360 produces a focused line of security appliances and firmware products, including endpoint protection (Total Security), network devices (360F5 and related routers), and associated firmware components that protect against network and application-layer threats. The vulnerability exposure clusters around memory-safety issues such as buffer overflows and out-of-bounds writes, alongside command-injection and search-path weaknesses typical of firmware and network-device codebases. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 360 over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-33974HIGH Qihoo 360 (https://www.360.cn/) Qihoo 360 Safeguard (https://www.360.cn/) Qihoo 360 Chrome (https://browser.360.cn/ee/) is affected by: Buffer Overflow. The impact is: execute arbi | Apr 19, 2023 | 8.8 | 26 | NO | NO |
CVE-2018-19031HIGH A command injection vulnerability exists when the authorized user passes crafted parameter to background process in the router. This affects 360 router series products (360 Safe Ro | Nov 4, 2019 | 8.8 | 25 | NO | NO |
CVE-2021-33971HIGH Qihoo 360 (https://www.360.cn/) Qihoo 360 Safeguard (https://www.360.cn/) Qihoo 360 Total Security (http://www.360totalsecurity.com/) is affected by: Buffer Overflow. The impact is | Apr 19, 2023 | 7.8 | 24 | NO | NO |
CVE-2023-27077HIGH Stack Overflow vulnerability found in 360 D901 allows a remote attacker to cause a Distributed Denial of Service (DDOS) via a crafted HTTP package. | Mar 23, 2023 | 7.5 | 24 | NO | NO |
CVE-2020-24158HIGH 360 Speed Browser 12.0.1247.0 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious code. It is a dual-core browser owned by Beijing Qihoo Tec | Sep 3, 2020 | 7.8 | 23 | NO | NO |
CVE-2019-3404HIGH By adding some special fields to the uri ofrouter app function, the user could abuse background app cgi functions withoutauthentication. This affects 360 router P0 and F5C. | Mar 4, 2020 | 7.5 | 23 | NO | NO |
CVE-2019-3405MEDIUM In the 3.1.3.64296 and lower version of 360F5, the third party can trigger the device to send a deauth frame by constructing and sending a specific illegal 802.11 Null Data Frame, | Jan 11, 2021 | 5.3 | 19 | NO | NO |
CVE-2011-4769MEDIUM The 360 MobileSafe (com.qihoo360.mobilesafe) application 2.x before 2.3.0 for Android does not properly protect data, which allows remote attackers to read or modify SMS messages a | Jan 25, 2012 | 5.8 | 19 | NO | NO |
CVE-2011-4772MEDIUM The 360 KouXin (com.qihoo360.kouxin) application 1.5.3 for Android does not properly protect data, which allows remote attackers to read or modify SMS messages and a contact list v | Jan 25, 2012 | 5.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 360.
Media articles that mention a CVE ID that affects a product developed by 360 — matched by CVE ID, not by vendor name.