*** EX RELS 03328 Release *** Total number of signatures: 6020 Description ================================================================== In this signature, we addressed the exploits/vulnerabilities and applications as below: Added 6 rule(s): --------------- 1133724 WEB-CLIENT Javascript Obfuscation in Exploit Kits - 93 (Ransomware Attack Vector) 1133725 WEB-CLIENT Javascript Obfuscation in Exploit Kits - 94 (Ransomware Attack Vector) 1133727 WEB URI Handler Buffer Overflow - GET -6 1133729 WEB PHPMailer Remote Code Execution -1.2 (CVE-2016-10045) 1133735 SMB Samba is_known_pipename Arbitrary Module Load Remote Code Execution (CVE-2017-7494) 1160399 MAIL Gmail access via UDP -1 Modified 6 rule(s): --------------- 1055106 WEB PHP Arbitrary Code Injection -1.a 1056217 FILE Apple QuickTime QTVR QTVRStringAtom Parsing Buffer Overflow (CVE-2012-0667) 1065879 WEB Akamai.net access via SSL -1 1069028 SOCIAL Google+ access via UDP -2 1133385 WEB PHPMailer Remote Code Execution -1.1 (CVE-2016-10045) 1133644 WEB Disk Sorter Enterprise GET Buffer Overflow Deleted 25 rule(s): --------------- 1058061 WEB-CLIENT Microsoft Windows Theme File Code Execution (CVE-2013-0810) (old rule) 1058108 WEB Microsoft .NET Framework Entity Expansion Vulnerability (CVE-2013-3860) (old rule) 1058175 WEB HP Intelligent Management Center BIMS UploadServlet Directory Traversal -1 (CVE-2013-4822) (old rule) 1058184 WEB Windows Powershell Remote Command Injection -2 (CVE-2013-3763) (old rule) 1058191 SMTP Microsoft Outlook MIME Email Message Parsing Remote Code Execution -1 (CVE-2013-3870) (old rule) 1058196 WEB-ACTIVEX HP LoadRunner WriteFileString Directory Traversal (CVE-2013-4798) (old rule) 1058197 SSL HP LoadRunner XDR Data Handling Heap Buffer Overflow (CVE-2013-4799) (old rule) 1058206 EXPLOIT Oracle Java java.awt.image.ByteComponentRaster Memory Corruption (CVE-2013-2473) (old rule) 1058215 FILE Microsoft Windows and Office TIFF Handling GDI Memory Corruption -4 (CVE-2013-3906) (old rule) 1058287 EXPLOIT Oracle Java sun.awt.image.ImagingLib.lookupByteBI Buffer Overflow (CVE-2013-2463) (old rule) 1058307 WEB Apache Struts Wildcard Matching OGNL Code Execution -4 (CVE-2013-2134) (old rule) 1058314 FILE Apple Quicktime 7 Invalid Atom Length Buffer Overflow -2 (CVE-2013-1017) (old rule) 1058334 WEB Cisco Prime Data Center Network Manager Arbitrary File Upload -1 (CVE-2013-5486) (old rule) 1058430 WEB vTiger CRM SOAP AddEmailAttachment Arbitrary File Upload (CVE-2013-3214) (old rule) 1058936 FILE Microsoft Windows and Office TIFF Handling GDI Memory Corruption -2 (CVE-2013-3906) (old rule) 1058937 FILE Microsoft Windows and Office TIFF Handling GDI Memory Corruption -3 (CVE-2013-3906) (old rule) 1059104 WEB Apache Camel XSLT Component Java Code Execution (CVE-2014-0003) (old rule) 1059139 WEB McAfee ePolicy Orchestrator XML External Entity -1 (CVE-2014-2205) (old rule) 1059142 WEB PHP Fileinfo Call Stack Exhaustion Denial of Service (CVE-2014-1943) (old rule) 1059144 SSL Apple Products SSLVerifySignedServerKeyExchange Security Feature Bypass (CVE-2014-1266) (old rule) 1059147 FILE Poster Software PUBLISH-iT PUI File Processing Buffer Overflow -1 (CVE-2014-0980) (old rule) 1059148 FILE Poster Software PUBLISH-iT PUI File Processing Buffer Overflow -2 (CVE-2014-0980) (old rule) 1059648 WEB VMware vCenter Chargeback Manager ImageUploadServlet Arbitrary File Upload -2 (CVE-2013-3520) (old rule) 1059814 DB Oracle Database Server LpxFSMSax QName Stack Buffer Overflow (CVE-2013-3751) (old rule) 1130562 SSL HP LoadRunner magentproc.exe Stack Buffer Overflow -3 (CVE-2013-4800) (old rule)