Update #2424 (09/30/2014)
21 new signatures:
| MEDIUM | HTTP:STC:MOZILLA:LOCATION-HOST | HTTP: Mozilla Firefox Location.Hostname Dom Property Cookie Theft |
| HIGH | HTTP:MISC:UPTIME-MONTRN-PHP-RCE | HTTP: UpTime Monitoring PHP File Remote Code Execution |
| MEDIUM | APP:MISC:SIMENS-GIGAST-DOS | APP: Siemens Gigaset SE361 WLAN Data Flood Denial of Service |
| HIGH | HTTP:STC:ADOBE:FLV-FILE-DOS | HTTP: Adobe Flash Player FLV file Denial of Service |
| HIGH | HTTP:STC:ADOBE:CVE-2014-0568-SE | HTTP: Adobe Reader CVE-2014-0568 Sandbox Escape |
| CRITICAL | HTTP:CGI:SHELLSHOCK | HTTP: Multiple Products Bash Shellshock Vulnerability |
| HIGH | SCADA:EKTRON-CMS-XSLT-RCE | SCADA: Ektron CMS XslCompiledTransform Class Remote Code Execution |
| HIGH | APP:MISC:DSM-SLICEUPLOAD-RCE | APP: Synology DiskStation Manager SliceUpload Functionality Remote Command Execution |
| HIGH | HTTP:STC:NDROID-BROW-SAME-ORIGN | HTTP: Android Browser URL Parser NULL-byte Handling Same Origin Policy Bypass |
| MEDIUM | SCADA:IOSERVER-INFO-DISCLSURE | SCADA: IOServer Information Disclosure |
| HIGH | SMTP:EXPLOIT:JPXDECODE-RCE | SMTP: Adobe PDF JPXDecode Remote Code Execution |
| HIGH | HTTP:STC:ADOBE:CVE-2014-0565-MC | HTTP: Adobe Reader CVE-2014-0565 Memory Corruption |
| MEDIUM | HTTP:MAMBO-MYSQL-INF-DISCLOSURE | HTTP: Mambo MySQL Database Info Disclosure |
| HIGH | HTTP:DIR:NOVELL-GROUPWSE-DIRTRA | HTTP: Novell GroupWise Admin Service FileUploadServlet Directory Traversal |
| CRITICAL | DHCP:SERVER:GNU-BASH-CMD-EXE | DHCP: GNU Bash Environment Variable Handling Command Execution DHCP Vector |
| HIGH | APP:SQUID-SNMPHANDLEUDP-CE | APP: Squid snmpHandleUdp Off-by-one Buffer Overflow |
| CRITICAL | HTTP:CGI:BASH-INJECTION-HEADER | HTTP: Multiple Products Bash Code Injection In Header |
| HIGH | HTTP:MISC:WIN-MOVIE-MAKER-DOS | HTTP: Microsoft Windows Movie Maker Denial Of Service |
| HIGH | HTTP:DLINK-CMD-RCE | HTTP: D-Link Multiple Router Cmd Parameter Remote Command Execution |
| CRITICAL | HTTP:CGI:BASH-INJECTION-URL | HTTP: Multiple Products Bash Code Injection In URL |
| MEDIUM | HTTP:STC:MOZILLA:ONKEYDOWN-FU | HTTP: Mozilla Firefox OnKeyDown Event File Upload |
1 new application signature:
| Web:Anonymizer:ZENGUARD-SSL | Zenguard SSL |
6 updated signatures:
| HIGH | HTTP:APACHE:STRUTS-OGNL-CMDEXEC | HTTP: Apache Struts OGNL Expression Parsing Arbitrary Command Execution |
| HIGH | HTTP:APACHE:MOD_DEFLATE-DOS | HTTP: Apache HTTP Server mod_deflate Denial of Service |
| HIGH | NFS:CAP-MKNOD | NFS: Linux CAP_MKNOD Bypass |
| MEDIUM | HTTP:TOMCAT:AJP12-SHUTDOWN | HTTP: Apache Tomcat Server AJP12 Shutdown DoS |
| HIGH | HTTP:OVERFLOW:SENKAS-KALIBRI-BO | HTTP: SENKAS Kolibri Webserver GET Request Buffer Overflow |
| MEDIUM | HTTP:STC:MOZILLA:FF-ABT-BLK-SPF | HTTP: Mozilla Firefox About:Blank Spoof |
Details of the signatures included within this bulletin:
HTTP:CGI:SHELLSHOCK - HTTP: Multiple Products Bash Shellshock Vulnerability
Severity: CRITICAL
Description:
This signature detects attempts to exploit a known vulnerability against GNU Bash. A successful attack can lead to arbitrary code execution.
Supported On:
DI-Client, DI-Worm, idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, idp-4.2.0, idp-5.0.0, mx-9.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, isg-3.5.0, srx-9.2, srx-branch-9.4, j-series-9.5, idp-4.2.110100823, srx-10.0, srx-branch-10.0, idp-4.2.110101203, idp-5.1.0, idp-4.1.110110609, srx-11.4, srx-branch-11.4, idp-4.1.110110719, mx-11.4, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, isg-3.5.140773, idp-5.1.110140626, isg-3.5.140842, idp-5.1.110140822
References:
DHCP:SERVER:GNU-BASH-CMD-EXE - DHCP: GNU Bash Environment Variable Handling Command Execution DHCP Vector
Severity: CRITICAL
Description:
This signature detects attempts to exploit a known vulnerability against GNU Bash. The vulnerability is due to a failure in handling environment variables. A remote attacker can exploit this vulnerability by interacting with an application that uses Bash environment variables whose content is determined by input read from the network such as a DHCP client. If an attacker can control the value of an environment variable, then command execution can be achieved in the context of the application using the environment variable.
Supported On:
idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, idp-4.2.0, idp-5.0.0, mx-9.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, isg-3.5.0, srx-9.2, srx-branch-9.4, j-series-9.5, idp-4.2.110100823, srx-10.0, srx-branch-10.0, idp-4.2.110101203, idp-5.1.0, idp-4.1.110110609, srx-11.4, srx-branch-11.4, idp-4.1.110110719, mx-11.4, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, isg-3.5.140773, idp-5.1.110140626, isg-3.5.140842, idp-5.1.110140822
References:
HTTP:APACHE:MOD_DEFLATE-DOS - HTTP: Apache HTTP Server mod_deflate Denial of Service
Severity: HIGH
Description:
This signature detects attempts to exploit a known vulnerability against Apache HTTP server. A successful attack can result in a denial-of-service condition.
