Записи Kingsoft
26 опубликованных записей вендора kingsoft.
Профиль для исследователя
- Попали в KEV
- 1 · 3,8 %
- С эксплойтом
- 1 · 3,8 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 3,8 %
- Медиана: публикация → KEV
- 19 дн.
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer8
- CWE-427 Uncontrolled Search Path Element3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-276 Incorrect Default Permissions1
- CWE-310 Cryptographic Issues1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
26 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
68На этой неделе | CVE-2024-7262Готовый эксплойт | Arbitrary Code Execution in WPS Officekingsoft · wps office · CWE-22 | Критическая9,3 | KEV | 2,9 % | 15 авг. 2024 г. |
45В плане | CVE-2012-4886Proof of concept | Stack-based buffer overflow in wpsio.dll in Kingsoft WPS Office 2012 possibly 8.1.0.3238 allows remote attackers to execute arbitrary code vkingsoft · office 2012 · CWE-119 | Критическая10,0 | — | 15,3 % | 24 мар. 2014 г. |
44В плане | CVE-2008-1307Proof of concept | Heap-based buffer overflow in the KUpdateObj2 Class ActiveX control in UpdateOcx2.dll in Beijing KingSoft Antivirus Online Update Module 200kingsoft · antivirus online update module · CWE-119 | Критическая10,0 | — | 15,0 % | 12 мар. 2008 г. |
40В плане | CVE-2013-3934Proof of concept | Stack-based buffer overflow in Kingsoft Writer 2012 8.1.0.3030, as used in Kingsoft Office 2013 before 9.1.0.4256, allows remote attackers tkingsoft · office 2012 · CWE-119 | Критическая9,3 | — | 9,8 % | 10 сент. 2013 г. |
38Наблюдать | CVE-2013-0710Эксплойта нет | Buffer overflow in Kingsoft Writer 2007 and 2010 before 2724 allows remote attackers to execute arbitrary code via a crafted RTF document.kingsoft · writer 2007 · CWE-119 | Критическая9,3 | — | 4,3 % | 5 мар. 2013 г. |
38Наблюдать | CVE-2013-0723Эксплойта нет | Multiple heap-based buffer overflows in etxrw.dll in Kingsoft Spreadsheets 2012 8.1.0.3030 allow remote attackers to cause a denial of servikingsoft · spreadsheets 2012 · CWE-119 | Критическая9,3 | — | 4,2 % | 29 июл. 2013 г. |
37Наблюдать | CVE-2024-7263Эксплойта нет | Arbitrary Code Execution in WPS Officekingsoft · wps office · CWE-22 | Критическая9,3 | — | 0,4 % | 15 авг. 2024 г. |
32Наблюдать | CVE-2023-31275Эксплойта нет | An uninitialized pointer use vulnerability exists in the functionality of WPS Office 11.2.0.11537 that handles Data elements in an Excel filkingsoft · wps office · CWE-457 | Высокая7,8 | — | 1,7 % | 27 нояб. 2023 г. |
32Наблюдать | CVE-2023-32548Эксплойта нет | OS command injection vulnerability exists in WPS Office version 10.8.0.6186.kingsoft · wps office · CWE-78 | Высокая8,1 | — | 1,1 % | 13 июн. 2023 г. |
31Наблюдать | CVE-2020-25291Эксплойта нет | GdiDrawHoriLineIAlt in Kingsoft WPS Office before 11.2.0.9403 allows remote heap corruption via a crafted PLTE chunk in PNG data within a Wokingsoft · wps office · CWE-787 | Высокая7,8 | — | 1,6 % | 13 сент. 2020 г. |
31Наблюдать | CVE-2022-26081Эксплойта нет | The installer of WPS Office Version 10.8.0.5745 insecurely load shcore.dll, allowing an attacker to execute arbitrary code with the privilegkingsoft · wps office · CWE-427 | Высокая7,8 | — | 0,8 % | 17 мар. 2022 г. |
31Наблюдать | CVE-2022-25969Эксплойта нет | The installer of WPS Office Version 10.8.0.6186 insecurely load VERSION.DLL (or some other DLLs), allowing an attacker to execute arbitrary kingsoft · wps office · CWE-427 | Высокая7,8 | — | 0,8 % | 17 мар. 2022 г. |
