Rule Update
18-028 (May 22, 2018)
Publish date: May 22, 2018
DESCRIPTION
* indicates a new version of an existing rule
Deep Packet Inspection Rules:
DHCP Client
1009116 - DHCP Client Script Code Execution Vulnerability (CVE-2018-1111) - 1
DHCP Client - Incoming
1009114 - DHCP Client Script Code Execution Vulnerability (CVE-2018-1111)
DNS Server
1008652* - DNSmasq Answer Auth And Answer Request Integer Underflow Vulnerability (CVE-2017-13704)
Microsoft Office
1009052 - Microsoft Excel Remote Code Execution Vulnerability (CVE-2018-0796)
Web Application Common
1005613* - Generic SQL Injection Prevention - 2
1009090 - ImageMagick ReadOneMNGImage Denial Of Service Vulnerability (CVE-2018-10177) - 1
1009057* - Pivotal Spring Data Commons Remote Code Execution Vulnerability (CVE-2018-1273)
Web Application PHP Based
1009054* - Drupal Core Remote Code Execution Vulnerability (CVE-2018-7602)
Web Client Common
1008739* - Adobe Acrobat And Reader Multiple Security Vulnerabilities (APSB17-36) - 1
1009092 - Foxit PDF Reader JavaScript 'XFA Clone' Remote Code Execution Vulnerability (CVE-2018-3850)
1009091 - Foxit PDF Reader Javascript 'Search Query' Remote Code Execution Vulnerability (CVE-2017-14458)
1009089 - ImageMagick ReadOneMNGImage Denial Of Service Vulnerability (CVE-2018-10177)
Web Client Internet Explorer/Edge
1008700* - Microsoft Internet Explorer And Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-11837)
1009047 - Microsoft Internet Explorer Information Disclosure Vulnerability (CVE-2018-0929)
1008935* - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2018-0935)
Web Client Mozilla Firefox
1008951 - Mozilla Firefox Buffer Overflow Parsing HTML5 Fragments Vulnerability (CVE-2016-2819)
Web Server Common
1008646 - Detect Illegal Characters In URI
1000128* - HTTP Protocol Decoding
1005839* - Identified XML External Entity Injection In HTTP Request
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Deep Packet Inspection Rules:
DHCP Client
1009116 - DHCP Client Script Code Execution Vulnerability (CVE-2018-1111) - 1
DHCP Client - Incoming
1009114 - DHCP Client Script Code Execution Vulnerability (CVE-2018-1111)
DNS Server
1008652* - DNSmasq Answer Auth And Answer Request Integer Underflow Vulnerability (CVE-2017-13704)
Microsoft Office
1009052 - Microsoft Excel Remote Code Execution Vulnerability (CVE-2018-0796)
Web Application Common
1005613* - Generic SQL Injection Prevention - 2
1009090 - ImageMagick ReadOneMNGImage Denial Of Service Vulnerability (CVE-2018-10177) - 1
1009057* - Pivotal Spring Data Commons Remote Code Execution Vulnerability (CVE-2018-1273)
Web Application PHP Based
1009054* - Drupal Core Remote Code Execution Vulnerability (CVE-2018-7602)
Web Client Common
1008739* - Adobe Acrobat And Reader Multiple Security Vulnerabilities (APSB17-36) - 1
1009092 - Foxit PDF Reader JavaScript 'XFA Clone' Remote Code Execution Vulnerability (CVE-2018-3850)
1009091 - Foxit PDF Reader Javascript 'Search Query' Remote Code Execution Vulnerability (CVE-2017-14458)
1009089 - ImageMagick ReadOneMNGImage Denial Of Service Vulnerability (CVE-2018-10177)
Web Client Internet Explorer/Edge
1008700* - Microsoft Internet Explorer And Edge Scripting Engine Memory Corruption Vulnerability (CVE-2017-11837)
1009047 - Microsoft Internet Explorer Information Disclosure Vulnerability (CVE-2018-0929)
1008935* - Microsoft Internet Explorer Memory Corruption Vulnerability (CVE-2018-0935)
Web Client Mozilla Firefox
1008951 - Mozilla Firefox Buffer Overflow Parsing HTML5 Fragments Vulnerability (CVE-2016-2819)
Web Server Common
1008646 - Detect Illegal Characters In URI
1000128* - HTTP Protocol Decoding
1005839* - Identified XML External Entity Injection In HTTP Request
Integrity Monitoring Rules:
There are no new or updated Integrity Monitoring Rules in this Security Update.
Log Inspection Rules:
There are no new or updated Log Inspection Rules in this Security Update.
Featured Stories
Hunt Them All: An AI-Powered Vulnerability Sweep of 19,000 MCP ServersIn this research, we analyzed over 19,000 open-source MCP server repositories to uncover how much AI-generated code they contain and how many harbor exploitable vulnerabilities.Read more
Update on Exposed MCP Servers: The Threat Widens to the CloudExposed Model Context Protocol (MCP) servers have become powerful vectors for cloud attacks, enabling threat actors to not only access sensitive data but also take control of the cloud services themselves.Read more
Old Vulnerabilities, New AI Era, Amplified Risk: How Outdated Flaws Continue to Fuel the N-Day Exploit MarketEven as AI adoption accelerates, old exploits remain overlooked weaknesses. Underground trends show a renewed demand for exploits, with cybercriminals relying on aging but still effective vulnerabilities. We examine this blind spot and why long-standing issues need to be addressed.Read more
Beware of MCP Hardcoded Credentials: A Perfect Target for Threat ActorsPoor secret management in MCP servers can lead to serious consequences, including data breaches and supply chain attacks. This article examines the reality of these unsecure configurations and offers practical recommendations that minimize the chances of exposure.Read more