Supported On:
idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, idp-4.2.0, idp-5.0.0, mx-9.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, isg-3.5.0, srx-9.2, srx-branch-9.4, j-series-9.5, idp-4.2.110100823, srx-10.0, srx-branch-10.0, idp-4.2.110101203, idp-5.1.0, idp-4.1.110110609, srx-11.4, srx-branch-11.4, idp-4.1.110110719, mx-11.4, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, isg-3.5.140773, idp-5.1.110140626, isg-3.5.140842, idp-5.1.110140822
References:
NFS:CAP-MKNOD - NFS: Linux CAP_MKNOD Bypass
Severity: HIGH
Description:
This signature detects attempts to exploit a known vulnerability against Linux Kernel nfsd module. A successful attack can lead to security bypass.
Supported On:
idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, idp-4.2.0, idp-5.0.0, mx-9.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, isg-3.5.0, srx-9.2, srx-branch-9.4, j-series-9.5, idp-4.2.110100823, srx-10.0, srx-branch-10.0, idp-4.2.110101203, idp-5.1.0, idp-4.1.110110609, srx-11.4, srx-branch-11.4, idp-4.1.110110719, mx-11.4, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, isg-3.5.140773, idp-5.1.110140626, isg-3.5.140842, idp-5.1.110140822
References:
Affected Products:
- Avaya Aura Application Enablement Services 4.2.1
- Linux kernel 2.6.24.6
- Linux kernel 2.6.12 .6
- Linux kernel 2.6.16 .1
- Linux kernel 2.6.25 19
- Linux kernel 2.6.28 -Rc1
- Linux kernel 2.6.26 7
- Linux kernel 2.6.27 3
- Linux kernel 2.6.29-Rc2
- Linux kernel 2.6.29-Rc2-Git1
- Linux kernel 2.6.20 -Git5
- Linux kernel 2.6.25.6
- Linux kernel 2.6.16 .23
- Linux kernel 2.6.17.3
- Linux kernel 2.6.28 -Rc7
- Linux kernel 2.4.33.4
- Linux kernel 2.6.11 -Rc2
- Linux kernel 2.6.11 -Rc3
- Linux kernel 2.6.18.3
- Linux kernel 2.6.19.1
- Linux kernel 2.6.25.10
- Linux kernel 2.6.23.09
- Avaya Aura SIP Enablement Services 3.1
- Linux kernel 2.4.22
- Linux kernel 2.4.23 -Pre9
- Linux kernel 2.6.0 -Test9
- Linux kernel 2.6.20-2
- Linux kernel 2.4.0 .0-Test3
- Linux kernel 2.4.0 .0-Test2
- Linux kernel 2.4.0 .0-Test4
- Linux kernel 2.4.0 .0-Test5
- Linux kernel 2.4.0 .0-Test6
- Linux kernel 2.4.0 .0-Test7
- Linux kernel 2.4.0 .0-Test8
- Linux kernel 2.4.0 .0-Test9
- Linux kernel 2.4.0 .0-Test10
- Linux kernel 2.4.0 .0-Test11
- Linux kernel 2.4.0 .0-Test12
- Linux kernel 2.4.27
- SuSE SUSE Linux Enterprise Server 11 DEBUGINFO
- Avaya Communication Manager 2.1
- Avaya Communication Manager 2.2
- Avaya Proactive Contact 4.1
- Linux kernel 2.6.28.2
- Linux kernel 2.6.27.12
- Linux kernel 2.6.27 12
- Linux kernel 2.6.27.13
- Linux kernel 2.6.20.5
- Linux kernel 2.6.24
- SuSE SUSE Linux Enterprise Server 11
- Linux kernel 2.6.17.4
- Avaya Aura SIP Enablement Services 5.1
- Linux kernel 2.4.37-Rc1
- Linux kernel 2.6.22-Rc1
- SuSE Novell Linux POS 9
- Linux kernel 2.6.15
- Linux kernel 2.4.36.7
- Avaya Aura Application Enablement Services 4.0
- Linux kernel 2.6.11 -Rc4
- Linux kernel 2.6.28
- Linux kernel 2.6.28 -Git7
- Linux kernel 2.6.21-RC4
- Linux kernel 2.6.21-RC5
- Linux kernel 2.6.21-RC6
- Linux kernel 2.6.16.2
- Linux kernel 2.4.28
- Avaya Communication Manager 4.0
- Linux kernel 2.6.11 .7
- Linux kernel 2.6.11 .8
- Linux kernel 2.6.15 -Rc4
- Linux kernel 2.6.15 -Rc5
- Linux kernel 2.6.15 -Rc6
- Linux kernel 2.6.16.4
- Linux kernel 2.6.26.3
- Linux kernel 2.6.26.4
- Linux kernel 2.4.33.5
- Linux kernel 2.6.17.13
- Linux kernel 2.6.20.1
- Linux kernel 2.4.0 .0-Test1
- Linux kernel 2.6.14
- Linux kernel 2.6.22.6
- Linux kernel 2.6.22.5
- Linux kernel 2.6.16.5
- Linux kernel 2.6.17.5
- SuSE SUSE Linux Enterprise Server 9
- Red Hat Enterprise Linux AS 4
- Red Hat Enterprise Linux ES 4
- Red Hat Enterprise Linux WS 4
- Linux kernel 2.6.18
- Linux kernel 2.6.27-Rc6
- Linux kernel 2.6.27-Rc5
- Avaya Message Networking MN 3.1
- Linux kernel 2.6.2
- Linux kernel 2.4.23 -Ow2
- Linux kernel 2.4.24 -Ow1
- Linux kernel 2.6.3
- Linux kernel 2.4.25
- Linux kernel 2.4.27 -Pre1
- Linux kernel 2.4.27 -Pre2
- Linux kernel 2.6.24-Rc4
- Linux kernel 2.4.33 .6
- Linux kernel 2.6.16.8
- Linux kernel 2.6.16 27
- Linux kernel 2.6.16 .9
