*** NK8 RELS 3361 Release *** Total number of signatures: 3237 Description ================================================================== In this signature, we addressed the exploits/vulnerabilities and applications as below: Added 9 rule(s): --------------- 1134349 WEB-CLIENT Multiple CPU Meltdown/Spectre Attacks Detection -1 1134352 WEB-CLIENT Microsoft Edge Chakra OP_Memset Type Confusion -1 (CVE-2017-11873) 1134354 WEB D-LINK DNS-320L ShareCenter mydlinkBRionyg Backdoor 1134356 FILE Adobe Flash Player Memory Corruption (CVE-2018-4871) 1134357 WEB-CLIENT Multiple CPU Meltdown/Spectre Attacks Detection -2 1134359 WEB Oracle WebLogic wls-wsat Deserialization -1 (CVE-2017-10271) 1134360 DNS Dnsmasq Lack of Free Denial of Service -1.3 (CVE-2017-14495) 1134361 WEB Oracle WebLogic wls-wsat Deserialization -2 (CVE-2017-10271) 1160795 GAME QQ/QQFO access via TCP -5 Modified 4 rule(s): --------------- 1055106 WEB PHP Arbitrary Code Injection -1.b 1130667 WEB-CLIENT Generic Javascript Obfuscation -25 1133370 WEB PHP Arbitrary Code Injection -1.u 1134321 WEB HTTP Insecure Deserialization Remote Code Execution -1 Deleted 7 rule(s): --------------- 1130548 EXPLOIT Nvidia Mental Ray Satellite Service Arbitrary DLL Injection (old rule) 1130549 MALWARE Gh0st Outbound Activity (old rule) 1130550 WEB-CLIENT Firefox Proxy Prototype Privileged Javascript Injection (CVE-2014-8636) (old rule) 1130551 WEB Belkin Play N750 login.cgi Buffer Overflow -1 (CVE-2014-1635) (old rule) 1130552 WEB Belkin Play N750 login.cgi Buffer Overflow -2 (CVE-2014-1635) (old rule) 1130553 WEB TWiki Debugenableplugins Remote Code Execution (CVE-2014-7236) (old rule) 1130703 WEB D-Link/TRENDnet NCC Service Command Injection -2 (CVE-2015-1187) (old rule)