*** EX RELS 03483 Release *** Total number of signatures: 6000 Description ================================================================== In this signature, we addressed the exploits/vulnerabilities and applications as below: Added 17 rule(s): --------------- 1136949 RPC Microsoft Windows Server Service RPC Request Handling Buffer Overflow -6 (MS08-067,CVE-2008-4250) 1136950 WEB Rockwell Automation FactoryTalk RNADiagnosticsSrv Insecure Deserialization -1.1 (CVE-2020-6967) 1136951 WEB Rockwell Automation FactoryTalk RNADiagnosticsSrv Insecure Deserialization -2 (CVE-2020-6967) 1136952 WEB Rockwell Automation FactoryTalk RNADiagnosticsSrv Insecure Deserialization -3 (CVE-2020-6967) 1136953 WEB Rockwell Automation FactoryTalk RNADiagnosticsSrv Insecure Deserialization -4 (CVE-2020-6967) 1136954 WEB Rockwell Automation FactoryTalk RNADiagnosticsSrv Insecure Deserialization -5 (CVE-2020-6967) 1136955 WEB Cisco UCS Director isEnableRestKeyAccessCheckForUser Authentication Bypass Vulnerability -1 (CVE-2020-3243) 1136964 WEB-CLIENT Microsoft Internet Explorer VBScript Remote Code Execution Vulnerability (CVE-2020-1058) 1136966 WEB-CLIENT Microsoft Internet Explorer VBScript Remote Code Execution Vulnerability (CVE-2020-1035) 1136973 WEB Oracle Business Intelligence BIRemotingServlet AMF Insecure Deserialization (CVE-2020-2950) 1136976 WEB-CLIENT Microsoft Internet Explorer VBScript Remote Code Execution Vulnerability (CVE-2020-1060) 1136977 WEB Rockwell Automation FactoryTalk RNADiagnosticsSrv Insecure Deserialization -1.2 (CVE-2020-6967) 1136978 WEB Rockwell Automation FactoryTalk RNADiagnosticsSrv Insecure Deserialization -1.3 (CVE-2020-6967) 1136979 WEB Rockwell Automation FactoryTalk RNADiagnosticsSrv Insecure Deserialization -1.4 (CVE-2020-6967) 1136980 WEB Rockwell Automation FactoryTalk RNADiagnosticsSrv Insecure Deserialization -1.5 (CVE-2020-6967) 1136981 WEB Rockwell Automation FactoryTalk RNADiagnosticsSrv Insecure Deserialization -1.6 (CVE-2020-6967) 1162518 WEB Baidu access via SSL -1.2 Modified 6 rule(s): --------------- 1063520 SOCIAL Weibo access via TCP -1.1 1064109 SOCIAL Weibo access via TCP -1.2 1068984 WEB Baidu access via SSL -1.1 1130595 FILE Microsoft Office Memory Corruption Vulnerability -1.1 (CVE-2015-1641) 1131075 FILE Microsoft Office Memory Corruption Vulnerability -1.2 (CVE-2015-1641) 1135883 WEB Atlassian JIRA Template Injection Code Execution -2.1 (CVE-2019-11581) Deleted 39 rule(s): --------------- 1064960 WEB Baidu login via SSL -1 (old rule) 1130218 WEB-CLIENT Microsoft Internet Explorer Same Origin Policy Bypass -1 (CVE-2015-0072) (old rule) 1130334 FILE Adobe Flash Player Sandbox Escape improper file validation (CVE-2015-0301) (old rule) 1130339 FILE Adobe Flash Player BrokerLcdDispatchMessage Memory corruption (CVE-2015-0306) (old rule) 1130351 FILE Microsoft Windows Application Compatibility Infrastructure Privilege Escalation (CVE-2015-0002) (old rule) 1130352 FILE Microsoft Windows WebDAV Kernel Driver Privilege Escalation (CVE-2015-0011) (old rule) 1130370 FILE Adobe Flash Player CVE-2015-0311 Unspecified Memory Corruption Vulnerability -1 (CVE-2015-0311) (old rule) 1130371 FILE Adobe Flash Player CVE-2015-0311 Unspecified Memory Corruption Vulnerability -2 (CVE-2015-0311) (old rule) 1130372 FILE Adobe Flash Player CVE-2015-0311 Unspecified Memory Corruption Vulnerability -3 (CVE-2015-0311) (old rule) 1130373 FILE Adobe Flash Player CVE-2015-0311 Unspecified Memory Corruption Vulnerability -4 (CVE-2015-0311) (old rule) 1130374 FILE Adobe Flash Player CVE-2015-0311 Unspecified Memory Corruption Vulnerability -5 (CVE-2015-0311) (old rule) 1130375 FILE Adobe Flash Player CVE-2015-0311 Unspecified Memory Corruption Vulnerability -6 (CVE-2015-0311) (old rule) 1130376 FILE Adobe Flash Player CVE-2015-0311 Unspecified Memory Corruption Vulnerability -7 (CVE-2015-0311) (old rule) 1130391 FILE Adobe Flash Player CVE-2015-0310 Memory Corruption (CVE-2015-0310) (old rule) 1130393 FILE Adobe Flash Player bytearray.compress() Remote Code Execution (CVE-2015-0312) (old rule) 1130398 FILE Adobe Flash Player CVE-2015-0313 Code Execution -1 (CVE-2015-0313) (old rule) 1130399 FILE Adobe Flash Player CVE-2015-0313 Code Execution -2 (CVE-2015-0313) (old rule) 1130403 WEB McAfee ePolicy Orchestrator XML Entity Injection -1 (CVE-2015-0921) (old rule) 1130405 FILE Adobe Flash Player DomainMemory Use After Free (CVE-2015-0311) (old rule) 1130414 FILE Adobe Flash Player XMLSocket.connect Type Confusion (CVE-2015-0317) (old rule) 1130421 FILE Adobe Flash Player JSON.stringify Integer Heap Overflow (CVE-2015-0324) (old rule) 1130424 FILE Adobe Flash Player Stringifying Proxy Objects Heap Overflow -1 (CVE-2015-0327) (old rule) 1130433 WEB-CLIENT Microsoft Internet Explorer Memory Corruption Vulnerability -1 (CVE-2015-0017) (old rule) 1130434 WEB-CLIENT Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2015-0018) (old rule) 1130437 WEB-CLIENT Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2015-0019) (old rule) 1130438 WEB-CLIENT Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2015-0020) (old rule) 1130439 WEB-CLIENT Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2015-0021) (old rule) 1130442 WEB-CLIENT Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2015-0022) (old rule) 1130444 WEB-CLIENT Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2015-0025) (old rule) 1130447 WEB-CLIENT Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2015-0029) (old rule) 1130449 WEB-CLIENT Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2015-0031) (old rule) 1130452 WEB-CLIENT Microsoft Internet Explorer Memory Corruption Vulnerability -1 (CVE-2015-0036) (old rule) 1130454 WEB-CLIENT Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2015-0052) (old rule) 1130457 WEB-CLIENT Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2015-0039) (old rule) 1130462 WEB-CLIENT Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2015-0041) (old rule) 1130467 WEB-CLIENT Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2015-0044) (old rule) 1130470 RADIUS Microsoft Network Policy Server RADIUS Denial of Service -1 (CVE-2015-0015) (old rule) 1130473 WEB WordPress XMLRPC GHOST Vulnerability (CVE-2015-0235) (old rule) 1130475 WEB-CLIENT Microsoft Internet Explorer Same Origin Policy Bypass -2 (CVE-2015-0072) (old rule)