
Full Disclosure Mailing List
A public, vendor-neutral forum for detailed discussion of vulnerabilities and exploitation techniques, as well as tools, papers, news, and events of interest to the community. The relaxed atmosphere of this quirky list provides some comic relief and certain industry gossip. More importantly, fresh vulnerabilities sometimes hit this list many hours or days before they pass through the Bugtraq moderation queue.
List Archives
- Jan
- Feb
- Mar
- Apr
- May
- Jun
- Jul
- Aug
- Sep
- Oct
- Nov
- Dec
- 2026
- 31
- 32
- 26
- 22
- 26
- 22
- 30
- 121
- 79
- –
- –
- –
- 2025
- 24
- 20
- 9
- 32
- 24
- 28
- 40
- 19
- 80
- 33
- 22
- 37
- 2024
- 75
- 25
- 44
- 29
- 37
- 13
- 24
- 41
- 60
- 21
- 20
- 22
- 2023
- 29
- 17
- 27
- 14
- 28
- 10
- 52
- 33
- 21
- 32
- 15
- 30
- 2022
- 91
- 57
- 63
- 54
- 48
- 57
- 27
- 17
- 30
- 52
- 26
- 32
- 2021
- 84
- 93
- 81
- 77
- 81
- 60
- 72
- 39
- 59
- 79
- 56
- 50
- 2020
- 52
- 36
- 57
- 63
- 60
- 35
- 37
- 24
- 55
- 34
- 45
- 60
- 2019
- 71
- 54
- 64
- 41
- 52
- 49
- 40
- 37
- 45
- 59
- 34
- 37
- 2018
- 102
- 84
- 79
- 61
- 73
- 46
- 95
- 53
- 57
- 54
- 69
- 56
- 2017
- 99
- 103
- 91
- 113
- 108
- 52
- 95
- 58
- 98
- 71
- 51
- 89
- 2016
- 100
- 128
- 97
- 93
- 75
- 79
- 89
- 139
- 85
- 103
- 162
- 88
- 2015
- 134
- 101
- 165
- 115
- 133
- 112
- 126
- 86
- 121
- 115
- 111
- 129
- 2014
- 194
- 273
- 434
- 325
- 213
- 173
- 167
- 89
- 115
- 135
- 103
- 138
- 2013
- 282
- 162
- 290
- 263
- 227
- 259
- 277
- 303
- 187
- 294
- 222
- 224
- 2012
- 611
- 477
- 390
- 382
- 323
- 428
- 394
- 393
- 210
- 277
- 236
- 280
- 2011
- 580
- 687
- 439
- 561
- 572
- 565
- 367
- 393
- 370
- 995
- 466
- 511
- 2010
- 637
- 502
- 564
- 452
- 408
- 631
- 417
- 445
- 414
- 523
- 342
- 696
- 2009
- 979
- 380
- 465
- 318
- 282
- 291
- 550
- 455
- 421
- 339
- 386
- 502
- 2008
- 615
- 496
- 600
- 821
- 681
- 403
- 591
- 557
- 639
- 531
- 739
- 634
- 2007
- 593
- 629
- 573
- 744
- 555
- 661
- 662
- 530
- 709
- 935
- 582
- 641
- 2006
- 992
- 740
- 1865
- 865
- 789
- 1058
- 770
- 771
- 578
- 678
- 545
- 493
- 2005
- 927
- 676
- 950
- 654
- 678
- 437
- 766
- 1078
- 890
- 677
- 1065
- 1531
- 2004
- 1358
- 1534
- 1499
- 1153
- 1451
- 1031
- 1370
- 1314
- 1091
- 1174
- 1424
- 731
- 2003
- 505
- 405
- 296
- 500
- 421
- 890
- 1251
- 1942
- 1763
- 1806
- 1123
- 782
- 2002
- –
- –
- –
- –
- –
- –
- 314
- 835
- 684
- 381
- 454
- 313
Latest Posts
[SYSS-2026-067]: GDCM (Grassroots DICOM) - Stack-based Buffer Overflow (CWE-121)
Matthias Deeg via Fulldisclosure (Sep 26)
Advisory ID: SYSS-2026-067
Product: GDCM (Grassroots DICOM)
Manufacturer: GDCM Project
Affected Version(s): 3.3.0
Tested Version(s): 3.3.0
Vulnerability Type: Stack-based Buffer Overflow (CWE-121)
Risk Level: High
Solution Status: Open
Manufacturer Notification: 2026-07-24
Public Disclosure: 2026-09-23
CVE Reference: Not yet assigned...
