Full Disclosure: by author

30 messages starting Jul 02 26 and ending Jul 22 26
Date index | Thread index | Author index


490h3fqwomf via Fulldisclosure

Samsung Galaxy Buds – Zero-Click HFP/A2DP Takeover via L2CAP Session Preemption (Vendor Response: Working as Intended) 490h3fqwomf via Fulldisclosure (Jul 02)

Agent Spooky's Fun Parade via Fulldisclosure

Zig std.http chunked reader integer overflow -> unauthenticated remote DoS Agent Spooky's Fun Parade via Fulldisclosure (Jul 02)

AliReza

Subject: Advisory Submission: EZ Game Booster - Cleartext Storage of Sensitive Credentials (CWE-312) AliReza (Jul 15)

Apple Product Security via Fulldisclosure

APPLE-SA-06-29-2026-1 iOS 26.5.2 and iPadOS 26.5.2 Apple Product Security via Fulldisclosure (Jul 02)
APPLE-SA-06-29-2026-2 macOS Tahoe 26.5.2 Apple Product Security via Fulldisclosure (Jul 02)
APPLE-SA-06-29-2026-3 Safari 26.5.2 Apple Product Security via Fulldisclosure (Jul 02)

Asterisk Development Team via Fulldisclosure

Asterisk Security Release 23.4.1 Asterisk Development Team via Fulldisclosure (Jul 02)
Certified Asterisk Security Release certified-22.8-cert3 Asterisk Development Team via Fulldisclosure (Jul 02)
Asterisk Security Release 21.12.3 Asterisk Development Team via Fulldisclosure (Jul 02)
Asterisk Security Release 22.10.1 Asterisk Development Team via Fulldisclosure (Jul 02)
Asterisk Security Release 20.20.1 Asterisk Development Team via Fulldisclosure (Jul 02)
Certified Asterisk Security Release certified-20.7-cert11 Asterisk Development Team via Fulldisclosure (Jul 02)

Egidio Romano

[KIS-2026-12] Control Web Panel <= 0.9.8.1224 (userRes) SQL Injection Vulnerability Egidio Romano (Jul 02)

evan

OPNsense XPATH Injection (CVE-2026-53582) evan (Jul 06)

ㅤevan via Fulldisclosure

[fulldis] CVE-2026-58451 - Horde Groupware IMP path traversal vuln ㅤevan via Fulldisclosure (Jul 02)

Greg via Fulldisclosure

pwnlift: symlink following and TOCTOU in privileged upload handler allow arbitrary file write as root Greg via Fulldisclosure (Jul 02)
CVE-2026-56877 - Skillable SCORM userId authorisation bypass Greg via Fulldisclosure (Jul 15)

Hayaturehman Ahmadzai

ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping in ASUS Business/Software Manager kernel driver Hayaturehman Ahmadzai (Jul 20)

Jan Hüber via Fulldisclosure

SCHUTZWERK-SA-2025-001: Authentication Bypass for SafeLine SL6 and SL6+ Jan Hüber via Fulldisclosure (Jul 06)

Matteo Beccati

[REVIVE-SA-2026-003] Revive Adserver Vulnerabilities Matteo Beccati (Jul 08)

NotCVE Advisories

NotCVE registry index — public records of vulnerabilities that shipped without a CVE NotCVE Advisories (Jul 20)
[NotCVE-2026-0001] Cloudflare Universal SSL CAA augmentation weakens RFC 8657 account binding — CVE-2026-14440 assigned 163 days after public no-CVE disclosure NotCVE Advisories (Jul 15)

psy

XSSer v.1.9 - "Bl4ck Swarm!" released psy (Jul 20)
New Release: UFONet v2.0 - "R3DST4R!"... psy (Jul 20)

Red Nanaki via Fulldisclosure

OpenBlow Multiple Deanonymization Vulnerabilities Red Nanaki via Fulldisclosure (Jul 02)
Whistleblowersoftware.com: confidentiality and anonymity leakage to third parties Red Nanaki via Fulldisclosure (Jul 02)
Whistlelink: Site-access password exposed in web server access logs via GET query string Red Nanaki via Fulldisclosure (Jul 02)

shed riot

Amplitude customers using domain proxies should update their configuration immediately. shed riot (Jul 22)
Synology stale DNS allows practical interception of traffic from vulnerable DSM clients shed riot (Jul 22)

zz lin

A project is publishing full analyses of AI-discovered 0-days - first batch of 10 with reproducible exploits zz lin (Jul 22)