*** EX RELS 03315 Release *** Total number of signatures: 6012 Description ================================================================== In this signature, we addressed the exploits/vulnerabilities and applications as below: Added 3 rule(s): --------------- 1133484 EXPLOIT Aerospike Database Server as_sindex__simatch_list_by_set_binid Stack Buffer Overflow (CVE-2016-9054) 1133489 FTP Java and Python FTP Injection -1 1133490 FTP Java and Python FTP Injection -2 Modified 8 rule(s): --------------- 1055505 WEB PHP htmlspecialchars htmlentities Buffer Overflow (BID-51860) 1057832 WEB PHP Arbitrary Code Injection -7 1058551 WEB-CLIENT Google Chrome XSSAuditor Filter Security Policy Bypass -1 (BID-65066) 1059684 EXPLOIT Bitcoin/LiteCoin/Dogecoin Mining Activity -1 1130245 WEB NetBSD tnftp fetch.c fetch_url Command Execution -2 (CVE-2014-8517) 1130527 SMB Microsoft DLL Planting Remote Code Exectution Vulnerability -1 (CVE-2015-0096) 1133085 WEB-CLIENT Microsoft Internet Explorer Internet Messaging API Information Disclosure -1 (CVE-2016-3298) 1133189 EXPLOIT Bitcoin/LiteCoin/Dogecoin Mining Activity -2 Deleted 30 rule(s): --------------- 1056432 EXPLOIT Adobe Photoshop TIFF Parsing Heap Buffer Overflow -2 (old rule) 1056449 EXPLOIT Oracle Business Transaction Management FlashTunnelService Arbitrary File Deletion -2 (old rule) 1056452 WEB-ACTIVEX HP Application Lifecycle Management ActiveX Control Insecure Method Exposure (OSVDB-85152) (old rule) 1056457 WEB-ACTIVEX HP Application Lifecycle Management ActiveX Control Arbitrary File Overwrite (OSVDB-85059) (old rule) 1056465 EXPLOIT Oracle Java java.util.concurrent.ConcurrentHashMap Memory Corruption (CVE-2013-2426) (old rule) 1056469 EXPLOIT QNX QCONN Remote Command Execution Vurnerability (old rule) 1056473 WEB Atmail Email Server Appliance 6.4 Stored XSS (old rule) 1056489 WEB SQL injection attempt -11 (old rule) 1056551 EXPLOIT Oracle Fusion Middleware Outside In Excel File Parsing Integer Overflow (old rule) 1056592 WEB-CLIENT Generic Javascript Obfuscation -4 (old rule) 1056595 SCADA Cogent Datahub Remote Unicode Buffer Overflow -1 (CVE-2011-3493) (old rule) 1056604 EXPLOIT Microsoft .NET Framework Insecure Library Loading -1 (CVE-2012-2519) (old rule) 1056606 EXPLOIT Microsoft .NET Framework Insecure Library Loading -2 (CVE-2012-2519) (old rule) 1056614 WEB Cisco Linksys E1500/E2500 apply.cgi Remote Command Injection -1 (BID-57760) (old rule) 1056634 WEB-CLIENT Microsoft Internet Explorer SelectAll Use-after-free -2 (CVE-2012-0171) (old rule) 1056652 WEB Narcissus Image Configuration Passthru Vulnerability (BID-87410) (old rule) 1056797 WEB Splunk 5.0 Custom App Remote Code Execution (old rule) 1056799 WEB Nagios XI Network Monitor Graph Explorer Component Command Injection (old rule) 1056802 SSH Symantec Messaging Gateway Default SSH Password -1 (CVE-2012-3579) (old rule) 1056807 WEB Microsoft SharePoint Username Sanitization Cross-site Scripting (CVE-2012-1861) (old rule) 1056828 DB Oracle MySQL DELETE Heap Buffer Overflow -2 (CVE-2012-5612) (old rule) 1056864 WEB HP SiteScope SOAP Call APISiteScopeImpl Multiple Information Disclosures -1 (old rule) 1056865 WEB HP SiteScope SOAP Call APISiteScopeImpl Multiple Information Disclosures -2 (old rule) 1056869 WEB Rhino Software Serv-U Web Client HTTP Request Remote Buffer Overflow (old rule) 1056871 EXPLOIT Nullsoft Winamp MIDI Timestamp Stack Buffer Overflow -2 (old rule) 1056873 WEB HP SiteScope loadFileContent SOAP Request Information Disclosure (old rule) 1056878 WEB HP SiteScope Multiple Directory Traversal Vulnerabilities -1 (old rule) 1056886 DB HP Intelligent Management Center Database Credentials Information Disclosure (BID-40298) (old rule) 1056891 FTP RhinoSoft Serv-U FTP Server rnto Command Directory Traversal (old rule) 1056903 DB IBM DB2 Universal Database receiveDASMessage Buffer Overflow -2 (old rule)