Show filters
29 Total Results
Displaying 11-20 of 29
Sort by:
Attacker Value
Unknown

CVE-2022-25949

Disclosure Date: March 17, 2022 (last updated February 23, 2025)
The kernel mode driver kwatch3 of KINGSOFT Internet Security 9 Plus Version 2010.06.23.247 fails to properly handle crafted inputs, leading to stack-based buffer overflow.
Attacker Value
Unknown

CVE-2022-25943

Disclosure Date: March 09, 2022 (last updated February 23, 2025)
The installer of WPS Office for Windows versions prior to v11.2.0.10258 fails to configure properly the ACL for the directory where the service program is installed.
Attacker Value
Unknown

CVE-2020-25291

Disclosure Date: September 13, 2020 (last updated February 22, 2025)
GdiDrawHoriLineIAlt in Kingsoft WPS Office before 11.2.0.9403 allows remote heap corruption via a crafted PLTE chunk in PNG data within a Word document. This is related to QBrush::setMatrix in gui/painting/qbrush.cpp in Qt 4.x.
Attacker Value
Unknown

CVE-2018-7546

Disclosure Date: July 18, 2018 (last updated November 27, 2024)
wpsmain.dll in Kingsoft WPS Office 2016 and Jinshan PDF 10.1.0.6621 allows remote attackers to cause a denial of service via a crafted pdf file.
0
Attacker Value
Unknown

CVE-2018-9151

Disclosure Date: March 30, 2018 (last updated November 26, 2024)
A NULL pointer dereference bug in the function ObReferenceObjectByHandle in the Kingsoft Internet Security 9+ kernel driver KWatch3.sys allows local non-privileged users to crash the system via IOCTL 0x80030030.
0
Attacker Value
Unknown

CVE-2018-6400

Disclosure Date: March 12, 2018 (last updated November 26, 2024)
Kingsoft WPS Office Free 10.2.0.5978 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through a use of \\.\pipe\WPSCloudSvr\WpsCloudSvr -- an "insecurely created named pipe." Ensures full access to Everyone users group.
0
Attacker Value
Unknown

CVE-2018-6217

Disclosure Date: January 25, 2018 (last updated November 26, 2024)
The WStr::_alloc_iostr_data() function in kso.dll in Kingsoft WPS Office 10.1.0.7106 and 10.2.0.5978 allows remote attackers to cause a denial of service (application crash) via a crafted (a) web page, (b) office document, or (c) .rtf file.
0
Attacker Value
Unknown

CVE-2012-4886

Disclosure Date: March 24, 2014 (last updated October 05, 2023)
Stack-based buffer overflow in wpsio.dll in Kingsoft WPS Office 2012 possibly 8.1.0.3238 allows remote attackers to execute arbitrary code via a long BSTR string.
0
Attacker Value
Unknown

CVE-2013-5999

Disclosure Date: November 22, 2013 (last updated October 05, 2023)
Kingsoft KDrive Personal before 1.21.0.1880 on Windows does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2013-3934

Disclosure Date: September 10, 2013 (last updated October 05, 2023)
Stack-based buffer overflow in Kingsoft Writer 2012 8.1.0.3030, as used in Kingsoft Office 2013 before 9.1.0.4256, allows remote attackers to execute arbitrary code via a long font name in a WPS file.
0