usvg SVGZ decompression bomb in `Tree::from_data`
Khashayar Fereidani (Sep 26)
# usvg SVGZ decompression bomb in `Tree::from_data`
**Author:** Khashayar Fereidani
**Disclosure Date:** 2026-09-18
**Advisory:** https://fereidani.com/usvg-svgz-decompression-bomb-in-treefromdata
**Contact:** https://fereidani.com/contact
## Description
`Tree::from_data` in `crates/usvg/src/parser/mod.rs:102` detects the gzip magic
bytes at the start of the input and decompresses the data before parsing it:
```rust
//...
[0day-rubbish] Netsis NetOpenX REST 2.0.6.9 Unauthenticated SQL injection to xp_cmdshell SYSTEM command execution (9.8)
disclosure via Fulldisclosure (Sep 26)
0day Rubbish Research Team is publicly disclosing a vulnerability in Logo
Netsis NetOpenX REST 2.0.6.9 (also distributed as Netsis Nox REST), the REST
API gateway of the Netsis enterprise ERP suite.
Type: unauthenticated SQL injection in the OAuth 2.0 token endpoint leading to
operating-system command execution via SQL Server xp_cmdshell
(CWE-89, CWE-306, CWE-78). A single POST /api/v2/token carrying no client and
no user credentials supplies a...
[0day-rubbish] MultiTech Conduit AEP 6.3.6 Authenticated import_config filename command injection to root RCE (7.2)
disclosure via Fulldisclosure (Sep 26)
0day Rubbish Research Team is publicly disclosing a vulnerability in MultiTech
Conduit AEP (models mtcdt / mtcdtip / mtcdtiphp), IoT gateways running mLinux on
ARM 32-bit.
Type: authenticated OS command injection (CWE-78) through the uploaded filename
of the admin-only upload_config command. The management API is served by lighttpd
on TCP 8080 and proxied to the proprietary FastCGI daemon /usr/bin/rcell_api. The
import_config handler wraps the...
[0day-rubbish] Lightstreamer Server 7.4.8 Unauthenticated JMX jvmtiAgentLoad native code execution (8.1)
disclosure via Fulldisclosure (Sep 26)
0day Rubbish Research Team is publicly disclosing a vulnerability in
Lightstreamer Server 7.4.8 build 3506 (with JMS Extender 2.1.0).
Type: unauthenticated JMX inspection console allowing an anonymous caller to
invoke any MBean operation, reaching jvmtiAgentLoad on
com.sun.management:type=DiagnosticCommand to load and run a native agent
library inside the broker JVM (CWE-306, CWE-345, CWE-20, CWE-250, CWE-1188)
Scoring. This finding is...
[0day-rubbish] Lightstreamer Server 7.4.8 Shipped placeholder JMX/RMI credentials plus MLet remote class loading to root RCE (9.8)
disclosure via Fulldisclosure (Sep 26)
0day Rubbish Research Team is publicly disclosing a vulnerability in
Lightstreamer Server 7.4.8 build 3506 ENTERPRISE (with JMS Extender 2.1.0).
Type: a hard-coded placeholder credential shipped in the distribution
(user_changeme / password_changeme) authenticating a cleartext RMI management
connector on TCP 8888 bound to every interface; because the connector exposes
createMBean, an attacker registers javax.management.loading.MLet and calls...
[0day-rubbish] Lantronix SGX5150 9.13.0.0R7 Authenticated FsBrowseClean command injection to root RCE (7.2)
disclosure via Fulldisclosure (Sep 26)
0day Rubbish Research Team is publicly disclosing a vulnerability in Lantronix
SGX5150, firmware 9.13.0.0R7, an IT/OT device server.
Type: authenticated OS command injection (CWE-78) in the FsBrowseClean AJAX
handler (0x5eea0) of /bin/ltrx_evo. A per-character filter blocks & | < ; ! $
backslash backtick and > but permits single quote, hash and newline. The path
POST parameter is concatenated into /sbin/ltrx_usb_umount '%s'...
[0day-rubbish] FME Flow 2026.2 Zip-Slip arbitrary file write to code execution as LocalSystem (8.8)
disclosure via Fulldisclosure (Sep 26)
0day Rubbish Research Team is publicly disclosing a vulnerability in Safe
Software FME Flow 2026.2 build 26333.
