Full Disclosure Mailing List

A public, vendor-neutral forum for detailed discussion of vulnerabilities and exploitation techniques, as well as tools, papers, news, and events of interest to the community. The relaxed atmosphere of this quirky list provides some comic relief and certain industry gossip. More importantly, fresh vulnerabilities sometimes hit this list many hours or days before they pass through the Bugtraq moderation queue.

List Archives

Latest Posts

APPLE-SA-08-17-2026-2 iOS 18.7.10 and iPadOS 18.7.10 Apple Product Security via Fulldisclosure (Aug 17)
APPLE-SA-08-17-2026-2 iOS 18.7.10 and iPadOS 18.7.10

iOS 18.7.10 and iPadOS 18.7.10 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/148287.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accessibility
Available for: iPhone XS, iPhone XS Max, iPhone XR, iPad 7th generation
Impact: An...

APPLE-SA-08-06-2026-2 macOS Sequoia 15.7.9 Apple Product Security via Fulldisclosure (Aug 13)
APPLE-SA-08-06-2026-2 macOS Sequoia 15.7.9

macOS Sequoia 15.7.9 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/en-us/148171.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Screen Sharing
Available for: macOS Sequoia
Impact: An attacker on the network may be able to authenticate to...

APPLE-SA-08-06-2026-3 macOS Sonoma 14.8.9 Apple Product Security via Fulldisclosure (Aug 13)
APPLE-SA-08-06-2026-3 macOS Sonoma 14.8.9

macOS Sonoma 14.8.9 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/en-us/148172.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Screen Sharing
Available for: macOS Sonoma
Impact: An attacker on the network may be able to authenticate to...

Dangling DNS record for bastion.certb.cdp.bethesda.net shed riot (Aug 06)
# Summary

The hostname resolved to an address within a dynamic cloud IP pool.
The address had been released and was no longer controlled by the
organisation operating the hostname.

This condition is referred to as an "afterlife" issue.

Unlike a conventional CNAME-based subdomain takeover, the DNS record
pointed directly to a reusable cloud IP address. An attacker obtaining
that address could receive traffic intended for the...

CL.0 desync in www.microsoft.com shed riot (Aug 06)
# Summary

I reported the issue to the Microsoft Security Response Center twice:

* VULN-165381, MSRC case 102964
* VULN-165876, MSRC case 103259

In both cases, they do not appear to have even looked at the PoCs, and so
have failed to adequately investigate before reaching a decision.

# Vulnerability

CWE-444: HTTP Request/Response Smuggling

The observed behaviour was consistent with CL.0 HTTP desync within the
request-processing chain.

#...

CVE-2026-15013 – miniOrange SAML SSO <= 5.4.3 Unauthenticated Authentication Bypass (PoC) Öner Efe Güngör (Aug 06)
Hello Full Disclosure,

I'd like to share an independent lab Proof-of-Concept for CVE-2026-15013.

### CVE-2026-15013 – miniOrange SAML SSO <= 5.4.3 Unauthenticated
Authentication Bypass

SAML Signature Algorithm Confusion vulnerability. An unauthenticated
attacker can forge a valid SAMLResponse by forcing HMAC-SHA1 verification
against the IdP's public key, allowing full account takeover (including
administrators).

Root cause:...

[KIS-2026-16] Telenia Software TVox <= 26.5.3 (nice) Local Privilege Escalation Vulnerability Egidio Romano (Aug 06)
-------------------------------------------------------------------------------
Telenia Software TVox <= 26.5.3 (nice) Local Privilege Escalation
Vulnerability
-------------------------------------------------------------------------------

[-] Software Link:

https://www.teleniasoftware.com

[-] Affected Versions:

Version 26.5.3 and prior 26.x versions.
Version 24.9.21 and prior 24.x versions.
Older versions may be affected as well.

[-]...

[KIS-2026-15] Telenia Software TVox <= 26.5.3 (action_audio.php) OS Command Injection Vulnerability Egidio Romano (Aug 06)
-------------------------------------------------------------------------------------
Telenia Software TVox <= 26.5.3 (action_audio.php) OS Command Injection
Vulnerability
-------------------------------------------------------------------------------------

[-] Software Link:

https://www.teleniasoftware.com

[-] Affected Versions:

Version 26.5.3 and prior 26.x versions.
Version 24.9.21 and prior 24.x versions.
Older versions may be affected...

