*** EX RELS 03411 Release *** Total number of signatures: 6008 Description ================================================================== In this signature, we addressed the exploits/vulnerabilities and applications as below: Added 6 rule(s): --------------- 1135268 MALWARE Shamoon HTTP Activity -4 1135269 FILE Foxit Reader Annotation delay Use After Free (CVE-2018-17682) 1135272 EXPLOIT Erlang Port Mapper Daemon Cookie RCE 1135275 WEB-CLIENT Microsoft Edge Chakra JIT NewScObjectNoCtor Array Type Confusion -1 (CVE-2018-0838) 1135277 FILE OMRON CX-One CX-Position cdmapi32 Stack-based Buffer Overflow -1 (CVE-2018-18993) 1135280 WEB phpMyAdmin Navigation-Tree Stored Cross-Site Scripting 1.1 (CVE-2018-19970) Modified 2 rule(s): --------------- 1134391 MISC Meterpreter Windows Payload Delivery -1.1 1134451 MISC Meterpreter Windows Payload Delivery -4 Deleted 45 rule(s): --------------- 1057983 WEB Apache Struts Wildcard Matching OGNL Code Execution -3 (CVE-2013-2134) (old rule) 1057992 EXPLOIT Oracle Java Runtime Environment storeImageArray Buffer Overflow -1 (CVE-2013-2465) (old rule) 1057993 WEB HP SiteScope SOAP Call runOMAgentCommand Command Injection (CVE-2013-2367) (old rule) 1057994 WEB Microsoft SharePoint Unassigned Workflow Denial of Service -1 (CVE-2013-0081) (old rule) 1058004 WEB-CLIENT Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2013-3209) (old rule) 1058008 WEB-CLIENT Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2013-3845) (old rule) 1058016 WEB Sophos Web Protection Appliance sblistpack Arbitrary Command Execution (CVE-2013-4983) (old rule) 1058017 WEB HP System Management Homepage iprange Stack Buffer Overflow -1 (CVE-2013-2362) (old rule) 1058026 NETBIOS Samba smbd read_nttrans_ea_list Infinite Allocation Loop Denial of Service (CVE-2013-4124) (old rule) 1058027 WEB PHP SdnToJewish Function Integer Overflow (CVE-2013-4635) (old rule) 1058029 WEB HP ProCurve Manager SNAC UpdateDomainControllerServlet File Upload -1 (CVE-2013-4811) (old rule) 1058030 WEB HP SiteScope issueSiebelCmd SOAP Request Code Execution (CVE-2013-4835) (old rule) 1058036 DNS ISC BIND RDATA Handling Assertion Failure Denial of Service (CVE-2013-4854) (old rule) 1058051 EXPLOIT Nodejs js-yaml load() Code Execution (CVE-2013-4660) (old rule) 1058056 WEB Linksys Devices pingstr Remote Command Injection (CVE-2013-3568) (old rule) 1058089 EXPLOIT Linux Kernel SCTP Duplicate Cookie Handling Denial of Service -1 (CVE-2013-2206) (old rule) 1058098 WEB-ACTIVEX HP LoadRunner micWebAjax.dll ActiveX Control Stack Buffer Overflow -1 (CVE-2013-2368) (old rule) 1058099 WEB HP System Management Homepage iprange Stack Buffer Overflow -2 (CVE-2013-2362) (old rule) 1058102 WEB-ACTIVEX HP LoadRunner micWebAjax.dll ActiveX Control Stack Buffer Overflow -2 (CVE-2013-2368) (old rule) 1058104 WEB-CLIENT Microsoft Internet Explorer onpropertychange Use After Free (CVE-2013-3897) (old rule) 1058107 FILE Microsoft Word Memory Corruption Vulnerability (CVE-2013-3891) (old rule) 1058111 WEB-CLIENT Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2013-3886) (old rule) 1058112 WEB-CLIENT Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2013-3885) (old rule) 1058116 SSL HP LoadRunner magentproc.exe Stack Buffer Overflow -1 (CVE-2013-4800) (old rule) 1058190 SIP Digium Asterisk SIP Invalid SDP Media Descriptions Denial of Service (CVE-2013-5642) (old rule) 1058205 EXPLOIT Oracle Java sun.awt.image.ImagingLib.lookupByteBI Memory Corruption (CVE-2013-2470) (old rule) 1058208 EXPLOIT Oracle Java Final Field Overwrite (CVE-2013-2423) (old rule) 1058210 WEB Symantec Web Gateway Cross Site Request Forgery Vulnerability (CVE-2013-4671) (old rule) 1058219 EXPLOIT Microsoft Windows DirectShow Memory Corruption (CVE-2013-3174) (old rule) 1058235 FILE Microsoft Word Stack Buffer Overwrite Vulnerability (CVE-2013-1324) (old rule) 1058236 FILE Microsoft Word Stack Buffer Overwrite Vulnerability (CVE-2013-1325) (old rule) 1058237 WEB-CLIENT Microsoft Internet Explorer runtimeStyle Handling Memory Corruption (CVE-2013-3882) (old rule) 1058238 EXPLOIT Microsoft Graphics Device Interface Integer Overflow Vulnerability (CVE-2013-3940) (old rule) 1058241 WEB-ACTIVEX Microsoft InformationCardSigninHelper ActiveX Remote Code Execution -1 (CVE-2013-3918) (old rule) 1058308 WEB NETGEAR ReadyNAS Perl Code Evaluation (CVE-2013-2751) (old rule) 1058309 WEB Wordpress W3 Total Cache PHP Code Execution -1 (CVE-2013-2010) (old rule) 1058315 EXPLOIT Corel PaintShop Pro Insecure Library Loading -1 (CVE-2013-0733) (old rule) 1058323 WEB-CLIENT Google Chrome NotifyInstanceWasDeleted Use After Free (CVE-2013-29121) (old rule) 1058335 WEB SonicWALL Multiple Products Authentication Bypass -2 (CVE-2013-1359) (old rule) 1058348 WEB-CLIENT Microsoft Scripting Runtime Object Library Use After Free (CVE-2013-5056) (old rule) 1058351 WEB Adobe ColdFusion 9 Administrative Login Bypass (CVE-2013-0632) (old rule) 1058352 WEB HP LoadRunner EmulationAdmin Web Service Directory Traversal -1 (CVE-2013-4837) (old rule) 1058361 WEB HTTP SonicWALL Multiple Products Unauthenticated Password Change Vulnerability (CVE-2013-1360) (old rule) 1058370 FILE Adobe Reader Unspecified Null Pointer (CVE-2013-3352) (old rule) 1058372 FILE Adobe Flash Player Type Confusion Remote Code Execution (CVE-2013-5331) (old rule)