Записи 360
9 опубликованных записей вендора 360.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')2
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-427 Uncontrolled Search Path Element1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-787 Out-of-bounds Write1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2018-19031Эксплойта нет | A command injection vulnerability exists when the authorized user passes crafted parameter to background process in the router.360 · safe router p0 firmware · CWE-77 | Высокая8,8 | — | 1,8 % | 4 нояб. 2019 г. |
35Наблюдать | CVE-2021-33974Эксплойта нет | Qihoo 360 (https://www.360.cn/) Qihoo 360 Safeguard (https://www.360.cn/) Qihoo 360 Chrome (https://browser.360.cn/ee/) is affected by: Buff360 · total security · CWE-120 | Высокая8,8 | — | 1,0 % | 19 апр. 2023 г. |
31Наблюдать | CVE-2021-33971Эксплойта нет | Qihoo 360 (https://www.360.cn/) Qihoo 360 Safeguard (https://www.360.cn/) Qihoo 360 Total Security (http://www.360totalsecurity.com/) is aff360 · total security · CWE-120 | Высокая7,8 | — | 0,4 % | 19 апр. 2023 г. |
31Наблюдать | CVE-2020-24158Эксплойта нет | 360 Speed Browser 12.0.1247.0 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious code.360 · speed browser · CWE-427 | Высокая7,8 | — | 0,3 % | 3 сент. 2020 г. |
30Наблюдать | CVE-2023-27077Эксплойта нет | Stack Overflow vulnerability found in 360 D901 allows a remote attacker to cause a Distributed Denial of Service (DDOS) via a crafted HTTP p360 · d901 firmware · CWE-787 | Высокая7,5 | — | 1,6 % | 23 мар. 2023 г. |
30Наблюдать | CVE-2019-3404Эксплойта нет | By adding some special fields to the uri ofrouter app function, the user could abuse background app cgi functions withoutauthentication.360 · p0 router firmware | Высокая7,5 | — | 0,9 % | 4 мар. 2020 г. |
23Наблюдать | CVE-2011-4769Эксплойта нет | The 360 MobileSafe (com.qihoo360.mobilesafe) application 2.x before 2.3.0 for Android does not properly protect data, which allows remote at360 · mobilesafe · CWE-264 | Средняя5,8 | — | 1,0 % | 25 янв. 2012 г. |
23Наблюдать | CVE-2011-4772Эксплойта нет | The 360 KouXin (com.qihoo360.kouxin) application 1.5.3 for Android does not properly protect data, which allows remote attackers to read or 360 · kouxin · CWE-264 | Средняя5,8 | — | 1,0 % | 25 янв. 2012 г. |
21Наблюдать | CVE-2019-3405Эксплойта нет | In the 3.1.3.64296 and lower version of 360F5, the third party can trigger the device to send a deauth frame by constructing and sending a s360 · 360f5 firmware | Средняя5,3 | — | 1,0 % | 11 янв. 2021 г. |
- CVE-2018-1903136Наблюдать
A command injection vulnerability exists when the authorized user passes crafted parameter to background process in the router.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %360 · safe router p0 firmware4 нояб. 2019 г.
- CVE-2021-3397435Наблюдать
Qihoo 360 (https://www.360.cn/) Qihoo 360 Safeguard (https://www.360.cn/) Qihoo 360 Chrome (https://browser.360.cn/ee/) is affected by: Buff
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %360 · total security19 апр. 2023 г.
- CVE-2021-3397131Наблюдать
Qihoo 360 (https://www.360.cn/) Qihoo 360 Safeguard (https://www.360.cn/) Qihoo 360 Total Security (http://www.360totalsecurity.com/) is aff
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %360 · total security19 апр. 2023 г.
- CVE-2020-2415831Наблюдать
360 Speed Browser 12.0.1247.0 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious code.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %360 · speed browser3 сент. 2020 г.
- CVE-2023-2707730Наблюдать
Stack Overflow vulnerability found in 360 D901 allows a remote attacker to cause a Distributed Denial of Service (DDOS) via a crafted HTTP p
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %360 · d901 firmware23 мар. 2023 г.
- CVE-2019-340430Наблюдать
By adding some special fields to the uri ofrouter app function, the user could abuse background app cgi functions withoutauthentication.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %360 · p0 router firmware4 мар. 2020 г.
- CVE-2011-476923Наблюдать
The 360 MobileSafe (com.qihoo360.mobilesafe) application 2.x before 2.3.0 for Android does not properly protect data, which allows remote at
СредняяCVSS 5,8Эксплойта нетEPSS 1 %360 · mobilesafe25 янв. 2012 г.
- CVE-2011-477223Наблюдать
The 360 KouXin (com.qihoo360.kouxin) application 1.5.3 for Android does not properly protect data, which allows remote attackers to read or
СредняяCVSS 5,8Эксплойта нетEPSS 1 %360 · kouxin25 янв. 2012 г.
- CVE-2019-340521Наблюдать
In the 3.1.3.64296 and lower version of 360F5, the third party can trigger the device to send a deauth frame by constructing and sending a s
СредняяCVSS 5,3Эксплойта нетEPSS 1 %360 · 360f5 firmware11 янв. 2021 г.