🦜 Full Disclosure
@seclists.org.fulldisclosure@rss-parrot.net
I'm an automated parrot! I relay a website's RSS feed to the Fediverse. Every time a new post appears in the feed, I toot about it. Follow me to get all new posts in your Mastodon timeline!
Brought to you by the RSS Parrot.
---
A public, vendor-neutral forum for detailed discussion of vulnerabilities and exploitation techniques, as well as tools, papers, news, and events of interest to the community. The relaxed atmosphere of this quirky list provides some comic relief and certain industry gossip. More importantly, fresh vulnerabilities sometimes hit this list many hours or days before they pass through the Bugtraq moderation queue.
Your feed and you don't want it here? Just
e-mail the birb.
Multiple Security Misconfigurations and Customer Enumeration Exposure in Convercent Whistleblowing Platform (EQS Group)
https://seclists.org/fulldisclosure/2025/Dec/4
Published: December 5, 2025 18:02
Posted by Yuffie Kisaragi via Fulldisclosure on Dec 05Advisory ID: CONVERCENT-2025-001
Title: Multiple Security Misconfigurations and Customer Enumeration Exposure in
Convercent Whistleblowing Platform (EQS Group)
Date: 2025-12-04
Vendor: EQS Group…
8 vulnerabilities in AudioCodes Fax/IVR Appliance
https://seclists.org/fulldisclosure/2025/Dec/3
Published: December 2, 2025 05:29
Posted by Pierre Kim on Dec 01## Advisory Information
Title: 8 vulnerabilities in AudioCodes Fax/IVR Appliance
Advisory URL: https://pierrekim.github.io/advisories/2025-audiocodes-fax-ivr.txt
Blog URL:…
2 vulnerabilities in Egovframe
https://seclists.org/fulldisclosure/2025/Dec/2
Published: December 2, 2025 05:29
Posted by Pierre Kim on Dec 01## Advisory Information
Title: 2 vulnerabilities in Egovframe
Advisory URL: https://pierrekim.github.io/advisories/2025-egovframe.txt
Blog URL: https://pierrekim.github.io/blog/2025-11-20-egovframe-2-vulnerabilities.html
Date…
[REVIVE-SA-2025-005] Revive Adserver Vulnerability
https://seclists.org/fulldisclosure/2025/Dec/1
Published: December 2, 2025 05:28
Posted by Matteo Beccati on Dec 01========================================================================
Revive Adserver Security Advisory REVIVE-SA-2025-005
------------------------------------------------------------------------…
Missing Critical Security Headers in Legality WHISTLEBLOWING
https://seclists.org/fulldisclosure/2025/Dec/0
Published: December 2, 2025 05:27
Posted by Aerith Gainsborough via Fulldisclosure on Dec 01Advisory ID: LEGALITYWHISTLEBLOWING-2025-001
Title: Missing Critical Security Headers in Legality WHISTLEBLOWING
Date: 2025-11-29
Vendor: DigitalPA (segnalazioni.net)
Severity: High
CVSS v3.1 Base…
[REVIVE-SA-2025-004] Revive Adserver Vulnerabilities
https://seclists.org/fulldisclosure/2025/Nov/21
Published: November 19, 2025 20:03
Posted by Matteo Beccati on Nov 19========================================================================
Revive Adserver Security Advisory REVIVE-SA-2025-004
------------------------------------------------------------------------…
[REVIVE-SA-2025-003] Revive Adserver Vulnerabilities
https://seclists.org/fulldisclosure/2025/Nov/20
Published: November 19, 2025 20:03
Posted by Matteo Beccati on Nov 19========================================================================
Revive Adserver Security Advisory REVIVE-SA-2025-003
------------------------------------------------------------------------…
[SYSS-2025-059]: Dell computer UEFI boot protection bypass
https://seclists.org/fulldisclosure/2025/Nov/19
Published: November 19, 2025 20:03
Posted by Micha Borrmann via Fulldisclosure on Nov 19Advisory ID: SYSS-2025-059
Product: Dell computer
Manufacturer: Dell
Affected Version(s): Probably all Dell computers
Tested Version(s): …
Re: [FD] : "Glass Cage" – Zero-Click iMessage → Persistent iOS Compromise + Bricking (CVE-2025-24085 / 24201, CNVD-2025-07885)
https://seclists.org/fulldisclosure/2025/Nov/18
Published: November 14, 2025 02:03
Posted by Patrick via Fulldisclosure on Nov 13Hello Jan,
You are completely right and it’s something I warned about early, which is abuse of AI-generated sensationalized
headline and fake PoC-s, for fame.
I urge the Full Disclosure staff to look into…
APPLE-SA-11-13-2025-1 Compressor 4.11.1
https://seclists.org/fulldisclosure/2025/Nov/17
Published: November 14, 2025 02:02
Posted by Apple Product Security via Fulldisclosure on Nov 13APPLE-SA-11-13-2025-1 Compressor 4.11.1
Compressor 4.11.1 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/125693.
Apple…
Re: 83 vulnerabilities in Vasion Print / PrinterLogic
https://seclists.org/fulldisclosure/2025/Nov/16
Published: November 14, 2025 02:02
Posted by Pierre Kim on Nov 13No message preview for long message of 668188 bytes.