Aggregates CVE and security vulnerability intelligence across all 360totalsecurity-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Common weakness patterns include vendor risk buffer overflow, with potential vendor impact application crash and vendor impact memory corruption across vendor surface software deployment use cases.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2024-22014 | An issue discovered in 360 Total Security Antivirus through 11.0.0.1061 for Windows allows attackers to gain escalated privileges via Symbolic Link Follow to Arbitrary File Delete. | [email protected] | 8.8 | 0.40% | 2024-04-15 | 2025-06-30 |
| CVE-2021-33973 | Buffer Overflow vulnerability in Qihoo 360 Safe guard v12.1.0.1004, v12.1.0.1005, v13.1.0.1001 allows attacker to escalate priveleges. | [email protected] | 7.8 | 0.19% | 2023-04-19 | 2025-02-05 |
| CVE-2020-15724 | In the version 12.1.0.1005 and below of 360 Total Security, when the Gamefolde calls GameChrome.exe, there exists a local privilege escalation vulnerability. An attacker who could exploit DLL hijacking to bypass the hips could execute arbitrary code on the Local system. | [email protected] | 7.8 | 0.04% | 2020-07-21 | 2024-11-21 |
| CVE-2020-15723 | In the version 12.1.0.1004 and below of 360 Total Security, when the main process of 360 Total Security calls GameChrome.exe, there exists a local privilege escalation vulnerability. An attacker who could exploit DLL hijacking to bypass the hips could execute arbitrary code on the Local system. | [email protected] | 7.8 | 0.04% | 2020-07-21 | 2024-11-21 |
| CVE-2020-15722 | In version 12.1.0.1004 and below of 360 Total Security,when TPI calls the browser process, there exists a local privilege escalation vulnerability. An attacker who could exploit DLL hijacking could execute arbitrary code on the Local system. | [email protected] | 7.8 | 0.05% | 2020-07-21 | 2024-11-21 |
| CVE-2018-18603 | 360 Total Security 3.5.0.1033 allows a Sandbox Escape via an "import os" statement, followed by os.system("CMD") or os.system("PowerShell"), within a .py file. NOTE: the vendor's position is that this cannot be categorized as a vulnerability, although it is a security-related issue | [email protected] | 6.3 | 0.19% | 2018-10-23 | 2024-11-21 |
| CVE-2017-12653 | 360 Total Security 9.0.0.1202 before 2017-07-07 allows Privilege Escalation via a Trojan horse Shcore.dll file in any directory in the PATH, as demonstrated by the C:\Python27 directory. | [email protected] | 7.8 | 2.24% | 2017-08-07 | 2026-05-13 |