ID

VAR-202009-0943


CVE

CVE-2020-24158


TITLE

360 Speed Browser Code problem vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-202009-230

DESCRIPTION

360 Speed Browser 12.0.1247.0 has a DLL hijacking vulnerability, which can be exploited by attackers to execute malicious code. It is a dual-core browser owned by Beijing Qihoo Technology

Trust: 0.99

sources: NVD: CVE-2020-24158 // VULHUB: VHN-178008

AFFECTED PRODUCTS

vendor:360model:speed browserscope:eqversion:12.0.1247.0

Trust: 1.0

sources: NVD: CVE-2020-24158

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-24158
value: HIGH

Trust: 1.0

CNNVD: CNNVD-202009-230
value: HIGH

Trust: 0.6

VULHUB: VHN-178008
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2020-24158
severity: MEDIUM
baseScore: 4.4
vectorString: AV:L/AC:M/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.4
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

VULHUB: VHN-178008
severity: MEDIUM
baseScore: 4.4
vectorString: AV:L/AC:M/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.4
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2020-24158
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

sources: VULHUB: VHN-178008 // CNNVD: CNNVD-202009-230 // NVD: CVE-2020-24158

PROBLEMTYPE DATA

problemtype:CWE-427

Trust: 1.1

problemtype:CWE-426

Trust: 0.1

sources: VULHUB: VHN-178008 // NVD: CVE-2020-24158

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202009-230

TYPE

code problem

Trust: 0.6

sources: CNNVD: CNNVD-202009-230

EXTERNAL IDS

db:NVDid:CVE-2020-24158

Trust: 1.7

db:CNNVDid:CNNVD-202009-230

Trust: 0.7

db:NSFOCUSid:48892

Trust: 0.6

db:VULHUBid:VHN-178008

Trust: 0.1

sources: VULHUB: VHN-178008 // CNNVD: CNNVD-202009-230 // NVD: CVE-2020-24158

REFERENCES

url:https://www.cnvd.org.cn/flaw/show/2105401

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2020-24158

Trust: 0.6

url:http://www.nsfocus.net/vulndb/48892

Trust: 0.6

sources: VULHUB: VHN-178008 // CNNVD: CNNVD-202009-230 // NVD: CVE-2020-24158

SOURCES

db:VULHUBid:VHN-178008
db:CNNVDid:CNNVD-202009-230
db:NVDid:CVE-2020-24158

LAST UPDATE DATE

2024-11-23T22:37:15.241000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-178008date:2021-07-21T00:00:00
db:CNNVDid:CNNVD-202009-230date:2022-03-08T00:00:00
db:NVDid:CVE-2020-24158date:2024-11-21T05:14:26.857

SOURCES RELEASE DATE

db:VULHUBid:VHN-178008date:2020-09-03T00:00:00
db:CNNVDid:CNNVD-202009-230date:2020-09-03T00:00:00
db:NVDid:CVE-2020-24158date:2020-09-03T17:15:11.160