Vulnerabilities > 360 > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-01-11 CVE-2019-3405 Improper Input Validation vulnerability in 360 360F5 Firmware 3.1.3.64296
In the 3.1.3.64296 and lower version of 360F5, the third party can trigger the device to send a deauth frame by constructing and sending a specific illegal 802.11 Null Data Frame, which will cause other wireless terminals connected to disconnect from the wireless, so as to attack the router wireless by DoS.
network
low complexity
360 CWE-20
5.0
2020-09-03 CVE-2020-24158 Untrusted Search Path vulnerability in 360 Speed Browser 12.0.1247.0
360 Speed Browser 12.0.1247.0 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious code.
local
360 CWE-426
4.4
2020-03-04 CVE-2019-3404 Unspecified vulnerability in 360 F5C Router Firmware and P0 Router Firmware
By adding some special fields to the uri ofrouter app function, the user could abuse background app cgi functions withoutauthentication.
network
low complexity
360
5.0
2019-11-04 CVE-2018-19031 Command Injection vulnerability in 360 products
A command injection vulnerability exists when the authorized user passes crafted parameter to background process in the router.
network
low complexity
360 CWE-77
6.5
2012-01-25 CVE-2011-4772 Permissions, Privileges, and Access Controls vulnerability in 360 Kouxin 1.5.3
The 360 KouXin (com.qihoo360.kouxin) application 1.5.3 for Android does not properly protect data, which allows remote attackers to read or modify SMS messages and a contact list via a crafted application.
network
360 android CWE-264
5.8
2012-01-25 CVE-2011-4769 Permissions, Privileges, and Access Controls vulnerability in 360 Mobilesafe 2.1.0/2.2.0
The 360 MobileSafe (com.qihoo360.mobilesafe) application 2.x before 2.3.0 for Android does not properly protect data, which allows remote attackers to read or modify SMS messages and a contact list via a crafted application.
network
360 android CWE-264
5.8