Qihoo 360

First CVE: Nov 4, 2019Active for: 7 years
6
CVEs Published
More CVEs Published than 18% of tracked CNAs
2.0
Avg CVEs / Year
More Avg CVEs / Year than 11% of tracked CNAs
7.5
Avg CVSS Score
Higher Avg CVSS Score than 68% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by Qihoo 360 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 4, 2019
6 years ago
Most Recent CVE
Jan 11, 2021
2,021 days ago

Top CVEs

All CVEs published by Qihoo 360 as a CNA, regardless of affected vendor or product.

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In the version 12.1.0.1005 and below of 360 Total Security, when the Gamefolde calls GameChrome.exe, there exists a local privilege escalation vulnerability. An attacker who could
Jul 21, 20207.825NONO
In the version 12.1.0.1004 and below of 360 Total Security, when the main process of 360 Total Security calls GameChrome.exe, there exists a local privilege escalation vulnerabilit
Jul 21, 20207.825NONO
A command injection vulnerability exists when the authorized user passes crafted parameter to background process in the router. This affects 360 router series products (360 Safe Ro
Nov 4, 20198.825NONO
By adding some special fields to the uri ofrouter app function, the user could abuse background app cgi functions withoutauthentication. This affects 360 router P0 and F5C.
Mar 4, 20207.523NONO
In version 12.1.0.1004 and below of 360 Total Security,when TPI calls the browser process, there exists a local privilege escalation vulnerability. An attacker who could exploit DL
Jul 21, 20207.822NONO
In the 3.1.3.64296 and lower version of 360F5, the third party can trigger the device to send a deauth frame by constructing and sending a specific illegal 802.11 Null Data Frame,
Jan 11, 20215.319NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA6 CVEs
Severity distribution among all CVEs352,708 CVEs
MediumHigh
Attack Vector
Local3 (50.0%)
Network3 (50.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (50.0%)
Unknown0 (0.0%)
Required3 (50.0%)
Privileges Required
Low1 (16.7%)
High0 (0.0%)
None5 (83.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Qihoo 360 as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Qihoo 360 as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs