Kingsoft kayıtları
kingsoft üreticisine ait 26 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %3,8
- Silahlaştırılmış
- 1 · %3,8
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %3,8
- Yayından KEV’e ortanca
- 19 gün
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer8
- CWE-427 Uncontrolled Search Path Element3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-276 Incorrect Default Permissions1
- CWE-310 Cryptographic Issues1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
26 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
68Bu hafta | CVE-2024-7262Silahlaştırılmış | Arbitrary Code Execution in WPS Officekingsoft · wps office · CWE-22 | Kritik9,3 | KEV | %2,9 | 15 Ağu 2024 |
45Planlayın | CVE-2012-4886Kavram kanıtı | Stack-based buffer overflow in wpsio.dll in Kingsoft WPS Office 2012 possibly 8.1.0.3238 allows remote attackers to execute arbitrary code vkingsoft · office 2012 · CWE-119 | Kritik10,0 | — | %15,3 | 24 Mar 2014 |
44Planlayın | CVE-2008-1307Kavram kanıtı | Heap-based buffer overflow in the KUpdateObj2 Class ActiveX control in UpdateOcx2.dll in Beijing KingSoft Antivirus Online Update Module 200kingsoft · antivirus online update module · CWE-119 | Kritik10,0 | — | %15,0 | 12 Mar 2008 |
40Planlayın | CVE-2013-3934Kavram kanıtı | Stack-based buffer overflow in Kingsoft Writer 2012 8.1.0.3030, as used in Kingsoft Office 2013 before 9.1.0.4256, allows remote attackers tkingsoft · office 2012 · CWE-119 | Kritik9,3 | — | %9,8 | 10 Eyl 2013 |
38İzleyin | CVE-2013-0710İstismar yok | Buffer overflow in Kingsoft Writer 2007 and 2010 before 2724 allows remote attackers to execute arbitrary code via a crafted RTF document.kingsoft · writer 2007 · CWE-119 | Kritik9,3 | — | %4,3 | 5 Mar 2013 |
38İzleyin | CVE-2013-0723İstismar yok | Multiple heap-based buffer overflows in etxrw.dll in Kingsoft Spreadsheets 2012 8.1.0.3030 allow remote attackers to cause a denial of servikingsoft · spreadsheets 2012 · CWE-119 | Kritik9,3 | — | %4,2 | 29 Tem 2013 |
37İzleyin | CVE-2024-7263İstismar yok | Arbitrary Code Execution in WPS Officekingsoft · wps office · CWE-22 | Kritik9,3 | — | %0,4 | 15 Ağu 2024 |
32İzleyin | CVE-2023-31275İstismar yok | An uninitialized pointer use vulnerability exists in the functionality of WPS Office 11.2.0.11537 that handles Data elements in an Excel filkingsoft · wps office · CWE-457 | Yüksek7,8 | — | %1,7 | 27 Kas 2023 |
32İzleyin | CVE-2023-32548İstismar yok | OS command injection vulnerability exists in WPS Office version 10.8.0.6186.kingsoft · wps office · CWE-78 | Yüksek8,1 | — | %1,1 | 13 Haz 2023 |
31İzleyin | CVE-2020-25291İstismar yok | GdiDrawHoriLineIAlt in Kingsoft WPS Office before 11.2.0.9403 allows remote heap corruption via a crafted PLTE chunk in PNG data within a Wokingsoft · wps office · CWE-787 | Yüksek7,8 | — | %1,6 | 13 Eyl 2020 |
