Apple Security Advisory 2017-03-27-7 - macOS Server 5.3 is now available and addresses denial of service and user enumeration vulnerabilities.
658872beabc18d8ce86f77b4f603d0f654af625711493b7b0c96aeb309af853a
Apple Security Advisory 2017-03-27-4 - iOS 10.3 is now available and addresses code execution, information disclosure, denial of service, and various other vulnerabilities.
22e0875f79f9c63aedffc618f68fec412607d64473f27fd6f5dbacb83463532e
pfsense version 2.3.2 suffers from a remote code execution vulnerability.
cdc9477114db9f75ccf0e32482329e27abeb984f900df0dba8af56cb83f111bb
Apple Security Advisory 2017-03-27-3 - macOS Sierra 10.12.4, Security Update 2017-001 El Capitan, and Security Update 2017-001 Yosemite are now available and address multiple vulnerabilities.
54a3d5f1eafce35231db5001f3683c3b0fd1ddc198a138e24dfe71082667f5b2
Apple Security Advisory 2017-03-27-5 - watchOS 3.2 is now available and addresses code execution, buffer overflow, and various other vulnerabilities.
40689b2a1e784e8eee7d60608dc73fdedca02ff0fbc1cf82d244f831d06e8eb7
NetComm NB16WV-02 suffers from a persistent cross site scripting vulnerability.
7528366296e53825ce8b1f5f682ff65037bbfe4609499705987eadc098835cda
This Metasploit module exploits two security issues in Github Enterprise, version 2.8.0 - 2.8.6. The first is that the session management uses a hard-coded secret value, which can be abused to sign a serialized malicious Ruby object. The second problem is due to the use of unsafe deserialization, which allows the malicious Ruby object to be loaded, and results in arbitrary remote code execution. This exploit was tested against version 2.8.0.
33f3404a6f4b774f58398937b9ab21c5dca1aec64058a30c79123e17a7208e17
Samba suffers from a symlink race that permits opening files outside of the share directory.
cbefcff5a7cc202c2a305ae0688d0de66a0ef4a9774c1d54a3d82ebf5097e489
inoERP version 0.6.1 suffers from cross site request forgery, cross site scripting, session fixation, and remote SQL injection vulnerabilities.
0dbae274c6ec3d066433df5925e8e6e06e3eb8799408ce2eb8814242b997affc
Microsoft IIS version 6.0 suffers from a WebDAV ScStoragePathFromUrl buffer overflow vulnerability.
6863dfccb5afdbb2b68e4e352d69d7475a42a362ead4a48025220cdbd740e6d3
Disk Sorter Server version 9.5.12 suffers from a buffer overflow vulnerability.
70c8f1cd0b11a6132069d46e2ac4bf4a996a12018c80ea2c6aeb432b76439055
Apple Security Advisory 2017-03-27-1 - Pages 6.1, Numbers 4.1, and Keynote 7.1 for Mac; Pages 3.1, Numbers 3.1, and Keynote 3.1 for iOS are now available and address a weak cryptography issue.
745de5dc99e800c0cbfca86a9ccf2b5cb8002743aa72c1b9242d277e90c4b038
pfsense versions 2.3.2 suffers from a cross site request forgery vulnerability.
fcf681ece2f83f4d6b675ac5d70d922fa1b6d25f6617555f840ef0872ca94996
Transcend with firmware version 1.8 suffers from cross site request forgery, predictable resource, and brute force vulnerabilities.
1a4032fa7dcf5d2be45c3dbe7dec9600646e994b5861142be52724d063667022
DzSoft PHP Editor version 4.2.7 suffers from a file enumeration vulnerability.
84b6c7d82476be2e2f6038e8544c4f4179460cae434520c1b313a71269ce8dcc
BluAdmin Riyan version 1 suffers from a remote SQL injection vulnerability.
624025d7e3367c64e072dc8d1f94b60e816d9ab7adb6f9f767d891f1ce3dd3d2
pfsense version 2.3.2 suffers from a cross site scripting vulnerability.
5265038acc564a91f8f3566357f7cc4c9a1e67a7ebda312a77ce2ab48ec2ffdd
Apple Security Advisory 2017-03-27-2 - Safari 10.1 is now available and addresses multiple vulnerabilities.
d26e9aff6bf7e7434e91a8b6c96617fdf3c0d54254c77601ccf9e657673e1334