A vulnerability was found in Interinfo DreamMaker. It has been rated as problematic. Affected by this issue is some unknown functionality of the component System Files Handler. The manipulation leads to absolute path traversal.
This vulnerability is handled as CVE-2024-11978. The attack may be launched remotely. There is no exploit available.
A vulnerability was found in Mitsubishi Electric GENESIS64 and MC Works64. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component DLL Handler. The manipulation leads to uncontrolled search path.
This vulnerability is known as CVE-2024-8299. Local access is required to approach this attack. There is no exploit available.
A vulnerability was found in Mitsubishi Electric GENESIS64 and MC Works64. It has been classified as critical. Affected is an unknown function of the component DLL Handler. The manipulation leads to uncontrolled search path.
This vulnerability is traded as CVE-2024-9852. An attack has to be approached locally. There is no exploit available.
A vulnerability has been found in pyspider up to 0.3.10 and classified as problematic. This vulnerability affects unknown code of the file /update. The manipulation leads to cross site scripting. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability was named CVE-2024-39162. The attack can be initiated remotely. There is no exploit available.
A vulnerability, which was classified as critical, was found in Interinfo DreamMaker. This affects an unknown part. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2024-11979. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability, which was classified as critical, has been found in LinkStack up to 4.7.7. Affected by this issue is some unknown functionality of the file resources\views\components\favicon.blade.php. The manipulation leads to server-side request forgery.
This vulnerability is handled as CVE-2024-35451. Access to the local network is required for this attack. There is no exploit available.
Thousands of unique IP addresses are potentially exposing medical devices, electronic medical records systems and other sensitive healthcare information to the internet, said security researcher Himaja Motheram of security firm Censys, which made the discovery.
President-Elect's Crypto Push Fuels Concerns Over Market Stability and Conflicts President-elect Donald Trump's strong cryptocurrency support amid market volatility is raising concerns over potential conflicts of interest, with experts warning his agenda - including potential plans to appoint a White House crypto czar - could destabilize the economy and undermine public trust.
Also: Africa Busts Cybercrime Suspects; Many Smart Devices Lack Update Transparency This week, Microsoft previews its latest attempt to introduce AI-enabled Windows Recall - now with added privacy features; over 1,000 cybercrime suspects busted in Africa; regulators report "smart" device update promises often missing; and Florida IT professional caught spying for China.
Linux-Targeting Bootkitty Appears More Proof-of-Concept Than Threat, Researcher Say Cybersecurity researchers have discovered the first-ever bootkit designed to target Linux systems and subvert their boot process for malicious purposes. The "Bootkitty" malware, first uploaded to VirusTotal this month, appears to be more "proof of concept" than full-fledged threat, they said.
A vulnerability was found in Nagios up to 4.4.1. It has been declared as problematic. Affected by this vulnerability is the function qh_core of the component Unix Socket Handler. The manipulation leads to null pointer dereference.
This vulnerability is known as CVE-2018-13458. An attack has to be approached locally. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
A 59-year-old U.S. citizen who immigrated from the People's Republic of China (PRC) has been sentenced to four years in prison for conspiring to act as a spy for the country and sharing sensitive information about his employer with China's principal civilian intelligence agency.
Ping Li, 59, of Wesley Chapel, Florida, is said to have served as a cooperative contact for the Ministry of State