm Internet Security Suite 6.0, (3) ZoneAlarm Anti-Virus 6.0, (4) ZoneAlarm Anti-Spyware 6.0 through 6.1, and (5) ZoneAlarm 6.0 allow remote attackers to bypass the "Advanced Program Control and OS Firewall filters" setting via URLs in "HTML Modal Dialogs" (window.location.href) contained within JavaScript tags.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS15.53% — more likely to be exploited than 97% of all CVEs
On CISA KEVno
Public exploityes
Published2005-11-16
Last modified2026-06-16

Affected (4)

VendorProduct
zonelabszonealarm
zonelabszonealarm anti-spyware
zonelabszonealarm antivirus
zonelabszonealarm security suite

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD