*** EX RELS 03444 Release *** Total number of signatures: 6002 Description ================================================================== In this signature, we addressed the exploits/vulnerabilities and applications as below: Added 9 rule(s): --------------- 1059599 WEB-CLIENT Microsoft Direct2D SVG Path Memory Corruption -3 (CVE-2014-0263) 1059607 SIP Digium Asterisk Cookie Stack Overflow -3 (CVE-2014-2286) 1059611 WEB PHP Libmagic Portable Executable Out Of Bounds Memory Access -2 (CVE-2014-2270) 1059612 WEB-ACTIVEX Mitsubishi ActiveX Control EZPcAut280.dll KeywordSet Argument Buffer Overflow (CVE-2014-2074) 1059617 WEB Easy File Management Web Server Stack Buffer Overflow (BID-67542) 1135901 WEB php imap_open Remote Code Execution -2 (CVE-2018-19518) 1135910 WEB XStream Library ReflectionConverter Insecure Deserialization (CVE-2019-10173) 1135918 WEB Webmin history Parameter Cross-Site-Scripting (CVE-2018-19191) 1135923 WEB Webmin 1.920 Unauhenticated Remote Command Execution (CVE-2019-15107) Modified 3 rule(s): --------------- 1135141 WEB php imap_open Remote Code Execution -1 (CVE-2018-19518) 1135911 WEB Apache Solr DataImport Handler RCE (CVE-2019-0193) 1135919 SSH Redis HyperLogLog hllCount Stack Buffer Overflow (CVE-2019-10193) Deleted 55 rule(s): --------------- 1059417 WEB Apache Tomcat Large Chunked Transfer Denial of Service -1 (CVE-2013-4322) (old rule) 1059420 WEB-CLIENT Microsoft Internet Explorer CVE-2014-0312 Use After Free -2 (CVE-2014-0312) (old rule) 1059433 FILE Adobe Flash Player SharedObject Use After Free -1 (CVE-2014-0502) (old rule) 1059434 FILE Adobe Flash Player load and store Write What Where -2 (CVE-2014-0497) (old rule) 1059437 WEB-ACTIVEX IBM SPSS SamplePower Vsflex8l.ocx ComboList And ColComboList Buffer Overflow (CVE-2014-0895) (old rule) 1059440 FILE Adobe Acrobat and Reader Unspecified Memory Corruption -2 (CVE-2013-3354) (old rule) 1059446 FILE Adobe Flash Player Unspecified Buffer Overflow (CVE-2014-0515) (old rule) 1059469 WEB-CLIENT Oracle Java JNDI Sandbox Bypass (CVE-2014-0422) (old rule) 1059471 EXPLOIT Acunetix 8 build 20120704 - Remote Stack Based Overflow (CVE-2014-2994) (old rule) 1059475 WEB Splunk collect file Directory Traversal (CVE-2013-6771) (old rule) 1059481 EXPLOIT Oracle Java SE GSUB ReqFeatureIndex Buffer Overflow (CVE-2013-5907) (old rule) 1059486 EXPLOIT Oracle Java Private MethodHandle Sandbox Bypass (CVE-2013-5893) (old rule) 1059488 SSL GnuTLS Certificate Verification Policy Bypass -1 (CVE-2014-0092) (old rule) 1059494 WEB Apache Struts CookieInterceptor ClassLoader Security Bypass (CVE-2014-0113) (old rule) 1059503 WEB-CLIENT Microsoft Internet Explorer TextRange Use After Free (CVE-2014-0307) (old rule) 1059504 WEB Microsoft Windows File Handling Component Remote Code Execution (CVE-2014-0315) (old rule) 1059510 FILE Adobe Reader Mobile JavaScript Interface Java Code Execution -1 (CVE-2014-0514) (old rule) 1059523 ICS Yokogawa CS3000 BKESimmgr.exe Buffer Overflow (CVE-2014-0782) (old rule) 1059524 WEB-CLIENT Microsoft Internet Explorer CInput Use After Free -1 (CVE-2014-0282) (old rule) 1059525 WEB-CLIENT Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2014-0310) (old rule) 1059526 WEB-CLIENT Microsoft Internet Explorer Memory Corruption Vulnerability -1 (CVE-2014-1815) (old rule) 1059527 