[KIS-2026-14] Telenia Software TVox <= 26.5.3 (set_env.php) Authentication Bypass Vulnerability Egidio Romano (Aug 06)
---------------------------------------------------------------------------------
Telenia Software TVox <= 26.5.3 (set_env.php) Authentication Bypass
Vulnerability
---------------------------------------------------------------------------------

[-] Software Link:

https://www.teleniasoftware.com

[-] Affected Versions:

Version 26.5.3 and prior 26.x versions.
Version 24.9.21 and prior 24.x versions.
Older versions may be affected as well....

[KIS-2026-13] vBulletin <= 6.2.1 (runMaths) Remote Code Execution Vulnerability Egidio Romano (Aug 06)
-----------------------------------------------------------------
vBulletin <= 6.2.1 (runMaths) Remote Code Execution Vulnerability
-----------------------------------------------------------------

[-] Software Link:

https://www.vbulletin.com

[-] Affected Versions:

Version 5.7.5 and prior 5.x versions.
Version 6.2.1 and prior 6.x versions.

[-] Vulnerability Description:

The vulnerable code is located within the...

[SYSS-2026-050]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190) Matthias Deeg via Fulldisclosure (Aug 06)
Advisory ID: SYSS-2026-050
Product: DCMTK (DICOM ToolKit)
Manufacturer: OFFIS e.V. / DCMTK Community
Affected Version(s): 3.7.0
Tested Version(s): 3.7.0
Vulnerability Type: Integer Overflow or Wraparound (CWE-190)
Risk Level: Medium
Solution Status: Fixed
Manufacturer Notification: 2026-07-02
Solution Date: 2026-07-03
Public Disclosure:...

[SYSS-2026-049]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190) Matthias Deeg via Fulldisclosure (Aug 06)
Advisory ID: SYSS-2026-049
Product: DCMTK (DICOM ToolKit)
Manufacturer: OFFIS e.V. / DCMTK Community
Affected Version(s): 3.7.0
Tested Version(s): 3.7.0
Vulnerability Type: Integer Overflow or Wraparound (CWE-190)
Risk Level: High
Solution Status: Fixed
Manufacturer Notification: 2026-07-02
Solution Date: 2026-07-03
Public Disclosure:...

[SYSS-2026-048]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190) Matthias Deeg via Fulldisclosure (Aug 06)
Advisory ID: SYSS-2026-048
Product: DCMTK (DICOM ToolKit)
Manufacturer: OFFIS e.V. / DCMTK Community
Affected Version(s): 3.7.0
Tested Version(s): 3.7.0
Vulnerability Type: Integer Overflow or Wraparound (CWE-190)
Risk Level: High
Solution Status: Fixed
Manufacturer Notification: 2026-07-02
Solution Date: 2026-07-03
Public Disclosure:...

[SYSS-2026-047]: DICOM Toolkit (DCMTK) - Path traversal (CWE-22) Matthias Deeg via Fulldisclosure (Aug 06)
Advisory ID: SYSS-2026-047
Product: DCMTK (DICOM ToolKit)
Manufacturer: OFFIS e.V. / DCMTK Community
Affected Version(s): 3.7.0
Tested Version(s): 3.7.0
Vulnerability Type: Path traversal (CWE-22)
Risk Level: High
Solution Status: Fixed
Manufacturer Notification: 2026-07-02
Solution Date: 2026-07-03
Public Disclosure: 2026-07-31
CVE...

[SYSS-2026-046]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190) Matthias Deeg via Fulldisclosure (Aug 06)
Advisory ID: SYSS-2026-046
Product: DCMTK (DICOM ToolKit)
Manufacturer: OFFIS e.V. / DCMTK Community
Affected Version(s): 3.7.0
Tested Version(s): 3.7.0
Vulnerability Type: Integer Overflow or Wraparound (CWE-190)
Risk Level: High
Solution Status: Fixed
Manufacturer Notification: 2026-07-02
Solution Date: 2026-07-03
Public Disclosure:...

More Lists

Dozens of other network security lists are archived at SecLists.Org.