31Наблюдать | CVE-2024-35205Proof of concept | The WPS Office (aka cn.wps.moffice_eng) application before 17.0.0 for Android fails to properly sanitize file names before processing them tCWE-22 | Высокая7,8 | — | 0,8 % | 14 мая 2024 г. |
31Наблюдать | CVE-2022-25949Proof of concept | The kernel mode driver kwatch3 of KINGSOFT Internet Security 9 Plus Version 2010.06.23.247 fails to properly handle crafted inputs, leading kingsoft · internet security 9 plus · CWE-121 | Высокая7,8 | — | 0,8 % | 17 мар. 2022 г. |
31Наблюдать | CVE-2022-25943Proof of concept | The installer of WPS Office for Windows versions prior to v11.2.0.10258 fails to configure properly the ACL for the directory where the servkingsoft · wps office · CWE-276 | Высокая7,8 | — | 0,7 % | 9 мар. 2022 г. |
31Наблюдать | CVE-2022-26511Эксплойта нет | WPS Presentation 11.8.0.5745 insecurely load d3dx9_41.dll when opening .pps files('current directory type' DLL loading).kingsoft · wps presentation · CWE-427 | Высокая7,8 | — | 0,6 % | 17 мар. 2022 г. |
28Наблюдать | CVE-2010-3396Proof of concept | Buffer overflow in kavfm.sys in Kingsoft Antivirus 2010.04.26.648 and earlier allows local users to execute arbitrary code via a long argumekingsoft · kingsoft antivirus · CWE-119 | Высокая7,2 | — | 1,1 % | 15 сент. 2010 г. |
28Наблюдать | CVE-2010-2031Proof of concept | KAVSafe.sys 2010.4.14.609 and earlier, as used in Kingsoft Webshield 3.5.1.2 and earlier, allows local users to overwrite arbitrary kernel mkingsoft · webshield · CWE-119 | Высокая7,2 | — | 0,8 % | 24 мая 2010 г. |
23Наблюдать | CVE-2013-5999Эксплойта нет | Kingsoft KDrive Personal before 1.21.0.1880 on Windows does not verify X.509 certificates from SSL servers, which allows man-in-the-middle akingsoft · kdrive · CWE-310 | Средняя5,8 | — | 0,6 % | 22 нояб. 2013 г. |
22Наблюдать | CVE-2018-7546Эксплойта нет | wpsmain.dll in Kingsoft WPS Office 2016 and Jinshan PDF 10.1.0.6621 allows remote attackers to cause a denial of service via a crafted pdf fkingsoft · jinshan pdf · CWE-119 | Средняя5,5 | — | 1,4 % | 18 июл. 2018 г. |
22Наблюдать | CVE-2018-9151Эксплойта нет | A NULL pointer dereference bug in the function ObReferenceObjectByHandle in the Kingsoft Internet Security 9+ kernel driver KWatch3.sys allokingsoft · internet security 9 plus · CWE-476 | Средняя5,5 | — | 0,3 % | 30 мар. 2018 г. |
22Наблюдать | CVE-2024-57096Эксплойта нет | An issue in wps office before v.19302 allows a local attacker to obtain sensitive information via a crafted file.kingsoft · wps office · CWE-200 | Средняя5,5 | — | 0,2 % | 14 мая 2025 г. |
21Наблюдать | CVE-2004-1494Эксплойта нет | Buffer overflow in the Screen Fetch option in XDICT 2002 through 2005 allows remote attackers to cause a denial of service ( CPU consumptionkingsoft · xdict | Средняя5,0 | — | 3,7 % | 31 дек. 2004 г. |
21Наблюдать | CVE-2010-5164Эксплойта нет | Race condition in KingSoft Personal Firewall 9 Plus 2009.05.07.70 on Windows XP allows local users to bypass kernel-mode hook handlers, and kingsoft · personal firewall 9 · CWE-362 | Средняя5,3 | — | 0,4 % | 25 авг. 2012 г. |
8Наблюдать | CVE-2011-0515Proof of concept | KisKrnl.sys 2011.1.13.89 and earlier in Kingsoft AntiVirus 2011 SP5.2 allows local users to cause a denial of service (crash) via a crafted kingsoft · kingsoft antivirus | Низкая2,1 | — | 0,9 % | 20 янв. 2011 г. |
- CVE-2024-726268На этой неделе
Arbitrary Code Execution in WPS Office
КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 3 %kingsoft · wps office15 авг. 2024 г.
