Kingsoft records
26 published records for vendor kingsoft.
Researcher profile
- Entered KEV
- 1 · 3.8%
- Weaponized
- 1 · 3.8%
- Pre-auth RCE
- 7
- With a fix record
- 3.8%
- Median publish → KEV
- 19 days
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer8
- CWE-427 Uncontrolled Search Path Element3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-276 Incorrect Default Permissions1
- CWE-310 Cryptographic Issues1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
26 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
68This week | CVE-2024-7262Weaponized | Arbitrary Code Execution in WPS Officekingsoft · wps office · CWE-22 | Critical9.3 | KEV | 2.9% | Aug 15, 2024 |
45Plan | CVE-2012-4886Proof of concept | Stack-based buffer overflow in wpsio.dll in Kingsoft WPS Office 2012 possibly 8.1.0.3238 allows remote attackers to execute arbitrary code vkingsoft · office 2012 · CWE-119 | Critical10.0 | — | 15.3% | Mar 24, 2014 |
44Plan | CVE-2008-1307Proof of concept | Heap-based buffer overflow in the KUpdateObj2 Class ActiveX control in UpdateOcx2.dll in Beijing KingSoft Antivirus Online Update Module 200kingsoft · antivirus online update module · CWE-119 | Critical10.0 | — | 15.0% | Mar 12, 2008 |
40Plan | CVE-2013-3934Proof of concept | Stack-based buffer overflow in Kingsoft Writer 2012 8.1.0.3030, as used in Kingsoft Office 2013 before 9.1.0.4256, allows remote attackers tkingsoft · office 2012 · CWE-119 | Critical9.3 | — | 9.8% | Sep 10, 2013 |
38Monitor | CVE-2013-0710No exploit | Buffer overflow in Kingsoft Writer 2007 and 2010 before 2724 allows remote attackers to execute arbitrary code via a crafted RTF document.kingsoft · writer 2007 · CWE-119 | Critical9.3 | — | 4.3% | Mar 5, 2013 |
38Monitor | CVE-2013-0723No exploit | Multiple heap-based buffer overflows in etxrw.dll in Kingsoft Spreadsheets 2012 8.1.0.3030 allow remote attackers to cause a denial of servikingsoft · spreadsheets 2012 · CWE-119 | Critical9.3 | — | 4.2% | Jul 29, 2013 |
37Monitor | CVE-2024-7263No exploit | Arbitrary Code Execution in WPS Officekingsoft · wps office · CWE-22 | Critical9.3 | — | 0.4% | Aug 15, 2024 |
32Monitor | CVE-2023-31275No exploit | An uninitialized pointer use vulnerability exists in the functionality of WPS Office 11.2.0.11537 that handles Data elements in an Excel filkingsoft · wps office · CWE-457 | High7.8 | — | 1.7% | Nov 27, 2023 |
32Monitor | CVE-2023-32548No exploit | OS command injection vulnerability exists in WPS Office version 10.8.0.6186.kingsoft · wps office · CWE-78 | High8.1 | — | 1.1% | Jun 13, 2023 |
31Monitor | CVE-2020-25291No exploit | GdiDrawHoriLineIAlt in Kingsoft WPS Office before 11.2.0.9403 allows remote heap corruption via a crafted PLTE chunk in PNG data within a Wokingsoft · wps office · CWE-787 | High7.8 | — | 1.6% | Sep 13, 2020 |
31Monitor | CVE-2022-26081No exploit | The installer of WPS Office Version 10.8.0.5745 insecurely load shcore.dll, allowing an attacker to execute arbitrary code with the privilegkingsoft · wps office · CWE-427 | High7.8 | — | 0.8% | Mar 17, 2022 |
31Monitor | CVE-2022-25969No exploit | The installer of WPS Office Version 10.8.0.6186 insecurely load VERSION.DLL (or some other DLLs), allowing an attacker to execute arbitrary kingsoft · wps office · CWE-427 | High7.8 | — | 0.8% | Mar 17, 2022 |
31Monitor | CVE-2024-35205Proof of concept | The WPS Office (aka cn.wps.moffice_eng) application before 17.0.0 for Android fails to properly sanitize file names before processing them tCWE-22 | High7.8 | — | 0.8% | May 14, 2024 |
31Monitor | CVE-2022-25949Proof of concept | The kernel mode driver kwatch3 of KINGSOFT Internet Security 9 Plus Version 2010.06.23.247 fails to properly handle crafted inputs, leading kingsoft · internet security 9 plus · CWE-121 | High7.8 | — | 0.8% | Mar 17, 2022 |
31Monitor | CVE-2022-25943Proof of concept | The installer of WPS Office for Windows versions prior to v11.2.0.10258 fails to configure properly the ACL for the directory where the servkingsoft · wps office · CWE-276 | High7.8 | — | 0.7% | Mar 9, 2022 |