- Linux kernel 2.4.31 -Pre1
- Linux kernel 2.6.12 -Rc4
- Linux kernel 2.6.25.1
- Linux kernel 2.4.23
- Linux kernel 2.4.36.9
- Linux kernel 2.6.27.14
- Linux kernel 2.6.0 -Test1
- Avaya Messaging Storage Server 3.1 SP1
- Linux kernel 2.6.28.3
- Debian Linux 5.0 Hppa
- Debian Linux 5.0 Ia-32
- Debian Linux 5.0 Ia-64
- Linux kernel 2.6.28.1
- Debian Linux 5.0 M68k
- Linux kernel 2.6.0 -Test7
- Linux kernel 2.6.27 6
- Debian Linux 5.0 Mipsel
- Linux kernel 2.4.19 -Pre1
- Linux kernel 2.4.19 -Pre2
- Linux kernel 2.4.19 -Pre3
- Linux kernel 2.4.19 -Pre4
- Linux kernel 2.4.19 -Pre5
- Linux kernel 2.4.19 -Pre6
- Debian Linux 5.0 S/390
- Ubuntu Ubuntu Linux 8.04 LTS Amd64
- Ubuntu Ubuntu Linux 8.04 LTS I386
- Ubuntu Ubuntu Linux 8.04 LTS Lpia
- Ubuntu Ubuntu Linux 8.04 LTS Powerpc
- Ubuntu Ubuntu Linux 8.04 LTS Sparc
- Linux kernel 2.6.22-Rc7
- Linux kernel 2.6.16 .7
- Linux kernel 2.6.16 -Rc1
- Linux kernel 2.4.36.4
- Red Hat Desktop 4.0.0
- Linux kernel 2.6.28.4
- Linux kernel 2.4.13
- Linux kernel 2.6.28 -Rc5
- Linux kernel 2.6.19 -Rc1
- Avaya Intuity AUDIX LX 2.0 SP1
- Avaya Intuity AUDIX LX 2.0 SP2
- Linux kernel 2.4.32
- Linux kernel 2.4.33 -Pre1
- Linux kernel 2.6.17.6
- Linux kernel 2.4.33.3
- Linux kernel 2.6.17.14
- Linux kernel 2.6.13 -Rc6
- Linux kernel 2.4.33.6
- Linux kernel 2.4.33.7
- Linux kernel 2.4.34
- Linux kernel 2.6.20-Rc2
- Linux kernel 2.6.18 .1
- Avaya Meeting Exchange 5.0 SP1
- Avaya Meeting Exchange 5.0 SP2
- Avaya Meeting Exchange 5.1 SP1
- Linux kernel 2.6.16 .11
- Linux kernel 2.6.23.6
- Linux kernel 2.4.34.3
- Debian Linux 5.0 Arm
- Linux kernel 2.6.25.3
- Linux kernel 2.6.13 -Rc1
- Linux kernel 2.6.28.5
- Avaya Communication Manager 5.2
- Avaya Aura SIP Enablement Services 5.2
- Avaya Voice Portal 5.0 SP1
- Ubuntu Ubuntu Linux 9.04 Amd64
- Debian Linux 5.0
- Debian Linux 5.0 Alpha
- Debian Linux 5.0 Amd64
- Linux kernel 2.6.0 -Test2
- Linux kernel 2.6.0 -Test3
- Linux kernel 2.6.0 -Test4
- Linux kernel 2.6.0 -Test5
- Linux kernel 2.6.0 -Test6
- Debian Linux 5.0 Mips
- Linux kernel 2.6.0 -Test8
- Linux kernel 2.6.0 -Test10
- Linux kernel 2.6.0 -Test11
- Debian Linux 5.0 Sparc
- Linux kernel 2.6.23.14
- Linux kernel 2.6.16 13
- Linux kernel 2.6.20.15
- Linux kernel 2.6.21.6
- Linux kernel 2.6.22
- Linux kernel 2.6.28.6
- Ubuntu Ubuntu Linux 9.04 I386
- Ubuntu Ubuntu Linux 9.04 Lpia
- Ubuntu Ubuntu Linux 9.04 Powerpc
- Ubuntu Ubuntu Linux 9.04 Sparc
- Linux kernel 2.4.0
- Linux kernel 2.4.1
- Linux kernel 2.4.2
- Linux kernel 2.4.3
- Linux kernel 2.6.22.11
- Linux kernel 2.6.20.9
- Linux kernel 2.6.26.5
- Linux kernel 2.6.18-8.1.8.El5
- Linux kernel 2.6.20.8
- Linux kernel 2.6.14 .1
- rPath rPath Linux 2
- Linux kernel 2.4.21 Pre7
- Avaya Aura SIP Enablement Services 3.1.1
- Linux kernel 2.6.22.14
- Avaya Communication Manager 3.1
- Linux kernel 2.4.7
- Linux kernel 2.4.8
- Linux kernel 2.4.9
- Linux kernel 2.4.10
- Linux kernel 2.4.11
- Linux kernel 2.6.27 .5
- Debian Linux 5.0 Powerpc
- Linux kernel 2.6.8.1
- Linux kernel 2.6.10 Rc2
- Linux kernel 2.4.12
- Avaya Meeting Exchange 5.0
- Avaya Voice Portal 4.0
- Avaya Voice Portal 4.1
- Linux kernel 2.6.15.3
- Linux kernel 2.6.15.2
- Linux kernel 2.6.15.1
- Linux kernel 2.6.21
- Linux kernel 2.6.12
- Linux kernel 2.6.23
- Linux kernel 2.6.16.16
- Linux kernel 2.6.13 -Rc7
- Linux kernel 2.6.23.1
- Linux kernel 2.6.6
- Linux kernel 2.6.7 Rc1
- Linux kernel 2.6.6 Rc1
- Linux kernel 2.6.25.11
- Avaya Aura Application Enablement Services 4.1
- Linux kernel 2.6.25.7
- Linux kernel 2.6.25.8
- Linux kernel 2.6.25.9
- VMWare ESX Server 4.0
- Linux kernel 2.6.23.2
- Linux kernel 2.6.23.3
- Linux kernel 2.6.23.4
- Linux kernel 2.6.23.7
- Linux kernel 2.6.23.5
- Linux kernel 2.6.23.10
- Linux kernel 2.6.24-Rc1
- Linux kernel 2.6.24-Rc2
- Linux kernel 2.6.7
- Linux kernel 2.6.0 -Test9-CVS
- Linux kernel 2.6.14.4
- Linux kernel 2.6.14.5
- Linux kernel 2.6.27.8
- Linux kernel 2.6.11 .11
- Linux kernel 2.6.15-27.48
- Linux kernel 2.6.21-Git8
- Linux kernel 2.6.12 .22
- Linux kernel 2.6.11
- Linux kernel 2.6.25.4
- Linux kernel 2.6.27 -Rc8
