Filtered by vendor Kingsoftstore
Subscribe
Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-6400 | 1 Kingsoftstore | 1 Wps Office Free | 2024-02-04 | 4.6 MEDIUM | 7.8 HIGH |
Kingsoft WPS Office Free 10.2.0.5978 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through a use of \\.\pipe\WPSCloudSvr\WpsCloudSvr -- an "insecurely created named pipe." Ensures full access to Everyone users group. | |||||
CVE-2018-6217 | 1 Kingsoftstore | 1 Kingsoft Wps Office | 2024-02-04 | 4.3 MEDIUM | 5.5 MEDIUM |
The WStr::_alloc_iostr_data() function in kso.dll in Kingsoft WPS Office 10.1.0.7106 and 10.2.0.5978 allows remote attackers to cause a denial of service (application crash) via a crafted (a) web page, (b) office document, or (c) .rtf file. |