Show filters
42 Total Results
Displaying 21-30 of 42
Sort by:
Attacker Value
Unknown

CVE-2021-24970

Disclosure Date: December 13, 2021 (last updated February 23, 2025)
The All-in-One Video Gallery WordPress plugin before 2.5.0 does not sanitise and validate the tab parameter before using it in a require statement in the admin dashboard, leading to a Local File Inclusion issue
Attacker Value
Unknown

CVE-2019-3405

Disclosure Date: January 11, 2021 (last updated November 28, 2024)
In the 3.1.3.64296 and lower version of 360F5, the third party can trigger the device to send a deauth frame by constructing and sending a specific illegal 802.11 Null Data Frame, which will cause other wireless terminals connected to disconnect from the wireless, so as to attack the router wireless by DoS. At present, the vulnerability has been effectively handled, and users can fix the vulnerability after updating the firmware version.
Attacker Value
Unknown

CVE-2020-24158

Disclosure Date: September 03, 2020 (last updated February 22, 2025)
360 Speed Browser 12.0.1247.0 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious code. It is a dual-core browser owned by Beijing Qihoo Technology.
Attacker Value
Unknown

CVE-2020-15724

Disclosure Date: July 21, 2020 (last updated February 21, 2025)
In the version 12.1.0.1005 and below of 360 Total Security, when the Gamefolde calls GameChrome.exe, there exists a local privilege escalation vulnerability. An attacker who could exploit DLL hijacking to bypass the hips could execute arbitrary code on the Local system.
Attacker Value
Unknown

CVE-2020-15723

Disclosure Date: July 21, 2020 (last updated February 21, 2025)
In the version 12.1.0.1004 and below of 360 Total Security, when the main process of 360 Total Security calls GameChrome.exe, there exists a local privilege escalation vulnerability. An attacker who could exploit DLL hijacking to bypass the hips could execute arbitrary code on the Local system.
Attacker Value
Unknown

CVE-2020-15722

Disclosure Date: July 21, 2020 (last updated February 21, 2025)
In version 12.1.0.1004 and below of 360 Total Security,when TPI calls the browser process, there exists a local privilege escalation vulnerability. An attacker who could exploit DLL hijacking could execute arbitrary code on the Local system.
Attacker Value
Unknown

CVE-2019-3404

Disclosure Date: March 04, 2020 (last updated November 27, 2024)
By adding some special fields to the uri ofrouter app function, the user could abuse background app cgi functions withoutauthentication. This affects 360 router P0 and F5C.
Attacker Value
Unknown

CVE-2018-19031

Disclosure Date: November 04, 2019 (last updated November 27, 2024)
A command injection vulnerability exists when the authorized user passes crafted parameter to background process in the router. This affects 360 router series products (360 Safe Router P0,P1,P2,P3,P4), the affected version is V2.0.61.58897.
Attacker Value
Unknown

CVE-2018-18603

Disclosure Date: October 23, 2018 (last updated November 08, 2023)
360 Total Security 3.5.0.1033 allows a Sandbox Escape via an "import os" statement, followed by os.system("CMD") or os.system("PowerShell"), within a .py file. NOTE: the vendor's position is that this cannot be categorized as a vulnerability, although it is a security-related issue
0
Attacker Value
Unknown

CVE-2017-16186

Disclosure Date: June 07, 2018 (last updated November 26, 2024)
360class.jansenhm is a static file server. 360class.jansenhm is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
0