- Linux kernel 2.6.27 -Rc8-Git5
- Linux kernel 2.6.19.2
- Linux kernel 2.6.25
- Linux kernel 2.6.12 -Rc5
- Linux kernel 2.6.12 .5
- Linux kernel 2.6.12 .4
- Linux kernel 2.6.12 .3
- Linux kernel 2.6.12 .2
- rPath Appliance Platform Linux Service 1
- Linux kernel 2.4.32 -Pre2
- Linux kernel 2.4.18 X86
- Linux kernel 2.6.25.12
- Linux kernel 2.6.25.13
- Linux kernel 2.6.11 .12
- Linux kernel 2.6.19 -Rc2
- Linux kernel 2.6.27 -Rc6-Git6
- Linux kernel 2.6.19 -Rc3
- Avaya Communication Manager 3.1.4 SP2
- Avaya Communication Manager 4.0.3 SP1
- Avaya Communication Manager 5.0 SP3
- Avaya Communication Manager 5.1
- Linux kernel 2.6.19 -Rc4
- Linux kernel 2.6.15.11
- Linux kernel 2.4.34.6
- Linux kernel 2.6.17.9
- Linux kernel 2.4.33
- Linux kernel 2.4.33.1
- Linux kernel 2.6.16.17
- Linux kernel 2.6.16.18
- Linux kernel 2.6.18-53
- Avaya Aura Application Enablement Services 4.2
- Avaya Aura Application Enablement Services 4.2.2
- Linux kernel 2.4.14
- Linux kernel 2.4.15
- Linux kernel 2.6.16 .12
- Linux kernel 2.6.26.6
- Linux kernel 2.6.20.11
- Avaya Aura SIP Enablement Services 3.0
- Linux kernel 2.4.18 Pre-1
- Linux kernel 2.4.18 Pre-2
- Linux kernel 2.4.18 Pre-3
- Linux kernel 2.4.18 Pre-4
- Linux kernel 2.4.18 Pre-5
- Linux kernel 2.4.18 Pre-6
- Linux kernel 2.4.18 Pre-7
- Linux kernel 2.4.18 Pre-8
- Linux kernel 2.4.18
- Linux kernel 2.4.36.5
- Linux kernel 2.6.22.7
- Linux kernel 2.4.35.3
- Linux kernel 2.6.17.2
- Linux kernel 2.6.26.1
- VMWare vMA 4.0
- Linux kernel 2.6.0
- Linux kernel 2.4.24
- Linux kernel 2.6.16
- Linux kernel 2.6.16 .19
- Linux kernel 2.6.17 -Rc5
- Linux kernel 2.6.15 -Rc3
- Linux kernel 2.6.15 -Rc2
- Linux kernel 2.6.15 -Rc1
- Linux kernel 2.6.0 .10
- Linux kernel 2.6.14 .2
- Linux kernel 2.6.14 .3
- Linux kernel 2.6.27-Rc1
- Linux kernel 2.6.27-Rc2
- Linux kernel 2.6.22.8
- Linux kernel 2.6.21-RC3
- Linux kernel 2.6.1 -Rc1
- Linux kernel 2.6.1 -Rc2
- SuSE SUSE Linux Enterprise Desktop 10 SP2
- SuSE SUSE Linux Enterprise Server 10 SP2
- SuSE SUSE Linux Enterprise SDK 10 SP2
- Linux kernel 2.6.28.8
- Linux kernel 2.4.19
- Linux kernel 2.6.17.11
- Linux kernel 2.6.19
- Linux kernel 2.6.20.2
- Linux kernel 2.6.13 .2
- Linux kernel 2.6.13 .1
- Linux kernel 2.6.13
- Linux kernel 2.4.36.6
- Linux kernel 2.6.26-Rc5-Git1
- Linux kernel 2.6.25.5
- Linux kernel 2.6.12 -Rc1
- Linux kernel 2.6.20.3
- SuSE Open-Enterprise-Server
- Linux kernel 2.6.25.2
- Linux kernel 2.6.22.12
- Linux kernel 2.6.22.13
- Linux kernel 2.6.12 .1
- Linux kernel 2.6.22.15
- Linux kernel 2.6.22.16
- Linux kernel 2.6.22.17
- Red Hat Enterprise MRG v1 for Red Hat Enterprise Linux Version 5
- Linux kernel 2.6.25 .15
- SuSE openSUSE 11.1
- Linux kernel 2.4.21 Pre1
- Avaya Proactive Contact 4.0
- Linux kernel 2.6.24.1
- Red Hat Enterprise Linux Desktop 5 Client
- Ubuntu Ubuntu Linux 6.06 LTS Powerpc
- Ubuntu Ubuntu Linux 6.06 LTS I386
- Ubuntu Ubuntu Linux 6.06 LTS Amd64
- Linux kernel 2.6.21.7
- Linux kernel 2.6.14 -Rc2
- Linux kernel 2.4.21 Pre4
- Linux kernel 2.6.23-Rc2
- Linux kernel 2.6.23-Rc1
- Linux kernel 2.4.29 -Rc2
- Linux kernel 2.6.10
- Avaya Aura Application Enablement Services 4.0.1
- Linux kernel 2.6.15.5
- Linux kernel 2.6.15 .4
- SuSE openSUSE 10.3
- Linux kernel 2.4.33 .3
- Linux kernel 2.6.17.10
- Linux kernel 2.4.33 2
- Linux kernel 2.6.21.2
- Linux kernel 2.6.21 .1
- Linux kernel 2.6.11 .6
- Linux kernel 2.4.30 Rc3
- Linux kernel 2.4.29
- Linux kernel 2.4.36.8
- Linux kernel 2.6.9
- Avaya Aura Session Manager 1.1
- Linux kernel 2.4.30 Rc2
- Linux kernel 2.4.29 -Rc1
- SuSE SUSE Linux Enterprise 10 SP2 DEBUGINFO
- Linux kernel 2.6.11 .5
- Linux kernel 2.6.15.6
- Linux kernel 2.6.27
- Linux kernel 2.6.21.3
- SuSE SUSE Linux Enterprise Desktop 11
- Avaya Communication Manager 5.0
- Linux kernel 2.6.26 -Rc6
- Linux kernel 2.6.26
- Linux kernel 2.4.20
- Linux kernel 2.6.17.7
- Avaya Intuity AUDIX LX 2.0
- Red Hat Enterprise Linux AS 4.8.Z
- Linux kernel 2.4.21
- Linux kernel 2.4.16
- Linux kernel 2.4.17
- Red Hat Enterprise Linux ES 4.8.Z
- Avaya Communication Manager 3.0
- Avaya Meeting Exchange 5.1