31İzleyin | CVE-2022-26081İstismar yok | The installer of WPS Office Version 10.8.0.5745 insecurely load shcore.dll, allowing an attacker to execute arbitrary code with the privilegkingsoft · wps office · CWE-427 | Yüksek7,8 | — | %0,8 | 17 Mar 2022 |
31İzleyin | CVE-2022-25969İstismar yok | The installer of WPS Office Version 10.8.0.6186 insecurely load VERSION.DLL (or some other DLLs), allowing an attacker to execute arbitrary kingsoft · wps office · CWE-427 | Yüksek7,8 | — | %0,8 | 17 Mar 2022 |
31İzleyin | CVE-2024-35205Kavram kanıtı | The WPS Office (aka cn.wps.moffice_eng) application before 17.0.0 for Android fails to properly sanitize file names before processing them tCWE-22 | Yüksek7,8 | — | %0,8 | 14 May 2024 |
31İzleyin | CVE-2022-25949Kavram kanıtı | The kernel mode driver kwatch3 of KINGSOFT Internet Security 9 Plus Version 2010.06.23.247 fails to properly handle crafted inputs, leading kingsoft · internet security 9 plus · CWE-121 | Yüksek7,8 | — | %0,8 | 17 Mar 2022 |
31İzleyin | CVE-2022-25943Kavram kanıtı | The installer of WPS Office for Windows versions prior to v11.2.0.10258 fails to configure properly the ACL for the directory where the servkingsoft · wps office · CWE-276 | Yüksek7,8 | — | %0,7 | 9 Mar 2022 |
31İzleyin | CVE-2022-26511İstismar yok | WPS Presentation 11.8.0.5745 insecurely load d3dx9_41.dll when opening .pps files('current directory type' DLL loading).kingsoft · wps presentation · CWE-427 | Yüksek7,8 | — | %0,6 | 17 Mar 2022 |
28İzleyin | CVE-2010-3396Kavram kanıtı | Buffer overflow in kavfm.sys in Kingsoft Antivirus 2010.04.26.648 and earlier allows local users to execute arbitrary code via a long argumekingsoft · kingsoft antivirus · CWE-119 | Yüksek7,2 | — | %1,1 | 15 Eyl 2010 |
28İzleyin | CVE-2010-2031Kavram kanıtı | KAVSafe.sys 2010.4.14.609 and earlier, as used in Kingsoft Webshield 3.5.1.2 and earlier, allows local users to overwrite arbitrary kernel mkingsoft · webshield · CWE-119 | Yüksek7,2 | — | %0,8 | 24 May 2010 |
23İzleyin | CVE-2013-5999İstismar yok | Kingsoft KDrive Personal before 1.21.0.1880 on Windows does not verify X.509 certificates from SSL servers, which allows man-in-the-middle akingsoft · kdrive · CWE-310 | Orta5,8 | — | %0,6 | 22 Kas 2013 |
22İzleyin | CVE-2018-7546İstismar yok | wpsmain.dll in Kingsoft WPS Office 2016 and Jinshan PDF 10.1.0.6621 allows remote attackers to cause a denial of service via a crafted pdf fkingsoft · jinshan pdf · CWE-119 | Orta5,5 | — | %1,4 | 18 Tem 2018 |
22İzleyin | CVE-2018-9151İstismar yok | A NULL pointer dereference bug in the function ObReferenceObjectByHandle in the Kingsoft Internet Security 9+ kernel driver KWatch3.sys allokingsoft · internet security 9 plus · CWE-476 | Orta5,5 | — | %0,3 | 30 Mar 2018 |
