360 kayıtları
360 üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')2
- CWE-264 Permissions, Privileges, and Access Controls2
- CWE-427 Uncontrolled Search Path Element1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-787 Out-of-bounds Write1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2018-19031İstismar yok | A command injection vulnerability exists when the authorized user passes crafted parameter to background process in the router.360 · safe router p0 firmware · CWE-77 | Yüksek8,8 | — | %1,8 | 4 Kas 2019 |
35İzleyin | CVE-2021-33974İstismar yok | Qihoo 360 (https://www.360.cn/) Qihoo 360 Safeguard (https://www.360.cn/) Qihoo 360 Chrome (https://browser.360.cn/ee/) is affected by: Buff360 · total security · CWE-120 | Yüksek8,8 | — | %1,0 | 19 Nis 2023 |
31İzleyin | CVE-2021-33971İstismar yok | Qihoo 360 (https://www.360.cn/) Qihoo 360 Safeguard (https://www.360.cn/) Qihoo 360 Total Security (http://www.360totalsecurity.com/) is aff360 · total security · CWE-120 | Yüksek7,8 | — | %0,4 | 19 Nis 2023 |
31İzleyin | CVE-2020-24158İstismar yok | 360 Speed Browser 12.0.1247.0 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious code.360 · speed browser · CWE-427 | Yüksek7,8 | — | %0,3 | 3 Eyl 2020 |
30İzleyin | CVE-2023-27077İstismar yok | Stack Overflow vulnerability found in 360 D901 allows a remote attacker to cause a Distributed Denial of Service (DDOS) via a crafted HTTP p360 · d901 firmware · CWE-787 | Yüksek7,5 | — | %1,6 | 23 Mar 2023 |
30İzleyin | CVE-2019-3404İstismar yok | By adding some special fields to the uri ofrouter app function, the user could abuse background app cgi functions withoutauthentication.360 · p0 router firmware | Yüksek7,5 | — | %0,9 | 4 Mar 2020 |
23İzleyin | CVE-2011-4769İstismar yok | The 360 MobileSafe (com.qihoo360.mobilesafe) application 2.x before 2.3.0 for Android does not properly protect data, which allows remote at360 · mobilesafe · CWE-264 | Orta5,8 | — | %1,0 | 25 Oca 2012 |
23İzleyin | CVE-2011-4772İstismar yok | The 360 KouXin (com.qihoo360.kouxin) application 1.5.3 for Android does not properly protect data, which allows remote attackers to read or 360 · kouxin · CWE-264 | Orta5,8 | — | %1,0 | 25 Oca 2012 |
21İzleyin | CVE-2019-3405İstismar yok | In the 3.1.3.64296 and lower version of 360F5, the third party can trigger the device to send a deauth frame by constructing and sending a s360 · 360f5 firmware | Orta5,3 | — | %1,0 | 11 Oca 2021 |
- CVE-2018-1903136İzleyin
A command injection vulnerability exists when the authorized user passes crafted parameter to background process in the router.
YüksekCVSS 8,8İstismar yokEPSS %2360 · safe router p0 firmware4 Kas 2019
- CVE-2021-3397435İzleyin
Qihoo 360 (https://www.360.cn/) Qihoo 360 Safeguard (https://www.360.cn/) Qihoo 360 Chrome (https://browser.360.cn/ee/) is affected by: Buff
YüksekCVSS 8,8İstismar yokEPSS %1360 · total security19 Nis 2023
- CVE-2021-3397131İzleyin
Qihoo 360 (https://www.360.cn/) Qihoo 360 Safeguard (https://www.360.cn/) Qihoo 360 Total Security (http://www.360totalsecurity.com/) is aff
YüksekCVSS 7,8İstismar yokEPSS %0360 · total security19 Nis 2023
- CVE-2020-2415831İzleyin
360 Speed Browser 12.0.1247.0 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious code.
YüksekCVSS 7,8İstismar yokEPSS %0360 · speed browser3 Eyl 2020
- CVE-2023-2707730İzleyin
Stack Overflow vulnerability found in 360 D901 allows a remote attacker to cause a Distributed Denial of Service (DDOS) via a crafted HTTP p
YüksekCVSS 7,5İstismar yokEPSS %2360 · d901 firmware23 Mar 2023
- CVE-2019-340430İzleyin
By adding some special fields to the uri ofrouter app function, the user could abuse background app cgi functions withoutauthentication.
YüksekCVSS 7,5İstismar yokEPSS %1360 · p0 router firmware4 Mar 2020
- CVE-2011-476923İzleyin
The 360 MobileSafe (com.qihoo360.mobilesafe) application 2.x before 2.3.0 for Android does not properly protect data, which allows remote at
OrtaCVSS 5,8İstismar yokEPSS %1360 · mobilesafe25 Oca 2012
- CVE-2011-477223İzleyin
The 360 KouXin (com.qihoo360.kouxin) application 1.5.3 for Android does not properly protect data, which allows remote attackers to read or
OrtaCVSS 5,8İstismar yokEPSS %1360 · kouxin25 Oca 2012
- CVE-2019-340521İzleyin
In the 3.1.3.64296 and lower version of 360F5, the third party can trigger the device to send a deauth frame by constructing and sending a s
OrtaCVSS 5,3İstismar yokEPSS %1360 · 360f5 firmware11 Oca 2021