*** EX RELS 03356 Release *** Total number of signatures: 6034 Description ================================================================== In this signature, we addressed the exploits/vulnerabilities and applications as below: Added 9 rule(s): --------------- 1133897 WEB Apache Http2 Null Pointer Dereference (CVE-2017-7659) 1134265 WEB Exponent CMS eaasController.php api Function SQL Injection Vulnerabilities -2.a (CVE-2017-7991) 1134271 FILE Microsoft Windows Graphics Component Information Disclosure -1 (CVE-2017-11816) 1134275 SMTP Exim BDAT command Remote Code Execution (CVE-2017-16943) 1134276 SMTP Exim BDAT command Denial of Service (CVE-2017-16944) 1134278 FILE Microsoft JET Database Engine Excel Component Buffer Overflow -1 (CVE-2017-8717) 1134287 WEB Huawei Home Gateway SOAP Command Execution 1134289 TELNET Polycom Shell HDX Series Traceroute Command Execution 1134291 FILE Microsoft Office EQNEDT32 Stack Buffer Overflow (CVE-2017-11882) Modified 12 rule(s): --------------- 1057129 WEB Sun Java System Web Server Digest Authorization Buffer Overflow -1 (BID-37896) 1057130 WEB Sun Java System Web Server Digest Authorization Buffer Overflow -2 (BID-37896) 1131239 WEB-CLIENT Microsoft Internet Explorer Memory Corruption Vulnerability -1 (CVE-2015-2425) 1132568 FILE Microsoft Graphics Component CVE-2016-0169 Information Disclosure (CVE-2016-0169) 1132676 FILE Microsoft Graphics Component CREATECOLORSPACEW Information Disclosure (CVE-2016-0168) 1132835 FILE Microsoft Office CVE-2016-3284 Memory Corruption (CVE-2016-3284) 1132875 FILE Microsoft Office Memory Corruption Vulnerability (CVE-2016-3316) 1132998 FILE Microsoft Windows Graphics Component CVE-2016-3301 Code Execution -1 (CVE-2016-3301) 1133045 FILE Microsoft Windows Graphics Component CVE-2016-3304 Code Execution -1 (CVE-2016-3304) 1133592 FILE Microsoft Graphics Device Interface CVE-2017-0038 Information Disclosure -1 (CVE-2017-0038) 1134026 WEB Trend Micro OfficeScan Proxy.php Command Injection -1 (CVE-2017-11394) 1134245 DNS Microsoft Windows DNSAPI NSEC3 Heap-based Buffer Overflow -1 (CVE-2017-11779) Deleted 0 rule(s): ---------------