- Linux kernel 2.6.24-Rc3
- Linux kernel 2.4.30
- Linux kernel 2.4.36
- Linux kernel 2.4.36.1
- Linux kernel 2.6.22.1
- Linux kernel 2.6.22.2
- SuSE openSUSE 11.0
- Linux kernel 2.6.8
- Linux kernel 2.6.14 -Rc1
- Linux kernel 2.6.14 -Rc3
- Linux kernel 2.6.14 -Rc4
- Linux kernel 2.4.26
- Linux kernel 2.6.5
- Linux kernel 2.6.4
- Linux kernel 2.6.17 .8
- Linux kernel 2.6.17.12
- Linux kernel 2.4.27 -Pre3
- Linux kernel 2.4.27 -Pre4
- Linux kernel 2.4.27 -Pre5
- Linux kernel 2.6.8 Rc1
- Linux kernel 2.6.8 Rc2
- Linux kernel 2.6.8 Rc3
- Red Hat Enterprise Linux 5 Server
- Linux kernel 2.6.20.4
- Linux kernel 2.6.24-Git13
- Linux kernel 2.6.17
- Linux kernel 2.6.17.1
- SuSE Novell Linux Desktop 9.0.0
- Linux kernel 2.4.31
- Linux kernel 2.4.32 -Pre1
- Linux kernel 2.6.13 .3
- Linux kernel 2.6.16.3
- Linux kernel 2.6.11.4
- Linux kernel 2.6.11 .4
- Linux kernel 2.6.12 .12
- Avaya Communication Manager 1.1.0
- Avaya Communication Manager 1.3.1
- Avaya Communication Manager 2.0.0
- Avaya Communication Manager 2.0.1
- Linux kernel 2.6.13 -Rc4
- Linux kernel 2.6.1
- Linux kernel 2.6.24.2
- Linux kernel 2.4.4
- Linux kernel 2.4.6
- Linux kernel 2.4.5
- Linux kernel 2.6.22.3
- Linux kernel 2.6.16.21
- Ubuntu Ubuntu Linux 8.10 Amd64
- Ubuntu Ubuntu Linux 8.10 I386
- Ubuntu Ubuntu Linux 8.10 Lpia
- Ubuntu Ubuntu Linux 8.10 Powerpc
- Ubuntu Ubuntu Linux 8.10 Sparc
- Linux kernel 2.6.18.4
- Linux kernel 2.4.34.5
- Linux kernel 2.6.21 4
- Ubuntu Ubuntu Linux 6.06 LTS Sparc
- Linux kernel 2.6.22.4
- Avaya Aura SIP Enablement Services 5.0
- Debian Linux 5.0 Armel
- Linux kernel 2.6.20.13
- rPath Appliance Platform Linux Service 2
- Linux kernel 2.6.24-Rc5
- Linux kernel 2.6.20
- Linux kernel 2.6.13 .4
Description:
This signature detects SSL access to Zenguard.biz. Zenguard.biz is the backend for the ZenMate anonymizing browser plugin.
Supported On:
srx-branch-11.4, srx-branch-12.1, srx-11.4, mx-11.4, srx-12.1
References:
HTTP:APACHE:STRUTS-OGNL-CMDEXEC - HTTP: Apache Struts OGNL Expression Parsing Arbitrary Command Execution
Severity: HIGH
Description:
This signature detects attempts to exploit a known vulnerability against Apache Struts. Attackers can inject and execute arbitrary commands on the targeted system.
Supported On:
idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, idp-4.2.0, idp-5.0.0, mx-9.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, isg-3.5.0, srx-9.2, srx-branch-9.4, j-series-9.5, idp-4.2.110100823, srx-10.0, srx-branch-10.0, idp-4.2.110101203, idp-5.1.0, idp-4.1.110110609, srx-11.4, srx-branch-11.4, idp-4.1.110110719, mx-11.4, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, isg-3.5.140773, idp-5.1.110140626, isg-3.5.140842, idp-5.1.110140822
References:
Affected Products:
- apache struts 2.0.0
- apache struts 2.0.14
- apache struts 2.3.1
- apache struts 2.0.1
- apache struts 2.2.1
- apache struts 2.0.6
- apache struts 2.3.3
- apache struts 2.0.7
- apache struts 2.2.3
- apache struts 2.0.11.2
- apache struts 2.0.5
- apache struts 2.2.1.1
- apache struts 2.1.8.1
- apache struts 2.1.8
- apache struts 2.0.4
- apache struts 2.0.8
- apache struts 2.0.9
- apache struts 2.1.6
- apache struts 2.3.1.2
- apache struts 2.1.5
- apache struts 2.2.3.1
- apache struts 2.1.4
- apache struts 2.3.8
- apache struts 2.1.3
- apache struts 2.3.14
- apache struts up to 2.3.14.2
- apache struts 2.0.12
- apache struts 2.1.2
- apache struts 2.0.13
- apache struts 2.1.1
- apache struts 2.3.12
- apache struts 2.3.4.1
- apache struts 2.0.10
- apache struts 2.1.0
- apache struts 2.3.1.1
- apache struts 2.0.11
- apache struts 2.3.4
- apache struts 2.0.2
- apache struts 2.0.11.1
- apache struts 2.3.7
- apache struts 2.0.3
- apache struts 2.3.14.1
HTTP:DIR:NOVELL-GROUPWSE-DIRTRA - HTTP: Novell GroupWise Admin Service FileUploadServlet Directory Traversal
Severity: HIGH
Description:
This signature detects directory traversal attempts in Administration Service of Novell GroupWise 2014.A successful attack can lead to gain access to restricted files. This may lead to disclosure of sensitive information.