22İzleyin | CVE-2024-57096İstismar yok | An issue in wps office before v.19302 allows a local attacker to obtain sensitive information via a crafted file.kingsoft · wps office · CWE-200 | Orta5,5 | — | %0,2 | 14 May 2025 |
21İzleyin | CVE-2004-1494İstismar yok | Buffer overflow in the Screen Fetch option in XDICT 2002 through 2005 allows remote attackers to cause a denial of service ( CPU consumptionkingsoft · xdict | Orta5,0 | — | %3,7 | 31 Ara 2004 |
21İzleyin | CVE-2010-5164İstismar yok | Race condition in KingSoft Personal Firewall 9 Plus 2009.05.07.70 on Windows XP allows local users to bypass kernel-mode hook handlers, and kingsoft · personal firewall 9 · CWE-362 | Orta5,3 | — | %0,4 | 25 Ağu 2012 |
8İzleyin | CVE-2011-0515Kavram kanıtı | KisKrnl.sys 2011.1.13.89 and earlier in Kingsoft AntiVirus 2011 SP5.2 allows local users to cause a denial of service (crash) via a crafted kingsoft · kingsoft antivirus | Düşük2,1 | — | %0,9 | 20 Oca 2011 |
- CVE-2024-726268Bu hafta
Arbitrary Code Execution in WPS Office
KritikCVSS 9,3KEVSilahlaştırılmışEPSS %3kingsoft · wps office15 Ağu 2024
- CVE-2012-488645Planlayın
Stack-based buffer overflow in wpsio.dll in Kingsoft WPS Office 2012 possibly 8.1.0.3238 allows remote attackers to execute arbitrary code v
KritikCVSS 10,0Kavram kanıtıEPSS %15kingsoft · office 201224 Mar 2014
- CVE-2008-130744Planlayın
Heap-based buffer overflow in the KUpdateObj2 Class ActiveX control in UpdateOcx2.dll in Beijing KingSoft Antivirus Online Update Module 200
KritikCVSS 10,0Kavram kanıtıEPSS %15kingsoft · antivirus online update module12 Mar 2008
- CVE-2013-393440Planlayın
Stack-based buffer overflow in Kingsoft Writer 2012 8.1.0.3030, as used in Kingsoft Office 2013 before 9.1.0.4256, allows remote attackers t
KritikCVSS 9,3Kavram kanıtıEPSS %10kingsoft · office 201210 Eyl 2013
- CVE-2013-071038İzleyin
Buffer overflow in Kingsoft Writer 2007 and 2010 before 2724 allows remote attackers to execute arbitrary code via a crafted RTF document.
KritikCVSS 9,3İstismar yokEPSS %4kingsoft · writer 20075 Mar 2013
- CVE-2013-072338İzleyin
Multiple heap-based buffer overflows in etxrw.dll in Kingsoft Spreadsheets 2012 8.1.0.3030 allow remote attackers to cause a denial of servi
KritikCVSS 9,3İstismar yokEPSS %4kingsoft · spreadsheets 201229 Tem 2013
- CVE-2024-726337İzleyin
Arbitrary Code Execution in WPS Office
KritikCVSS 9,3İstismar yokEPSS %0kingsoft · wps office15 Ağu 2024
- CVE-2023-3127532İzleyin
An uninitialized pointer use vulnerability exists in the functionality of WPS Office 11.2.0.11537 that handles Data elements in an Excel fil
YüksekCVSS 7,8İstismar yokEPSS %2kingsoft · wps office27 Kas 2023
- CVE-2023-3254832İzleyin
OS command injection vulnerability exists in WPS Office version 10.8.0.6186.
