A vulnerability was found in ContiNew Admin 3.2.0 and classified as critical. Affected by this issue is the function top.continew.starter.extension.crud.controller.BaseController#page of the file /api/system/user?deptId=1&page=1&size=10. The manipulation of the argument sort leads to sql injection.
This vulnerability is handled as CVE-2024-8150. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability has been found in Hyperledger Fabric up to 2.5.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Timestamp Handler. The manipulation leads to Privilege Escalation.
This vulnerability is known as CVE-2024-45244. The attack needs to be approached within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
A vulnerability, which was classified as problematic, was found in TikTok App up to 34.5.4 on Android. Affected is an unknown function of the component Lynxview JavaScript Interface. The manipulation leads to an unknown weakness.
This vulnerability is traded as CVE-2024-45240. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in NICMx Fort up to 1.6.2. This issue affects some unknown processing. The manipulation of the argument eContent leads to null pointer dereference.
The identification of this vulnerability is CVE-2024-45239. Access to the local network is required for this attack. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic was found in NICMx Fort up to 1.6.2. This vulnerability affects unknown code of the component Signed Object Handler. The manipulation of the argument signedAttributes leads to denial of service.
This vulnerability was named CVE-2024-45236. The attack needs to be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as problematic has been found in NICMx Fort up to 1.6.2. This affects an unknown part of the component BER Decoder. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2024-45234. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in NICMx Fort up to 1.6.2. It has been rated as critical. Affected by this issue is some unknown functionality of the component Resource Certificate Handler. The manipulation leads to buffer overflow.
This vulnerability is handled as CVE-2024-45237. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in NICMx Fort up to 1.6.2. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Resource Certificate Handler. The manipulation of the argument keyIdentifier leads to null pointer dereference.
This vulnerability is known as CVE-2024-45235. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in NICMx Fort up to 1.6.2. It has been classified as problematic. Affected is an unknown function of the component RPKI Repository Handler. The manipulation leads to null pointer dereference.
This vulnerability is traded as CVE-2024-45238. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
Pavel Durov, founder and chief executive of the popular messaging app Telegram, was arrested in France on Saturday, according to French television network TF1.
Durov is believed to have been apprehended pursuant to a warrant issued in connection with a preliminary police investigation.
TF1 said the probe was focused on a lack of content moderation on the instant messaging service, which the
Cybersecurity researchers have uncovered a new stealthy piece of Linux malware that leverages an unconventional technique to achieve persistence on infected systems and hide credit card skimmer code.
The malware, attributed to a financially motivated threat actor, has been codenamed sedexp by Aon's Stroz Friedberg incident response services team.
"This advanced threat, active since 2022, hides