Supported On:
idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, idp-4.2.0, idp-5.0.0, mx-9.4, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, isg-3.5.0, srx-9.2, srx-branch-9.4, j-series-9.5, idp-4.2.110100823, srx-10.0, srx-branch-10.0, idp-4.2.110101203, idp-5.1.0, idp-4.1.110110609, srx-11.4, srx-branch-11.4, idp-4.1.110110719, mx-11.4, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, isg-3.5.140773, idp-5.1.110140626, isg-3.5.140842, idp-5.1.110140822
References:
APP:SQUID-SNMPHANDLEUDP-CE - APP: Squid snmpHandleUdp Off-by-one Buffer Overflow
Severity: HIGH
Description:
This signature detects attempts to exploit a known vulnerability against Squid. A successful attack can lead to arbitrary code execution.
Supported On:
idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, idp-4.2.0, idp-5.0.0, mx-9.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, isg-3.5.0, srx-9.2, srx-branch-9.4, j-series-9.5, idp-4.2.110100823, srx-10.0, srx-branch-10.0, idp-4.2.110101203, idp-5.1.0, idp-4.1.110110609, srx-11.4, srx-branch-11.4, idp-4.1.110110719, mx-11.4, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, isg-3.5.140773, idp-5.1.110140626, isg-3.5.140842, idp-5.1.110140822
References:
Severity: HIGH
Description:
This signature detects attempts to exploit a known vulnerability against Windows Movie Maker 5.1. A successful attack can result in a denial of service condition.
Supported On:
idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, idp-4.2.0, idp-5.0.0, mx-9.4, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, isg-3.5.0, srx-9.2, srx-branch-9.4, j-series-9.5, idp-4.2.110100823, srx-10.0, srx-branch-10.0, idp-4.2.110101203, idp-5.1.0, idp-4.1.110110609, srx-11.4, srx-branch-11.4, idp-4.1.110110719, mx-11.4, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, isg-3.5.140773, idp-5.1.110140626, isg-3.5.140842, idp-5.1.110140822
HTTP:DLINK-CMD-RCE - HTTP: D-Link Multiple Router Cmd Parameter Remote Command Execution
Severity: HIGH
Description:
This signature detects attempts to exploit a known vulnerability against D-LINK Multiple Router. A successful attack can lead to arbitrary Command execution.
Supported On:
idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, idp-4.2.0, idp-5.0.0, mx-9.4, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, isg-3.5.0, srx-9.2, srx-branch-9.4, j-series-9.5, idp-4.2.110100823, srx-10.0, srx-branch-10.0, idp-4.2.110101203, idp-5.1.0, idp-4.1.110110609, srx-11.4, srx-branch-11.4, idp-4.1.110110719, mx-11.4, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, isg-3.5.140773, idp-5.1.110140626, isg-3.5.140842, idp-5.1.110140822
References:
Severity: MEDIUM
Description:
This signature detects attempts to exploit a known vulnerability against Mozilla Firefox. A successful attack could allow the attacker to spoof legitimate websites.
Supported On:
idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, idp-4.2.0, idp-5.0.0, mx-9.4, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, isg-3.5.0, srx-9.2, srx-branch-9.4, j-series-9.5, idp-4.2.110100823, srx-10.0, srx-branch-10.0, idp-4.2.110101203, idp-5.1.0, idp-4.1.110110609, srx-11.4, srx-branch-11.4, idp-4.1.110110719, mx-11.4, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, isg-3.5.140773, idp-5.1.110140626, isg-3.5.140842, idp-5.1.110140822
References:
Affected Products:
- Mozilla Firefox 1.5.0.1
- Mozilla Firefox 1.5.0 Beta 1
- Mozilla Firefox 0.9.0
- Mozilla Firefox 0.9.1
- Mozilla Firefox 1.5.0.5
- Mozilla Firefox 1.5.0.3
- Mozilla Firefox 1.0.7
- Mozilla Firefox 1.5.0.4
- Mozilla Firefox 0.10.1
- Mozilla Firefox 1.5.0.6
- Mozilla Firefox 1.0.3
- Mozilla Firefox 1.0.6
- Mozilla Firefox 1.0.2
- Mozilla Firefox 1.0.5
- Mozilla Firefox 1.0.0
- Mozilla Firefox 1.5.0.7
- Mozilla Firefox 1.5.0.8
- Mozilla Firefox 1.0.1
- Mozilla Firefox 0.9.3
- Mozilla Firefox 1.5.0 Beta 2
- Mozilla Firefox 2.0.0.1
- Mozilla Firefox 1.5.0.9
- Mozilla Firefox 0.8.0
- Mozilla Firefox 1.5.0
- Mozilla Firefox 0.10.0
- Mozilla Firefox 2.0
- Mozilla Firefox 0.9.2
- Mozilla Firefox 0.9.0 Rc
- Mozilla Firefox 1.5.0.2
- Mozilla Firefox 1.0.8
- Mozilla Firefox 1.0.4
Severity: MEDIUM
Description:
This signature detects attempts to exploit a known vulnerability against Mozilla Firefox OnKeyDown. A successful attack can lead to the upload of an arbitrary file.