YüksekCVSS 8,1İstismar yokEPSS %1kingsoft · wps office13 Haz 2023
- CVE-2020-2529131İzleyin
GdiDrawHoriLineIAlt in Kingsoft WPS Office before 11.2.0.9403 allows remote heap corruption via a crafted PLTE chunk in PNG data within a Wo
YüksekCVSS 7,8İstismar yokEPSS %2kingsoft · wps office13 Eyl 2020
- CVE-2022-2608131İzleyin
The installer of WPS Office Version 10.8.0.5745 insecurely load shcore.dll, allowing an attacker to execute arbitrary code with the privileg
YüksekCVSS 7,8İstismar yokEPSS %1kingsoft · wps office17 Mar 2022
- CVE-2022-2596931İzleyin
The installer of WPS Office Version 10.8.0.6186 insecurely load VERSION.DLL (or some other DLLs), allowing an attacker to execute arbitrary
YüksekCVSS 7,8İstismar yokEPSS %1kingsoft · wps office17 Mar 2022
- CVE-2024-3520531İzleyin
The WPS Office (aka cn.wps.moffice_eng) application before 17.0.0 for Android fails to properly sanitize file names before processing them t
YüksekCVSS 7,8Kavram kanıtıEPSS %114 May 2024
- CVE-2022-2594931İzleyin
The kernel mode driver kwatch3 of KINGSOFT Internet Security 9 Plus Version 2010.06.23.247 fails to properly handle crafted inputs, leading
YüksekCVSS 7,8Kavram kanıtıEPSS %1kingsoft · internet security 9 plus17 Mar 2022
- CVE-2022-2594331İzleyin
The installer of WPS Office for Windows versions prior to v11.2.0.10258 fails to configure properly the ACL for the directory where the serv
YüksekCVSS 7,8Kavram kanıtıEPSS %1kingsoft · wps office9 Mar 2022
- CVE-2022-2651131İzleyin
WPS Presentation 11.8.0.5745 insecurely load d3dx9_41.dll when opening .pps files('current directory type' DLL loading).
YüksekCVSS 7,8İstismar yokEPSS %1kingsoft · wps presentation17 Mar 2022
- CVE-2010-339628İzleyin
Buffer overflow in kavfm.sys in Kingsoft Antivirus 2010.04.26.648 and earlier allows local users to execute arbitrary code via a long argume
YüksekCVSS 7,2Kavram kanıtıEPSS %1kingsoft · kingsoft antivirus15 Eyl 2010
- CVE-2010-203128İzleyin
KAVSafe.sys 2010.4.14.609 and earlier, as used in Kingsoft Webshield 3.5.1.2 and earlier, allows local users to overwrite arbitrary kernel m
YüksekCVSS 7,2Kavram kanıtıEPSS %1kingsoft · webshield24 May 2010
- CVE-2013-599923İzleyin
Kingsoft KDrive Personal before 1.21.0.1880 on Windows does not verify X.509 certificates from SSL servers, which allows man-in-the-middle a
OrtaCVSS 5,8İstismar yokEPSS %1kingsoft · kdrive22 Kas 2013
- CVE-2018-754622İzleyin
wpsmain.dll in Kingsoft WPS Office 2016 and Jinshan PDF 10.1.0.6621 allows remote attackers to cause a denial of service via a crafted pdf f
OrtaCVSS 5,5İstismar yokEPSS %1kingsoft · jinshan pdf18 Tem 2018
- CVE-2018-915122İzleyin
A NULL pointer dereference bug in the function ObReferenceObjectByHandle in the Kingsoft Internet Security 9+ kernel driver KWatch3.sys allo
OrtaCVSS 5,5İstismar yokEPSS %0kingsoft · internet security 9 plus30 Mar 2018
- CVE-2024-5709622İzleyin
An issue in wps office before v.19302 allows a local attacker to obtain sensitive information via a crafted file.
OrtaCVSS 5,5İstismar yokEPSS %0kingsoft · wps office14 May 2025
- CVE-2004-149421İzleyin
Buffer overflow in the Screen Fetch option in XDICT 2002 through 2005 allows remote attackers to cause a denial of service ( CPU consumption
OrtaCVSS 5,0İstismar yokEPSS %4kingsoft · xdict31 Ara 2004
- CVE-2010-516421İzleyin
Race condition in KingSoft Personal Firewall 9 Plus 2009.05.07.70 on Windows XP allows local users to bypass kernel-mode hook handlers, and
OrtaCVSS 5,3İstismar yokEPSS %0kingsoft · personal firewall 925 Ağu 2012
- CVE-2011-05158İzleyin
KisKrnl.sys 2011.1.13.89 and earlier in Kingsoft AntiVirus 2011 SP5.2 allows local users to cause a denial of service (crash) via a crafted
DüşükCVSS 2,1Kavram kanıtıEPSS %1kingsoft · kingsoft antivirus20 Oca 2011