- CVE-2012-488645В плане
Stack-based buffer overflow in wpsio.dll in Kingsoft WPS Office 2012 possibly 8.1.0.3238 allows remote attackers to execute arbitrary code v
КритическаяCVSS 10,0Proof of conceptEPSS 15 %kingsoft · office 201224 мар. 2014 г.
- CVE-2008-130744В плане
Heap-based buffer overflow in the KUpdateObj2 Class ActiveX control in UpdateOcx2.dll in Beijing KingSoft Antivirus Online Update Module 200
КритическаяCVSS 10,0Proof of conceptEPSS 15 %kingsoft · antivirus online update module12 мар. 2008 г.
- CVE-2013-393440В плане
Stack-based buffer overflow in Kingsoft Writer 2012 8.1.0.3030, as used in Kingsoft Office 2013 before 9.1.0.4256, allows remote attackers t
КритическаяCVSS 9,3Proof of conceptEPSS 10 %kingsoft · office 201210 сент. 2013 г.
- CVE-2013-071038Наблюдать
Buffer overflow in Kingsoft Writer 2007 and 2010 before 2724 allows remote attackers to execute arbitrary code via a crafted RTF document.
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %kingsoft · writer 20075 мар. 2013 г.
- CVE-2013-072338Наблюдать
Multiple heap-based buffer overflows in etxrw.dll in Kingsoft Spreadsheets 2012 8.1.0.3030 allow remote attackers to cause a denial of servi
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %kingsoft · spreadsheets 201229 июл. 2013 г.
- CVE-2024-726337Наблюдать
Arbitrary Code Execution in WPS Office
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %kingsoft · wps office15 авг. 2024 г.
- CVE-2023-3127532Наблюдать
An uninitialized pointer use vulnerability exists in the functionality of WPS Office 11.2.0.11537 that handles Data elements in an Excel fil
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %kingsoft · wps office27 нояб. 2023 г.
- CVE-2023-3254832Наблюдать
OS command injection vulnerability exists in WPS Office version 10.8.0.6186.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %kingsoft · wps office13 июн. 2023 г.
- CVE-2020-2529131Наблюдать
GdiDrawHoriLineIAlt in Kingsoft WPS Office before 11.2.0.9403 allows remote heap corruption via a crafted PLTE chunk in PNG data within a Wo
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %kingsoft · wps office13 сент. 2020 г.
- CVE-2022-2608131Наблюдать
The installer of WPS Office Version 10.8.0.5745 insecurely load shcore.dll, allowing an attacker to execute arbitrary code with the privileg
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %kingsoft · wps office17 мар. 2022 г.
- CVE-2022-2596931Наблюдать
The installer of WPS Office Version 10.8.0.6186 insecurely load VERSION.DLL (or some other DLLs), allowing an attacker to execute arbitrary
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %kingsoft · wps office17 мар. 2022 г.