31Monitor | CVE-2022-26511No exploit | WPS Presentation 11.8.0.5745 insecurely load d3dx9_41.dll when opening .pps files('current directory type' DLL loading).kingsoft · wps presentation · CWE-427 | High7.8 | — | 0.6% | Mar 17, 2022 |
28Monitor | CVE-2010-3396Proof of concept | Buffer overflow in kavfm.sys in Kingsoft Antivirus 2010.04.26.648 and earlier allows local users to execute arbitrary code via a long argumekingsoft · kingsoft antivirus · CWE-119 | High7.2 | — | 1.1% | Sep 15, 2010 |
28Monitor | CVE-2010-2031Proof of concept | KAVSafe.sys 2010.4.14.609 and earlier, as used in Kingsoft Webshield 3.5.1.2 and earlier, allows local users to overwrite arbitrary kernel mkingsoft · webshield · CWE-119 | High7.2 | — | 0.8% | May 24, 2010 |
23Monitor | CVE-2013-5999No exploit | Kingsoft KDrive Personal before 1.21.0.1880 on Windows does not verify X.509 certificates from SSL servers, which allows man-in-the-middle akingsoft · kdrive · CWE-310 | Medium5.8 | — | 0.6% | Nov 22, 2013 |
22Monitor | CVE-2018-7546No exploit | wpsmain.dll in Kingsoft WPS Office 2016 and Jinshan PDF 10.1.0.6621 allows remote attackers to cause a denial of service via a crafted pdf fkingsoft · jinshan pdf · CWE-119 | Medium5.5 | — | 1.4% | Jul 18, 2018 |
22Monitor | CVE-2018-9151No exploit | A NULL pointer dereference bug in the function ObReferenceObjectByHandle in the Kingsoft Internet Security 9+ kernel driver KWatch3.sys allokingsoft · internet security 9 plus · CWE-476 | Medium5.5 | — | 0.3% | Mar 30, 2018 |
22Monitor | CVE-2024-57096No exploit | An issue in wps office before v.19302 allows a local attacker to obtain sensitive information via a crafted file.kingsoft · wps office · CWE-200 | Medium5.5 | — | 0.2% | May 14, 2025 |
21Monitor | CVE-2004-1494No exploit | Buffer overflow in the Screen Fetch option in XDICT 2002 through 2005 allows remote attackers to cause a denial of service ( CPU consumptionkingsoft · xdict | Medium5.0 | — | 3.7% | Dec 31, 2004 |
21Monitor | CVE-2010-5164No exploit | Race condition in KingSoft Personal Firewall 9 Plus 2009.05.07.70 on Windows XP allows local users to bypass kernel-mode hook handlers, and kingsoft · personal firewall 9 · CWE-362 | Medium5.3 | — | 0.4% | Aug 25, 2012 |
8Monitor | CVE-2011-0515Proof of concept | KisKrnl.sys 2011.1.13.89 and earlier in Kingsoft AntiVirus 2011 SP5.2 allows local users to cause a denial of service (crash) via a crafted kingsoft · kingsoft antivirus | Low2.1 | — | 0.9% | Jan 20, 2011 |
- CVE-2024-726268This week
Arbitrary Code Execution in WPS Office
CriticalCVSS 9.3KEVWeaponizedEPSS 3%kingsoft · wps officeAug 15, 2024
- CVE-2012-488645Plan
Stack-based buffer overflow in wpsio.dll in Kingsoft WPS Office 2012 possibly 8.1.0.3238 allows remote attackers to execute arbitrary code v
CriticalCVSS 10.0Proof of conceptEPSS 15%kingsoft · office 2012Mar 24, 2014
- CVE-2008-130744Plan
Heap-based buffer overflow in the KUpdateObj2 Class ActiveX control in UpdateOcx2.dll in Beijing KingSoft Antivirus Online Update Module 200
CriticalCVSS 10.0Proof of conceptEPSS 15%kingsoft · antivirus online update moduleMar 12, 2008
- CVE-2013-393440Plan
Stack-based buffer overflow in Kingsoft Writer 2012 8.1.0.3030, as used in Kingsoft Office 2013 before 9.1.0.4256, allows remote attackers t
CriticalCVSS 9.3Proof of conceptEPSS 10%kingsoft · office 2012Sep 10, 2013
- CVE-2013-071038Monitor
Buffer overflow in Kingsoft Writer 2007 and 2010 before 2724 allows remote attackers to execute arbitrary code via a crafted RTF document.
CriticalCVSS 9.3No exploitEPSS 4%kingsoft · writer 2007Mar 5, 2013
- CVE-2013-072338Monitor
Multiple heap-based buffer overflows in etxrw.dll in Kingsoft Spreadsheets 2012 8.1.0.3030 allow remote attackers to cause a denial of servi
CriticalCVSS 9.3No exploitEPSS 4%kingsoft · spreadsheets 2012Jul 29, 2013
- CVE-2024-726337Monitor
Arbitrary Code Execution in WPS Office
CriticalCVSS 9.3No exploitEPSS 0%kingsoft · wps officeAug 15, 2024
- CVE-2023-3127532Monitor
An uninitialized pointer use vulnerability exists in the functionality of WPS Office 11.2.0.11537 that handles Data elements in an Excel fil
HighCVSS 7.8No exploitEPSS 2%kingsoft · wps officeNov 27, 2023
- CVE-2023-3254832Monitor
OS command injection vulnerability exists in WPS Office version 10.8.0.6186.
