Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2021-33971

EPSS 0.22% · P45
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2021-33971

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Qihoo 360 (https://www.360.cn/) Qihoo 360 Safeguard (https://www.360.cn/) Qihoo 360 Total Security (http://www.360totalsecurity.com/) is affected by: Buffer Overflow. The impact is: execute arbitrary code (local). The component is: This is a set of vulnerabilities affecting popular software, "360 Safeguard(12.1.0.1004,12.1.0.1005,13.1.0.1001)" , "360 Total Security(10.8.0.1060,10.8.0.1213)", "360 Safe Browser & 360 Chrome(13.0.2170.0)". The attack vector is: On the browser vulnerability, just open a link to complete the vulnerability exploitation remotely; on the client software, you need to locally execute the vulnerability exploitation program, which of course can be achieved with the full chain of browser vulnerability. ¶¶ This is a set of the most serious vulnerabilities that exist on Qihoo 360's PC client a variety of popular software, remote vulnerabilities can be completed by opening a link to arbitrary code execution on both security browsers, with the use of local vulnerabilities, not only help the vulnerability code constitutes an escalation of privileges, er can make the spyware persistent without being scanned permanently resides on the target PC computer (because local vulnerability against Qihoo 360 company's antivirus kernel flaws); this group of remote and local vulnerability of the perfect match, to achieve an information security fallacy, in Qihoo 360's antivirus vulnerability, not only can not be scanned out of the virus, but will help the virus persistently control the target computer, while Qihoo 360 claims to be a safe browser, which exists in the kernel vulnerability but helped the composition of the remote vulnerability. (Security expert "Memory Corruptor" have reported this set of vulnerabilities to the corresponding vendor, all vulnerabilities have been fixed and the vendor rewarded thousands of dollars to the security experts)
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
360 Total Security 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
360 Total Security是中国北京奇虎科技有限公司(360)公司的一套计算机杀毒软件。 360 Total Security存在安全漏洞,该漏洞源于存在缓冲区溢出问题,导致攻击者可以执行任意代码。受影响的产品和版本:360 Safeguard 12.1.0.1004版本,12.1.0.1005版本,13.1.0.1001版本。360 Total Security 10.8.0.1060版本,10.8.0.1213版本。360 Safe Browser & 360 Chrome 13.0.217
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2021-33971

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-33971

登录查看更多情报信息。

Other References for CVE-2021-33971 (3)

Same Patch Batch · n/a · 2023-04-19 · 67 CVEs total

CVE-2021-0875Google Android 输入验证错误漏洞
CVE-2023-28122UI Desktop 安全漏洞
CVE-2023-23451多款SICK产品访问控制错误漏洞
CVE-2023-22894Strapi 安全漏洞
CVE-2023-29923PowerJob 安全漏洞
CVE-2023-29586Code Sector TeraCopy 安全漏洞
CVE-2023-29922PowerJob 安全漏洞
CVE-2021-0872Google Android 输入验证错误漏洞
CVE-2021-0873Google Android 输入验证错误漏洞
CVE-2021-0874Google Android 输入验证错误漏洞
CVE-2023-27777Sourcecodester Online Jewelry Shop 跨站脚本漏洞
CVE-2021-0876Google Android 输入验证错误漏洞
CVE-2021-0878Google Android 输入验证错误漏洞
CVE-2021-0879Google Android 输入验证错误漏洞
CVE-2021-0880Google Android 输入验证错误漏洞
CVE-2021-0881Google Android 输入验证错误漏洞
CVE-2021-0882Google Android 输入验证错误漏洞
CVE-2021-0883Google Android 输入验证错误漏洞
CVE-2021-0884Google Android 输入验证错误漏洞
CVE-2021-0885Google Android 输入验证错误漏洞

Showing top 20 of 67 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2021-33971

No comments yet


Leave a comment