The TAOTH campaign exploited abandoned software and spear-phishing to deploy multiple malware families, targeting dissidents and other high-value individuals across Eastern Asia.
A vulnerability classified as critical has been found in Oracle Commerce Platform 11.3.0/11.3.1/11.3.2. This affects an unknown part of the component Dynamo Application Framework. This manipulation causes denial of service.
This vulnerability is tracked as CVE-2020-36518. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.
A vulnerability identified as critical has been detected in Oracle Communications Billing and Revenue Management up to 12.0.0.6.0. Affected by this issue is some unknown functionality of the component Billing Care/BOC/DM Kafka/REST API. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2020-36518. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
A vulnerability has been found in Oracle Communications Cloud Native Core Binding Support Function 22.1.3 and classified as critical. This issue affects some unknown processing of the component BSF. The manipulation leads to denial of service.
This vulnerability is listed as CVE-2020-36518. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
A vulnerability labeled as critical has been found in Oracle Communications Cloud Native Core Network Repository Function 22.1.2/22.2.0. Affected by this vulnerability is an unknown functionality of the component NRF. The manipulation results in denial of service.
This vulnerability is known as CVE-2020-36518. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
A vulnerability described as critical has been identified in Oracle Communications Cloud Native Core Network Slice Selection Function 22.1.1. This affects an unknown part of the component NSSF. Such manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2020-36518. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability classified as critical was found in Oracle Communications Cloud Native Core Security Edge Protection Proxy 22.1.1. This issue affects some unknown processing of the component SEPP. Executing manipulation can lead to denial of service.
The identification of this vulnerability is CVE-2020-36518. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability has been found in Oracle Communications Cloud Native Core Service Communication Proxy 22.2.0 and classified as critical. The impacted element is an unknown function of the component SCP. This manipulation causes denial of service.
This vulnerability is tracked as CVE-2020-36518. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
A vulnerability was found in Oracle Communications Cloud Native Core Unified Data Repository 22.2.0 and classified as critical. This affects an unknown function of the component UDR. Such manipulation leads to denial of service.
This vulnerability is listed as CVE-2020-36518. The attack may be performed from a remote location. There is no available exploit.
It is suggested to upgrade the affected component.
A vulnerability classified as critical was found in Oracle SD-WAN Edge 9.0/9.1. The impacted element is an unknown function of the component MGMT. The manipulation results in denial of service.
This vulnerability was named CVE-2020-36518. The attack may be performed from a remote location. There is no available exploit.
Upgrading the affected component is advised.
A vulnerability classified as critical was found in WP Easy Gallery Plugin up to 4.8.5 on WordPress. This issue affects some unknown processing. Such manipulation leads to sql injection.
This vulnerability is listed as CVE-2024-8436. The attack may be performed from a remote location. There is no available exploit.