Supported On:
idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, idp-4.2.0, idp-5.0.0, mx-9.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, isg-3.5.0, srx-9.2, srx-branch-9.4, j-series-9.5, idp-4.2.110100823, srx-10.0, srx-branch-10.0, idp-4.2.110101203, idp-5.1.0, idp-4.1.110110609, srx-11.4, srx-branch-11.4, idp-4.1.110110719, mx-11.4, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, isg-3.5.140773, idp-5.1.110140626, isg-3.5.140842, idp-5.1.110140822
References:
Affected Products:
- SuSE Linux Personal 10.1
- SuSE Linux Professional 10.1
- Sun Solaris 10 Sparc
- Red Hat Enterprise Linux Desktop 5 Client
- Ubuntu Ubuntu Linux 6.06 LTS Powerpc
- Red Hat Enterprise Linux Optional Productivity Application 5 Server
- Ubuntu Ubuntu Linux 6.06 LTS Amd64
- SuSE Novell Linux POS 9
- Mozilla Firefox 2.0 Beta 1
- Red Hat Desktop 4.0.0
- Red Hat Enterprise Linux ES 3
- Slackware Linux 10.2.0
- SuSE UnitedLinux 1.0.0
- SuSE SuSE Linux School Server for i386
- Red Hat Desktop 3.0.0
- SuSE Linux Personal 10.2
- SuSE Linux Personal 10.2 X86 64
- SuSE Linux Professional 10.2 X86 64
- SuSE Linux Professional 10.2
- Ubuntu Ubuntu Linux 6.10 Amd64
- Ubuntu Ubuntu Linux 6.10 I386
- Ubuntu Ubuntu Linux 6.10 Powerpc
- Ubuntu Ubuntu Linux 6.10 Sparc
- SuSE Linux Professional 10.0.0 OSS
- SuSE Linux Personal 10.0.0 OSS
- Debian Iceweasel
- SuSE openSUSE 10.3
- SuSE Linux 10.1 X86
- SuSE Linux 10.1 X86-64
- SuSE Linux 10.1 Ppc
- SuSE Linux 10.0 Ppc
- SuSE Linux 10.0 X86
- SuSE Linux 10.0 X86-64
- SuSE SUSE Linux Enterprise Server 8
- Mozilla Firefox 1.5.0
- Mozilla SeaMonkey 1.0.99
- Mozilla Firefox 2.0.0.5
- Mandriva Corporate Server 4.0.0 X86 64
- Ubuntu Ubuntu Linux 6.06 LTS I386
- SuSE Open-Enterprise-Server
- Mozilla Firefox 1.5.0.5
- Mozilla SeaMonkey 1.0.3
- Mozilla Firefox 2.0.0.7
- Mandriva Linux Mandrake 2008.0
- Mandriva Linux Mandrake 2008.0 X86 64
- Red Hat Fedora 7
- Ubuntu Ubuntu Linux 7.10 I386
- Ubuntu Ubuntu Linux 7.10 Powerpc
- SuSE SUSE LINUX Retail Solution 8.0.0
- Avaya Intuity AUDIX LX 2.0
- Mozilla SeaMonkey 1.1.3
- Mozilla Firefox 2.0 RC2
- Mozilla Firefox 2.0 RC3
- Mozilla Firefox 1.5.0.2
- Mozilla Firefox 1.5.0.6
- Mozilla SeaMonkey 1.0.6
- Mozilla Firefox 1.5.0 Beta 2
- Red Hat Enterprise Linux AS 2.1
- Red Hat Enterprise Linux ES 2.1
- Red Hat Enterprise Linux WS 2.1
- Mozilla Firefox 2.0.0.2
- Mozilla SeaMonkey 1.0.8
- Mozilla Firefox 2.0.0.3
- Mozilla Firefox 1.5.0.11
- Mozilla Firefox 2.0.0.4
- Mozilla Firefox 1.5.0 Beta 1
- Mozilla SeaMonkey 1.0.9
- Mozilla SeaMonkey 1.1.2
- Avaya Messaging Storage Server 3.1
- Avaya Message Networking 3.1
- Mozilla Firefox 1.5.0.1
- Ubuntu Ubuntu Linux 7.10 Sparc
- Red Hat Enterprise Linux AS 3
- Sun Solaris 10 X86
- Red Hat Enterprise Linux WS 3
- Mozilla SeaMonkey 1.0
- rPath rPath Linux 1
- Mozilla Firefox 1.5.0.3
- Mozilla SeaMonkey 1.0.2
- Mozilla Firefox 1.5.0.10
- SuSE SuSE Linux Openexchange Server 4.0.0
- SuSE SuSE Linux Standard Server 8.0.0
- Mozilla SeaMonkey 1.1.1
- Mandriva Corporate Server 4.0
- Red Hat Enterprise Linux Desktop Workstation 5 Client
- Red Hat Enterprise Linux 5 Server
- Mozilla SeaMonkey 1.1 Beta
- Debian Iceape 1.0.11
- Slackware Linux 12.0
- Ubuntu Ubuntu Linux 7.04 Amd64
- Ubuntu Ubuntu Linux 7.04 I386
- Ubuntu Ubuntu Linux 7.04 Powerpc
- Ubuntu Ubuntu Linux 7.04 Sparc
- SuSE Novell Linux Desktop 9.0.0
- Mandriva Corporate Server 3.0.0
- SuSE openSUSE 10.2
- Mozilla Firefox 2.0
- Ubuntu Ubuntu Linux 7.10 Amd64
- Debian Linux 4.0 Alpha
- Debian Linux 4.0 Amd64
- Debian Linux 4.0 Arm
- Debian Linux 4.0 Hppa
- Debian Linux 4.0 Ia-32
- Debian Linux 4.0 Ia-64
- Debian Linux 4.0 M68k
- Debian Linux 4.0 Mips
- Debian Linux 4.0 Mipsel
- Debian Linux 4.0 Powerpc
- Debian Linux 4.0 S/390
- Debian Linux 4.0 Sparc
- Debian Linux 4.0
- Mozilla SeaMonkey 1.0 Dev
- Mozilla Firefox 1.5.0 12
- Mozilla Firefox 1.5.0.4
- Mozilla Firefox 2.0.0.6
- Mozilla SeaMonkey 1.1.4
- Avaya Messaging Storage Server MM3.0
- Foresight Linux 1.1
- SuSE SUSE Linux Enterprise Server 9
- Red Hat Advanced Workstation for the Itanium Processor 2.1.0
- Red Hat Enterprise Linux AS 4
- Red Hat Enterprise Linux ES 4
- Red Hat Enterprise Linux WS 4
- Red Hat Enterprise Linux Desktop Version 4
- Red Hat Fedora Core6
- Avaya Message Networking MN 3.1
- Mozilla SeaMonkey 1.0.1
- Mandriva Linux Mandrake 2007.1
- Slackware Linux 11.0
- Mozilla Firefox 1.5.0.7
- Mozilla SeaMonkey 1.0.5
- Slackware Linux -Current
- Mozilla Firefox 1.5.0.8
- Ubuntu Ubuntu Linux 6.06 LTS Sparc
- SuSE SUSE Linux Enterprise Desktop 10 SP1
- SuSE SUSE Linux Enterprise Server 10 SP1
- Mandriva Corporate Server 3.0.0 X86 64
- Mandriva Linux Mandrake 2007.1 X86 64
- Mozilla Firefox 2.0.0.1
- Mozilla Firefox 1.5.0.9
- Mozilla SeaMonkey 1.0.7
- SuSE Linux Professional 10.0.0
HTTP:STC:MOZILLA:LOCATION-HOST - HTTP: Mozilla Firefox Location.Hostname Dom Property Cookie Theft
Severity: MEDIUM
Description:
This signature detects attempts to exploit a known vulnerability against Mozilla Firefox Location.Hostname. A successful attack can lead to unauthorized information disclosure.
