*** EX RELS 03393 Release *** Total number of signatures: 6011 Description ================================================================== In this signature, we addressed the exploits/vulnerabilities and applications as below: Added 12 rule(s): --------------- 1134917 WEB Easy FIle Sharing WebServer UserID Remote Buffer Overflow (CVE-2018-9059) 1134932 FILE Adobe Acrobat XPS JPEG APP13 Tag Out-of-Bounds Read (CVE-2018-5029) 1134938 WEB ManageEngine ecovery Manager Plus Persistent Cross-Site Scripting (CVE-2018-9163) 1134939 SCADA Multiple Schneider Electric Products CVE-2018-8840 Stack Based Buffer Overflow Vulnerability 1134941 WEB Trend Micro Smart Protection Server Auth Command Injection Authentication Bypass 1134944 FILE Adobe Acrobat XPS Font Parsing Out-of-Bounds Read (CVE-2018-5014) 1134945 FILE Adobe Acrobat and Reader Out of Bounds Read Multiple Remote Code Execution Vulnerabilities (CVE-2018-4885) 1134946 FILE Adobe Acrobat and Reader Multiple Remote Code Execution Vulnerabilities (CVE-2018-4888) 1134947 FILE Adobe Acrobat and Reader Multiple Heap Buffer Overflow Vulnerabilities (CVE-2018-4890) 1134948 EXPLOIT HPE Intelligent Management Center PLAT tftpserver fread Stack Buffer Overflow (CVE-2018-7074) 1134951 FILE Foxit Reader JavaScript mailForm Use After Free (CVE-2018-3924) 1161187 MEDIA Dailymotion media via SSL -1 Modified 5 rule(s): --------------- 1055434 WEB Apache Struts 2 OGNL Script Injection -3 1055457 WEB Apache Struts 2 OGNL Script Injection -5 1064068 FILE Sugarsync login via SSL -1 1067062 WEB eBay login via SSL -1 1067173 FILE Sugarsync login via SSL -2 Deleted 33 rule(s): --------------- 1057740 WEB-ACTIVEX Oracle WebCenter Content CheckOutAndOpen.dll ActiveX Remote Code Execution -1 (CVE-2013-1559) (old rule) 1057760 EXPLOIT EMC AlphaStor Library Control Program Multiple Buffer Overflows (CVE-2013-0946) (old rule) 1057761 WEB Novell ZENworks Mobile Management MDM.php Code Execution -1 (CVE-2013-1081) (old rule) 1057762 WEB MiniUPnPd 1.0 Stack Buffer Overflow Remote Code Execution (CVE-2013-0230) (old rule) 1057763 EXPLOIT Oracle Java java.sql.DriverManager Sandbox Bypass (CVE-2013-1488) (old rule) 1057765 DB Oracle MySQL Server InnoDB Memcached Plugin Resource Exhaustion -1 (CVE-2013-1570) (old rule) 1057768 DB Oracle MySQL Server InnoDB Memcached Plugin Resource Exhaustion -2 (CVE-2013-1570) (old rule) 1057769 DB Oracle MySQL Server InnoDB Memcached Plugin Resource Exhaustion -3 (CVE-2013-1570) (old rule) 1057775 WEB Novell ZENworks Configuration Management Remote Execution -3 (CVE-2013-1080) (old rule) 1057776 WEB Novell ZENworks Mobile Management MDM.php Code Execution -2 (CVE-2013-1081) (old rule) 1057777 FILE ClamAV Encrypted PDF File Handling Memory Access Error (CVE-2013-2021) (old rule) 1057779 WEB Nginx Chunked Transfer Parsing Denial of Service (CVE-2013-2070) (old rule) 1057780 WEB-CLIENT Microsoft Internet Explorer CTreeNode Memory Corruption Vulnerability (CVE-2013-3142) (old rule) 1057796 WEB Apache Struts URL and Anchor tag includeParams OGNL Command Execution -1 (CVE-2013-2115) (old rule) 1057802 FILE Adobe Reader and Acrobat RLE Encoded BMP File Integer Overflow -1 (CVE-2013-2729) (old rule) 1057803 EXPLOIT Linux Kernel iscsi_add_notunderstood_response Heap Buffer Overflow (CVE-2013-2850) (old rule) 1057805 FILE IBM Notes PNG Image Parsing Integer Overflow -1 (CVE-2013-2977) (old rule) 1057806 FILE IBM Notes PNG Image Parsing Integer Overflow -2 (CVE-2013-2977) (old rule) 1057807 WEB phpMyAdmin preg_replace Function Code Injection (CVE-2013-3238) (old rule) 1057813 EXPLOIT FreeBSD NFS Server READDIR Request Memory Corruption (CVE-2013-3266) (old rule) 1057834 VULN 3S Smart Software Solutions CoDeSys Gateway Server Directory Traversal -2 (CVE-2012-4705) (old rule) 1057835 VULN 3S Smart Software Solutions CoDeSys Gateway Server Memory Access Error -1 (CVE-2012-4704) (old rule) 1057836 VULN 3S Smart Software Solutions CoDeSys Gateway Server Memory Access Error -2 (CVE-2012-4704) (old rule) 1057837 VULN 3S Smart Software Solutions CoDeSys Gateway Server Memory Access Error -3 (CVE-2012-4704) (old rule) 1057845 EXPLOIT Microsoft Windows Briefcase Integer Overflow Vulnerability -2 (CVE-2012-1528) (old rule) 1057854 EXPLOIT HP LeftHand Virtual SAN Appliance hydra Diag Processing Buffer Overflow -2 (CVE-2012-3283) (old rule) 1057855 EXPLOIT Oracle Java Gmbal Package Sandbox Breach -1 (CVE-2012-5076) (old rule) 1058198 WEB HP ProCurve Manager SNAC UpdateDomainControllerServlet File Upload -2 (CVE-2013-4811) (old rule) 1058216 EXPLOIT Adobe Illustrator APSB12-10 Multiple Memory Corruption Vulnerability (CVE-2012-0780) (old rule) 1058390 WEB HP Operations Agent Performance Component Last Chunk Buffer Overflow -1 (CVE-2012-2019) (old rule) 1130381 WEB-CLIENT Microsoft Internet Explorer MSXML Object Buffer Overflow -5 (CVE-2012-1889) (old rule) 1134100 WEB Symantec Messaging Gateway Directory Traversal -1 (CVE-2012-4347) (old rule) 1134700 EXPLOIT Mikrotik RouterOS Denial of Service (CVE-2012-6050) (old rule)