Mail Index
Thread Index
[FD] Zig std.http chunked reader integer overflow -> unauthenticated remote DoS
From
: Agent Spooky's Fun Parade via Fulldisclosure
[FD] Certified Asterisk Security Release certified-20.7-cert11
From
: Asterisk Development Team via Fulldisclosure
[FD] Certified Asterisk Security Release certified-22.8-cert3
From
: Asterisk Development Team via Fulldisclosure
[FD] Asterisk Security Release 20.20.1
From
: Asterisk Development Team via Fulldisclosure
[FD] Asterisk Security Release 21.12.3
From
: Asterisk Development Team via Fulldisclosure
[FD] Asterisk Security Release 22.10.1
From
: Asterisk Development Team via Fulldisclosure
[FD] Asterisk Security Release 23.4.1
From
: Asterisk Development Team via Fulldisclosure
[FD] Samsung Galaxy Buds – Zero-Click HFP/A2DP Takeover via L2CAP Session Preemption (Vendor Response: Working as Intended)
From
: 490h3fqwomf via Fulldisclosure
[FD] [fulldis] CVE-2026-58451 - Horde Groupware IMP path traversal vuln
From
: ㅤevan via Fulldisclosure
[FD] [KIS-2026-12] Control Web Panel <= 0.9.8.1224 (userRes) SQL Injection Vulnerability
From
: Egidio Romano
[FD] pwnlift: symlink following and TOCTOU in privileged upload handler allow arbitrary file write as root
From
: Greg via Fulldisclosure
[FD] APPLE-SA-06-29-2026-1 iOS 26.5.2 and iPadOS 26.5.2
From
: Apple Product Security via Fulldisclosure
[FD] APPLE-SA-06-29-2026-2 macOS Tahoe 26.5.2
From
: Apple Product Security via Fulldisclosure
[FD] APPLE-SA-06-29-2026-3 Safari 26.5.2
From
: Apple Product Security via Fulldisclosure
[FD] Whistlelink: Site-access password exposed in web server access logs via GET query string
From
: Red Nanaki via Fulldisclosure
[FD] OpenBlow Multiple Deanonymization Vulnerabilities
From
: Red Nanaki via Fulldisclosure
[FD] Whistleblowersoftware.com: confidentiality and anonymity leakage to third parties
From
: Red Nanaki via Fulldisclosure
[FD] SCHUTZWERK-SA-2025-001: Authentication Bypass for SafeLine SL6 and SL6+
From
: Jan Hüber via Fulldisclosure
[FD] OPNsense XPATH Injection (CVE-2026-53582)
From
: evan
[FD] [REVIVE-SA-2026-003] Revive Adserver Vulnerabilities
From
: Matteo Beccati
[FD] CVE-2026-56877 - Skillable SCORM userId authorisation bypass
From
: Greg via Fulldisclosure
[FD] Subject: Advisory Submission: EZ Game Booster - Cleartext Storage of Sensitive Credentials (CWE-312)
From
: AliReza
[FD] [NotCVE-2026-0001] Cloudflare Universal SSL CAA augmentation weakens RFC 8657 account binding — CVE-2026-14440 assigned 163 days after public no-CVE disclosure
From
: NotCVE Advisories
[FD] NotCVE registry index — public records of vulnerabilities that shipped without a CVE
From
: NotCVE Advisories
[FD] XSSer v.1.9 - "Bl4ck Swarm!" released
From
: psy
[FD] New Release: UFONet v2.0 - "R3DST4R!"...
From
: psy
[FD] ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping in ASUS Business/Software Manager kernel driver
From
: Hayaturehman Ahmadzai
[FD] Amplitude customers using domain proxies should update their configuration immediately.
From
: shed riot
[FD] Synology stale DNS allows practical interception of traffic from vulnerable DSM clients
From
: shed riot
[FD] A project is publishing full analyses of AI-discovered 0-days - first batch of 10 with reproducible exploits
From
: zz lin
Mail converted by
MHonArc