*** NK8 RELS 3348 Release *** Total number of signatures: 3218 Description ================================================================== In this signature, we addressed the exploits/vulnerabilities and applications as below: Added 10 rule(s): --------------- 1134058 WEB-CLIENT Microsoft Edge Chakra arguments Off By One -1 (CVE-2017-8671) 1134061 FILE Adobe Flash Player APSB17-04 Multiple Unspecified Memory Corruption (CVE-2017-2988) 1134067 DNS Dnsmasq 2-byte Heap-Based Overflow (CVE-2017-14491) 1134068 DHCP Dnsmasq Heap-Based Overflow (CVE-2017-14493) 1134069 DNS Dnsmasq Integer Underflow (CVE-2017-14496) 1134070 ICMP Dnsmasq Heap-Based Overflow (CVE-2017-14492) 1134071 DNS Dnsmasq Lack of Free Denial of Service (CVE-2017-14495) 1134072 DHCP Dnsmasq IPv6 Information Leak (CVE-2017-14494) 1134073 DNS Dnsmasq Overly Large DNS Query Denial of Service (CVE-2017-13704) 1134091 FILE Microsoft Office OOXML Memory Corruption (CVE-2017-11826) Modified 6 rule(s): --------------- 1055396 WEB Cross-site Scripting -9 1120193 WEB URI Handler Buffer Overflow - POST -1 1132274 FTP ProFTPD mod_copy Unauthenticated Remote File Copying -2 (CVE-2015-3306) 1133407 WEB Brute Force Login -1.1021 1133952 WEB PHP gdImageCreateFromGifCtx Out of Bounds Read -1 (CVE-2017-7890) 1134057 WEB Netgear ReadyNAS Surveillance Unauthenticated Remote Command Execution Deleted 11 rule(s): --------------- 1059811 WEB-CLIENT SOAPUI Remote Code Execution -1 (CVE-2014-1202) (old rule) 1059812 WEB-CLIENT SOAPUI Remote Code Execution -2 (CVE-2014-1202) (old rule) 1059816 SSL OpenSSL Anonymous TLS_ECDH_Anon_WITH_3DES_EDE_CBC_SHA Denial of Service -1.1 (CVE-2014-3470) (old rule) 1059817 SSL OpenSSL Anonymous TLS_ECDH_Anon_WITH_AES_128_CBC_SHA Denial of Service -1.1 (CVE-2014-3470) (old rule) 1059840 WEB Oracle Business Intelligence Mobile App Designer Information Disclosure (CVE-2014-4249) (old rule) 1059851 WEB-CLIENT Google Chrome locationAttributeSetter Use After Free -2 (CVE-2014-1713) (old rule) 1059934 RPC Drupal Core XML-RPC Endpoint xmlrpc.php Internal Entity Expansion Denial of Service -1 (CVE-2014-5265) (old rule) 1059942 FTP Wing FTP Server Authenticated Command Execution (old rule) 1059992 FILE Adobe Reader and Acrobat Sandbox Policy Bypass -1 (CVE-2014-0521) (old rule) 1130051 EXPLOIT HP Network Node Manager I PMD Buffer Overflow -1 (CVE-2014-2624) (old rule) 1130052 EXPLOIT HP Network Node Manager I PMD Buffer Overflow -2 (CVE-2014-2624) (old rule)