- CVE-2024-3520531Наблюдать
The WPS Office (aka cn.wps.moffice_eng) application before 17.0.0 for Android fails to properly sanitize file names before processing them t
ВысокаяCVSS 7,8Proof of conceptEPSS 1 %14 мая 2024 г.
- CVE-2022-2594931Наблюдать
The kernel mode driver kwatch3 of KINGSOFT Internet Security 9 Plus Version 2010.06.23.247 fails to properly handle crafted inputs, leading
ВысокаяCVSS 7,8Proof of conceptEPSS 1 %kingsoft · internet security 9 plus17 мар. 2022 г.
- CVE-2022-2594331Наблюдать
The installer of WPS Office for Windows versions prior to v11.2.0.10258 fails to configure properly the ACL for the directory where the serv
ВысокаяCVSS 7,8Proof of conceptEPSS 1 %kingsoft · wps office9 мар. 2022 г.
- CVE-2022-2651131Наблюдать
WPS Presentation 11.8.0.5745 insecurely load d3dx9_41.dll when opening .pps files('current directory type' DLL loading).
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %kingsoft · wps presentation17 мар. 2022 г.
- CVE-2010-339628Наблюдать
Buffer overflow in kavfm.sys in Kingsoft Antivirus 2010.04.26.648 and earlier allows local users to execute arbitrary code via a long argume
ВысокаяCVSS 7,2Proof of conceptEPSS 1 %kingsoft · kingsoft antivirus15 сент. 2010 г.
- CVE-2010-203128Наблюдать
KAVSafe.sys 2010.4.14.609 and earlier, as used in Kingsoft Webshield 3.5.1.2 and earlier, allows local users to overwrite arbitrary kernel m
ВысокаяCVSS 7,2Proof of conceptEPSS 1 %kingsoft · webshield24 мая 2010 г.
- CVE-2013-599923Наблюдать
Kingsoft KDrive Personal before 1.21.0.1880 on Windows does not verify X.509 certificates from SSL servers, which allows man-in-the-middle a
СредняяCVSS 5,8Эксплойта нетEPSS 1 %kingsoft · kdrive22 нояб. 2013 г.
- CVE-2018-754622Наблюдать
wpsmain.dll in Kingsoft WPS Office 2016 and Jinshan PDF 10.1.0.6621 allows remote attackers to cause a denial of service via a crafted pdf f
СредняяCVSS 5,5Эксплойта нетEPSS 1 %kingsoft · jinshan pdf18 июл. 2018 г.
- CVE-2018-915122Наблюдать
A NULL pointer dereference bug in the function ObReferenceObjectByHandle in the Kingsoft Internet Security 9+ kernel driver KWatch3.sys allo
СредняяCVSS 5,5Эксплойта нетEPSS 0 %kingsoft · internet security 9 plus30 мар. 2018 г.
- CVE-2024-5709622Наблюдать
An issue in wps office before v.19302 allows a local attacker to obtain sensitive information via a crafted file.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %kingsoft · wps office14 мая 2025 г.
- CVE-2004-149421Наблюдать
Buffer overflow in the Screen Fetch option in XDICT 2002 through 2005 allows remote attackers to cause a denial of service ( CPU consumption
СредняяCVSS 5,0Эксплойта нетEPSS 4 %kingsoft · xdict31 дек. 2004 г.
- CVE-2010-516421Наблюдать
Race condition in KingSoft Personal Firewall 9 Plus 2009.05.07.70 on Windows XP allows local users to bypass kernel-mode hook handlers, and
СредняяCVSS 5,3Эксплойта нетEPSS 0 %kingsoft · personal firewall 925 авг. 2012 г.
- CVE-2011-05158Наблюдать
KisKrnl.sys 2011.1.13.89 and earlier in Kingsoft AntiVirus 2011 SP5.2 allows local users to cause a denial of service (crash) via a crafted
НизкаяCVSS 2,1Proof of conceptEPSS 1 %kingsoft · kingsoft antivirus20 янв. 2011 г.