WEB-CLIENT Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2014-1806) (old rule) 1059528 WEB-CLIENT Microsoft Internet Explorer CVE-2014-1804 CBlockContainerBlock Use After Free (CVE-2014-1804) (old rule) 1059533 WEB-CLIENT Microsoft Internet Explorer CVE-2014-1795 Memory Corruption (CVE-2014-1795) (old rule) 1059534 WEB-CLIENT Microsoft Internet Explorer CVE-2014-1791 Memory Corruption (CVE-2014-1791) (old rule) 1059535 WEB-CLIENT Microsoft Internet Explorer CTreePos Use-After-Free (CVE-2014-1793) (old rule) 1059536 WEB-CLIENT Microsoft Internet Explorer CVE-2014-1789 Memory Corruption -1 (CVE-2014-1789) (old rule) 1059537 ICS Schneider Electric ClearSCADA OPF File Parsing Out of Bounds Array Indexing (CVE-2014-0779) (old rule) 1059541 WEB-ACTIVEX Adobe Acrobat Reader AdobePDF ActiveX Use After Free -1 (CVE-2014-0527) (old rule) 1059542 FILE Adobe Adobe Reader PDF417 barcode nteger overflow (CVE-2014-0511) (old rule) 1059543 FILE Adobe Reader DCT Encode Null Pointer Dereference (CVE-2014-0526) (old rule) 1059554 WEB Broadcom PIPA C211 Sensitive Information Disclosure (CVE-2014-2046) (old rule) 1059560 FILE Adobe Flash Player window message handling vulnerability (CVE-2014-0512) (old rule) 1059561 WEB Easy File Sharing Web Server 6.8 - Stack Buffer Overflow (CVE-2014-3791) (old rule) 1059562 EXPLOIT LibYAML Scanner yaml_parser_scan_uri_escapes Heap Buffer Overflow (CVE-2014-2525) (old rule) 1059567 WEB-CLIENT Google Chrome V8 JavaScript Engine Memory Corruption -1 (CVE-2014-1705) (old rule) 1059568 FILE Microsoft Word RTF listoverridecount Memory Corruption -2 (CVE-2014-1761) (old rule) 1059572 SIP Digium Asterisk Cookie Stack Overflow -1 (CVE-2014-2286) (old rule) 1059574 WEB Fitnesse Wiki Remote Command Execution (CVE-2014-1216) (old rule) 1059575 WEB ASUS Multiple Router Products Multiple Vulnerabilities (CVE-2014-2925) (old rule) 1059576 WEB Apache Struts ActionForm ClassLoader Security Bypass -1 (CVE-2014-0114) (old rule) 1059583 ICS Advantech WebAccess SCADA webvact.ocx AccessCode Buffer Overflow -1 (CVE-2014-0768) (old rule) 1059584 ICS Advantech WebAccess SCADA webvact.ocx AccessCode Buffer Overflow -2 (CVE-2014-0768) (old rule) 1059590 WEB-CLIENT Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2014-1802) (old rule) 1059591 WEB-CLIENT Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2014-1800) (old rule) 1059592 FILE Adobe Flash Player security bypass vulnerability (CVE-2014-0520) (old rule) 1059593 WEB-CLIENT Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2014-1766) (old rule) 1059622 EXPLOIT Kerberos Cross-Realm Referrals KDC NULL Pointer Dereference Denial of Service -2 (CVE-2013-1417) (old rule) 1059624 EXPLOIT HP LeftHand Virtual SAN Appliance Remote Arbitrary Code Execution Vulnerability (CVE-2013-2343) (old rule) 1059625 VULN HP Data Protector Backup Client Service Remote Code Execution -2 (CVE-2013-2347) (old rule) 1059627 EXPLOIT HP Data Protector Opcode 45 and 46 Code Execution -5 (CVE-2013-2348) (old rule) 1059628 EXPLOIT HP Data Protector Opcode 45 and 46 Code Execution -6 (CVE-2013-2348) (old rule) 1059629 EXPLOIT Oracle Java JPEGImageWriter Memory Corruption (CVE-2013-2429) (old rule) 1059630 EXPLOIT Oracle Java and JavaFX JPEGImageReader Memory Corruption (CVE-2013-2430) (old rule) 1059639 WEB-ACTIVEX Mitsubishi MCWorkX ActiveX Control File Execution -1 (CVE-2013-2817) (old rule)