HighCVSS 8.1No exploitEPSS 1%kingsoft · wps officeJun 13, 2023
- CVE-2020-2529131Monitor
GdiDrawHoriLineIAlt in Kingsoft WPS Office before 11.2.0.9403 allows remote heap corruption via a crafted PLTE chunk in PNG data within a Wo
HighCVSS 7.8No exploitEPSS 2%kingsoft · wps officeSep 13, 2020
- CVE-2022-2608131Monitor
The installer of WPS Office Version 10.8.0.5745 insecurely load shcore.dll, allowing an attacker to execute arbitrary code with the privileg
HighCVSS 7.8No exploitEPSS 1%kingsoft · wps officeMar 17, 2022
- CVE-2022-2596931Monitor
The installer of WPS Office Version 10.8.0.6186 insecurely load VERSION.DLL (or some other DLLs), allowing an attacker to execute arbitrary
HighCVSS 7.8No exploitEPSS 1%kingsoft · wps officeMar 17, 2022
- CVE-2024-3520531Monitor
The WPS Office (aka cn.wps.moffice_eng) application before 17.0.0 for Android fails to properly sanitize file names before processing them t
HighCVSS 7.8Proof of conceptEPSS 1%May 14, 2024
- CVE-2022-2594931Monitor
The kernel mode driver kwatch3 of KINGSOFT Internet Security 9 Plus Version 2010.06.23.247 fails to properly handle crafted inputs, leading
HighCVSS 7.8Proof of conceptEPSS 1%kingsoft · internet security 9 plusMar 17, 2022
- CVE-2022-2594331Monitor
The installer of WPS Office for Windows versions prior to v11.2.0.10258 fails to configure properly the ACL for the directory where the serv
HighCVSS 7.8Proof of conceptEPSS 1%kingsoft · wps officeMar 9, 2022
- CVE-2022-2651131Monitor
WPS Presentation 11.8.0.5745 insecurely load d3dx9_41.dll when opening .pps files('current directory type' DLL loading).
HighCVSS 7.8No exploitEPSS 1%kingsoft · wps presentationMar 17, 2022
- CVE-2010-339628Monitor
Buffer overflow in kavfm.sys in Kingsoft Antivirus 2010.04.26.648 and earlier allows local users to execute arbitrary code via a long argume
HighCVSS 7.2Proof of conceptEPSS 1%kingsoft · kingsoft antivirusSep 15, 2010
- CVE-2010-203128Monitor
KAVSafe.sys 2010.4.14.609 and earlier, as used in Kingsoft Webshield 3.5.1.2 and earlier, allows local users to overwrite arbitrary kernel m
HighCVSS 7.2Proof of conceptEPSS 1%kingsoft · webshieldMay 24, 2010
- CVE-2013-599923Monitor
Kingsoft KDrive Personal before 1.21.0.1880 on Windows does not verify X.509 certificates from SSL servers, which allows man-in-the-middle a
MediumCVSS 5.8No exploitEPSS 1%kingsoft · kdriveNov 22, 2013
- CVE-2018-754622Monitor
wpsmain.dll in Kingsoft WPS Office 2016 and Jinshan PDF 10.1.0.6621 allows remote attackers to cause a denial of service via a crafted pdf f
MediumCVSS 5.5No exploitEPSS 1%kingsoft · jinshan pdfJul 18, 2018
- CVE-2018-915122Monitor
A NULL pointer dereference bug in the function ObReferenceObjectByHandle in the Kingsoft Internet Security 9+ kernel driver KWatch3.sys allo
MediumCVSS 5.5No exploitEPSS 0%kingsoft · internet security 9 plusMar 30, 2018
- CVE-2024-5709622Monitor
An issue in wps office before v.19302 allows a local attacker to obtain sensitive information via a crafted file.
MediumCVSS 5.5No exploitEPSS 0%kingsoft · wps officeMay 14, 2025
- CVE-2004-149421Monitor
Buffer overflow in the Screen Fetch option in XDICT 2002 through 2005 allows remote attackers to cause a denial of service ( CPU consumption
MediumCVSS 5.0No exploitEPSS 4%kingsoft · xdictDec 31, 2004
- CVE-2010-516421Monitor
Race condition in KingSoft Personal Firewall 9 Plus 2009.05.07.70 on Windows XP allows local users to bypass kernel-mode hook handlers, and
MediumCVSS 5.3No exploitEPSS 0%kingsoft · personal firewall 9Aug 25, 2012
- CVE-2011-05158Monitor
KisKrnl.sys 2011.1.13.89 and earlier in Kingsoft AntiVirus 2011 SP5.2 allows local users to cause a denial of service (crash) via a crafted
LowCVSS 2.1Proof of conceptEPSS 1%kingsoft · kingsoft antivirusJan 20, 2011