Supported On:
idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, idp-4.2.0, idp-5.0.0, mx-9.4, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, isg-3.5.0, srx-9.2, srx-branch-9.4, j-series-9.5, idp-4.2.110100823, srx-10.0, srx-branch-10.0, idp-4.2.110101203, idp-5.1.0, idp-4.1.110110609, srx-11.4, srx-branch-11.4, idp-4.1.110110719, mx-11.4, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, isg-3.5.140773, idp-5.1.110140626, isg-3.5.140842, idp-5.1.110140822
References:
Affected Products:
- Avaya Messaging Storage Server 1.0
- Avaya Messaging Storage Server 2.0
- Avaya Messaging Storage Server
- Red Hat Enterprise Linux Desktop 5 Client
- Red Hat Enterprise Linux Optional Productivity Application 5 Server
- SuSE Novell Linux POS 9
- Mozilla Firefox 2.0 Beta 1
- Slackware Linux 10.2.0
- Gentoo Linux
- Mozilla Firefox 1.0.3
- Mozilla Firefox 1.0.2
- SuSE UnitedLinux 1.0.0
- SuSE SuSE Linux School Server for i386
- Red Hat Desktop 3.0.0
- Ubuntu Ubuntu Linux 6.10 Amd64
- Ubuntu Ubuntu Linux 6.10 I386
- Ubuntu Ubuntu Linux 6.10 Powerpc
- Ubuntu Ubuntu Linux 6.10 Sparc
- Turbolinux Turbolinux Server 10.0.0 X64
- Mozilla Camino 0.7.0 .0
- Mozilla Camino 1.0.3
- Mozilla Camino 0.8.0
- SuSE Linux 10.1 X86
- SuSE Linux 10.0 X86
- Red Hat Desktop 4.0.0
- SuSE Linux 9.3 X86
- SuSE SUSE Linux Enterprise Server 8
- Mozilla Firefox 1.5.0
- Mandriva Corporate Server 4.0.0 X86 64
- Red Hat Enterprise Linux WS 2.1 IA64
- Turbolinux 10 F...
- Red Hat Enterprise Linux ES 2.1 IA64
- SuSE Open-Enterprise-Server
- Mozilla Firefox 1.5.0.5
- Mozilla SeaMonkey 1.0.3
- Turbolinux Multimedia
- Turbolinux Personal
- Mozilla Firefox 1.0.6
- Mozilla Firefox 1.0.0
- Mozilla Firefox 2.0 RC2
- Mozilla Firefox 2.0 RC3
- Mozilla SeaMonkey 1.0.6
- Mozilla Firefox 1.5.0 Beta 2
- Red Hat Enterprise Linux AS 2.1 IA64
- Red Hat Enterprise Linux AS 2.1
- Debian Linux 3.1.0 Amd64
- Red Hat Enterprise Linux WS 2.1
- Debian Linux 3.1.0 Alpha
- Debian Linux 3.1.0 Arm
- Debian Linux 3.1.0 Hppa
- Debian Linux 3.1.0 Ia-32
- Debian Linux 3.1.0 Ia-64
- Debian Linux 3.1.0 M68k
- Debian Linux 3.1.0 Mips
- Debian Linux 3.1.0 Mipsel
- Debian Linux 3.1.0 Ppc
- Debian Linux 3.1.0 S/390
- Debian Linux 3.1.0 Sparc
- Mozilla Firefox 1.5.0 Beta 1
- Mozilla Firefox 1.0.1
- Red Hat Advanced Workstation for the Itanium Processor 2.1.0 IA64
- Red Hat Enterprise Linux AS 3
- Red Hat Enterprise Linux ES 3
- Red Hat Enterprise Linux WS 3
- Mozilla SeaMonkey 1.0
- rPath rPath Linux 1
- Mozilla Firefox 1.5.0.3
- Turbolinux Turbolinux Server 10.0.0 X86
- Turbolinux FUJI
- Red Hat Enterprise Linux ES 2.1
- HP HP-UX B.11.11
- SuSE SuSE Linux Openexchange Server 4.0.0
- SuSE SUSE LINUX Retail Solution 8.0.0
- SuSE SuSE Linux Standard Server 8.0.0
- Mozilla Firefox 1.5.0.6
- Mozilla SeaMonkey 1.0.7
- Mandriva Corporate Server 4.0
- Mandriva Linux Mandrake 2007.0
- Mandriva Corporate Server 3.0.0
- Red Hat Enterprise Linux 5 Server
- SuSE Novell Linux Desktop 9.0.0
- Red Hat Enterprise Linux Desktop Workstation 5 Client
- HP HP-UX B.11.23
- Mozilla Camino 0.8.3
- SuSE openSUSE 10.2
- Mozilla Firefox 2.0
- SGI ProPack 3.0.0 SP6
- Mozilla Camino 1.0.1
- Mozilla Camino 1.0.2
- Mozilla Firefox 1.5.0.2
- Mozilla Firefox 1.0.8
- Turbolinux Home
- Mozilla SeaMonkey 1.0.1
- Mozilla Firefox 1.5.0.1
- Red Hat Fedora Core5
- Mozilla SeaMonkey 1.0 Dev
- Mozilla SeaMonkey 1.0.2
- Mozilla Firefox 1.5.0.4
- Mozilla Camino 1.0
- Mozilla Firefox 1.0.7
- Avaya Messaging Storage Server MM3.0
- Turbolinux Turbolinux Desktop 10.0.0
- SuSE SUSE Linux Enterprise Server 9
- Red Hat Advanced Workstation for the Itanium Processor 2.1.0
- Ubuntu Ubuntu Linux 5.10.0 Amd64
- Ubuntu Ubuntu Linux 5.10.0 I386
- Ubuntu Ubuntu Linux 5.10.0 Powerpc
- Red Hat Enterprise Linux AS 4
- Red Hat Enterprise Linux ES 4
- Red Hat Enterprise Linux WS 4
- Debian Linux 3.1.0
- Red Hat Fedora Core6
- Mozilla Firefox 1.0.5
- Slackware Linux 11.0
- Mozilla Firefox 1.5.0.7
- Mozilla SeaMonkey 1.0.5
- Mandriva Linux Mandrake 2007.0 X86 64
- