Full Disclosure: by date

30 messages starting Jul 02 26 and ending Jul 22 26
Date index | Thread index | Author index


Thursday, 02 July

Zig std.http chunked reader integer overflow -> unauthenticated remote DoS Agent Spooky's Fun Parade via Fulldisclosure
Certified Asterisk Security Release certified-20.7-cert11 Asterisk Development Team via Fulldisclosure
Certified Asterisk Security Release certified-22.8-cert3 Asterisk Development Team via Fulldisclosure
Asterisk Security Release 20.20.1 Asterisk Development Team via Fulldisclosure
Asterisk Security Release 21.12.3 Asterisk Development Team via Fulldisclosure
Asterisk Security Release 22.10.1 Asterisk Development Team via Fulldisclosure
Asterisk Security Release 23.4.1 Asterisk Development Team via Fulldisclosure
Samsung Galaxy Buds – Zero-Click HFP/A2DP Takeover via L2CAP Session Preemption (Vendor Response: Working as Intended) 490h3fqwomf via Fulldisclosure
[fulldis] CVE-2026-58451 - Horde Groupware IMP path traversal vuln ㅤevan via Fulldisclosure
[KIS-2026-12] Control Web Panel <= 0.9.8.1224 (userRes) SQL Injection Vulnerability Egidio Romano
pwnlift: symlink following and TOCTOU in privileged upload handler allow arbitrary file write as root Greg via Fulldisclosure
APPLE-SA-06-29-2026-1 iOS 26.5.2 and iPadOS 26.5.2 Apple Product Security via Fulldisclosure
APPLE-SA-06-29-2026-2 macOS Tahoe 26.5.2 Apple Product Security via Fulldisclosure
APPLE-SA-06-29-2026-3 Safari 26.5.2 Apple Product Security via Fulldisclosure
Whistlelink: Site-access password exposed in web server access logs via GET query string Red Nanaki via Fulldisclosure
OpenBlow Multiple Deanonymization Vulnerabilities Red Nanaki via Fulldisclosure
Whistleblowersoftware.com: confidentiality and anonymity leakage to third parties Red Nanaki via Fulldisclosure

Monday, 06 July

SCHUTZWERK-SA-2025-001: Authentication Bypass for SafeLine SL6 and SL6+ Jan Hüber via Fulldisclosure
OPNsense XPATH Injection (CVE-2026-53582) evan

Wednesday, 08 July

[REVIVE-SA-2026-003] Revive Adserver Vulnerabilities Matteo Beccati

Wednesday, 15 July

CVE-2026-56877 - Skillable SCORM userId authorisation bypass Greg via Fulldisclosure
Subject: Advisory Submission: EZ Game Booster - Cleartext Storage of Sensitive Credentials (CWE-312) AliReza
[NotCVE-2026-0001] Cloudflare Universal SSL CAA augmentation weakens RFC 8657 account binding — CVE-2026-14440 assigned 163 days after public no-CVE disclosure NotCVE Advisories

Monday, 20 July

NotCVE registry index — public records of vulnerabilities that shipped without a CVE NotCVE Advisories
XSSer v.1.9 - "Bl4ck Swarm!" released psy
New Release: UFONet v2.0 - "R3DST4R!"... psy
ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping in ASUS Business/Software Manager kernel driver Hayaturehman Ahmadzai

Wednesday, 22 July

Amplitude customers using domain proxies should update their configuration immediately. shed riot
Synology stale DNS allows practical interception of traffic from vulnerable DSM clients shed riot
A project is publishing full analyses of AI-discovered 0-days - first batch of 10 with reproducible exploits zz lin