*** NK8 RELS 3427 Release *** Total number of signatures: 3182 Description ================================================================== In this signature, we addressed the exploits/vulnerabilities and applications as below: Added 5 rule(s): --------------- 1135553 SMB Microsoft Windows SMB Server SMBv1 CVE-2017-0143 Memory Corruption -4 1135557 EXPLOIT UltraVNC VNC Server File Transfer Offer Handler Heap-based Buffer Overflow (CVE-2019-8274) 1135559 WEB Atlassian Confluence Widget Connector Macro Velocity Template Injection (CVE-2019-3396) 1135560 WEB-CLIENT Microsoft Edge and Internet Explorer Chakra CVE-2018-8145 Heap Buffer Overflow -3 (CVE-2018-8145) 1135561 WEB Apache Tomcat HTTP2 Denial of Service (CVE-2019-0199) Modified 5 rule(s): --------------- 1134909 WEB-CLIENT Microsoft Edge and Internet Explorer Chakra CVE-2018-8145 Heap Buffer Overflow -1 (CVE-2018-8145) 1134910 WEB-CLIENT Microsoft Edge and Internet Explorer Chakra CVE-2018-8145 Heap Buffer Overflow -2 (CVE-2018-8145) 1135520 WEB WordPress Crop-image Shell Upload (CVE-2019-8942) 1135529 FILE Foxit Reader JavaScript popUpMenu Use After Free -1.1 (CVE-2019-7089) 1135541 NTP NTPsec ntpd ctl_getitem Out of Bounds Read -1 (CVE-2019-6443) Deleted 13 rule(s): --------------- 1130032 WEB HP Network Virtualization storedNtxFile Directory Traversal -1 (CVE-2014-2625) (old rule) 1130034 WEB HP Network Virtualization toServerObject Directory Traversal -1 (CVE-2014-2626) (old rule) 1130044 WEB SQL injection attempt -70 (old rule) 1130047 SSL OpenSSL DTLS Handshake Double Free -1 (CVE-2014-3505) (old rule) 1130048 SSL OpenSSL DTLS Handshake Memory Exhaustion (CVE-2014-3506) (old rule) 1130049 SSL OpenSSL Invalid SRP Parameter A Buffer Overflow (CVE-2014-3512) (old rule) 1130050 SSL OpenSSL Invalid SRP Parameters g and B Buffer Overflow (CVE-2014-3512) (old rule) 1130062 WEB AlienVault OSSIM av-centerd Util.pm remote_task Arbitrary Command Execution -1 (CVE-2014-5210) (old rule) 1130065 RPC Drupal Core XML-RPC Endpoint xmlrpc.php Tags Denial of Service -1 (CVE-2014-5266) (old rule) 1130068 FILE BlazeVideo BlazeDVD Pro PLF File Processing Buffer Overflow -1 (OSVDB-105679) (old rule) 1130092 WEB-CLIENT Google Android Browser Same Origin Policy Bypass (CVE-2014-6041) (old rule) 1130110 EXPLOIT HP Data Protector Opcode 1091 Directory Traversal -1 (CVE-2014-5160) (old rule) 1130125 WEB-CLIENT Mozilla Firefox DOMSVGLength Reflected Attribute Use-After-Free -2 (CVE-2014-1563) (old rule)