Qihoo 360
First CVE: Nov 4, 2019Active for: 7 years
6
CVEs Published
More CVEs Published than 18% of tracked CNAs
2.0
Avg CVEs / Year
More Avg CVEs / Year than 11% of tracked CNAs
7.5
Avg CVSS Score
Higher Avg CVSS Score than 68% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Qihoo 360 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 4, 2019
6 years ago
Most Recent CVE
Jan 11, 2021
2,021 days ago
Top CVEs
All CVEs published by Qihoo 360 as a CNA, regardless of affected vendor or product.
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-15724HIGH In the version 12.1.0.1005 and below of 360 Total Security, when the Gamefolde calls GameChrome.exe, there exists a local privilege escalation vulnerability. An attacker who could | Jul 21, 2020 | 7.8 | 25 | NO | NO |
CVE-2020-15723HIGH In the version 12.1.0.1004 and below of 360 Total Security, when the main process of 360 Total Security calls GameChrome.exe, there exists a local privilege escalation vulnerabilit | Jul 21, 2020 | 7.8 | 25 | NO | NO |
CVE-2018-19031HIGH A command injection vulnerability exists when the authorized user passes crafted parameter to background process in the router. This affects 360 router series products (360 Safe Ro | Nov 4, 2019 | 8.8 | 25 | NO | NO |
CVE-2019-3404HIGH By adding some special fields to the uri ofrouter app function, the user could abuse background app cgi functions withoutauthentication. This affects 360 router P0 and F5C. | Mar 4, 2020 | 7.5 | 23 | NO | NO |
CVE-2020-15722HIGH In version 12.1.0.1004 and below of 360 Total Security,when TPI calls the browser process, there exists a local privilege escalation vulnerability. An attacker who could exploit DL | Jul 21, 2020 | 7.8 | 22 | NO | NO |
CVE-2019-3405MEDIUM In the 3.1.3.64296 and lower version of 360F5, the third party can trigger the device to send a deauth frame by constructing and sending a specific illegal 802.11 Null Data Frame, | Jan 11, 2021 | 5.3 | 19 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA6 CVEs
17%
83%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local3 (50.0%)
Network3 (50.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (50.0%)
Unknown0 (0.0%)
Required3 (50.0%)
Privileges Required
Low1 (16.7%)
High0 (0.0%)
None5 (83.3%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Qihoo 360 as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Qihoo 360 as a CNA — matched by CVE ID, not by organization name.