04-05-2020 21:15:00
A potential DoS flaw was found in the virtio-fs shared file system daemon (virtiofsd) implementation of the QEMU version >= v5.0. Virtio-fs is meant to share a host file system directory with a guest via virtio-fs device. If the guest opens the maximum number of file descriptors under the shared directory, a denial of service may occur. This flaw allows a guest user/process to cause this denial of service on the host.
04-05-2020 21:15:00
A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user registers as oneself. The attacker could then use the remove devices form to post different credential IDs and possibly remove MFA devices for other users.
04-05-2020 20:15:00
A Buffer Overflow vulnerability in the khcrypt implementation in Google Earth Pro versions up to and including 7.3.2 allows an attacker to perform a Man-in-the-Middle attack using a specially crafted key to read data past the end of the buffer used to hold it. Mitigation: Update to Google Earth Pro 7.3.3.
04-05-2020 19:15:00
RSA Archer, versions prior to 6.7 P2 (, contain a cross-site request forgery vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim application user to send arbitrary requests to the vulnerable application to perform server operations with the privileges of the authenticated victim user.
04-05-2020 19:15:00
LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to arbitrary file creation by unauthorized users



FaceTime - 'readSPSandGetDecoderParams' Stack Corruption macos Google Security Research
OpenBiz Cubi Lite 3.0.8 - 'username' SQL Injection php AkkuS
SiAdmin 1.1 - 'id' SQL Injection php Ihsan Sencan
LiquidVPN 1.36 / 1.37 - Privilege Escalation macos Bernd Leitner
Royal TS/X - Information Disclosure json Jakub Palaczynski