Type: path-traversal write inside archive extraction (Zip-Slip) in
COM.safe.web.upload.StoreManager.extract(), shipped in
clients-webservicesutil-1.0.jar (CWE-22). The sink builds each destination path
from ZipArchiveEntry.getName() verbatim; commons-compress 1.26.2 does not
normalise "..", and the class's own canonical...
[0day-rubbish] Cambium cnMatrix EX3024F 6.2.1-r4 SSL CSR COMMON_NAME command injection to root RCE (7.2)
disclosure via Fulldisclosure (Sep 26)
0day Rubbish Research Team is publicly disclosing a vulnerability in the Cambium
cnMatrix EX3024F managed switch, firmware 6.2.1-r4.
Type: OS command injection (CWE-78, with CWE-20 bearing on it because
percent-decoding is the only processing applied; CWE-250/CWE-269 bear on
remediation priority). The COMMON_NAME form field submitted to
POST /iss/specific/ssl_digitalcert.html is extracted by HttpGetValuebyName,
percent-decoded by...
SCHUTZWERK-SA-2024-006: Stored Cross-Site Scripting via text fields in H5P module (h5p-nodejs-library) of Lumi Education
David Brown via Fulldisclosure (Sep 26)
A stored cross-site scripting (XSS) vulnerability has been identified in
the H5P module
h5p-nodejs-library by Lumi Education UG in versions prior to 9.3.3. The
vulnerability
allows users to inject malicious JavaScript code in text fields. This
code is then
executed in victims' browsers when viewing the affected H5P content.
Metadata
========
- Affected product: h5p-nodejs-library
- Affected version: All versions prior to 9.3.3
- Vendor:...
[NotCVE-2026-0015] Input Leap through 3.0.3 input-leapd Unauthenticated IPC Command Execution Allows Local Privilege Escalation to SYSTEM
advisories (Sep 26)
----------------------------------------------------------------------------
NotCVE Advisory — NotCVE-2026-0015
----------------------------------------------------------------------------
[-] Summary:
Missing authentication for a critical function in the input-leapd daemon of
Input Leap, the open-source keyboard and mouse sharing tool, allows a
local, low-privileged user on Windows to execute arbitrary commands as
NT AUTHORITY\SYSTEM by...
[NotCVE-2026-0014] Input Leap 3.0.3 Drag-and-Drop File Transfer Path Traversal Allows Arbitrary File Write Outside the Drop Directory
advisories (Sep 26)
----------------------------------------------------------------------------
NotCVE Advisory — NotCVE-2026-0014
----------------------------------------------------------------------------
[-] Summary:
Improper limitation of a pathname in the drag-and-drop file transfer
feature of Input Leap, the open-source keyboard and mouse sharing tool,
allows a connected peer to write a file outside the configured drop-target
directory. Writing into the...
Code Security Review tool
E. Kellinis (Sep 22)
Karma Pro is an open source code review tool that can assist code reviewers with a multitude of useful tools. Karma Pro
is a macOS source-code security scanner (AST base and Heuristics) that statically analyses projects in multiple
languages. It's backed by an ML classifier trained on real patches to catch subtle issues. Beyond scanning, it offers
interactive call graphs and data-flow diagrams, a bug tracker, a private research wiki,...
HP Advance / Output Central: unauthenticated SYSTEM RCE and two additional vulnerabilities (CVE-2026-89082/89083/89084)
Joe via Fulldisclosure (Sep 22)
HP Advance / HP Output Central
Unauthenticated SYSTEM RCE, authorization bypass, and arbitrary file
write/delete
CVE-2026-89082, CVE-2026-89083, CVE-2026-89084
================================================================
SUMMARY
================================================================
Vendor: HP Inc.
Product family named by HP: HP Advance
Products in HP's update table: HP AC Print & Scan; HP Output Central
Components:...
CFP No cON Name 2k26 - Palma, Mallorca - Spain
Jose Nicolas Castellano (Sep 22)
No cON Name 2026 - Palma, Mallorca - Balearic Islands
************************************
***** Call For Papers ******
************************************
https://www.noconname.org/call-for-papers/
Exact place not disclosed until a few weeks before due celebration.
* INTRODUCTIONfulldisclosure () seclists org
The organization has opened CFP proposals. No cON Name is the eldest
Hacking
and Security Conference in Span....
More Lists
Dozens of other network security lists are archived at SecLists.Org.
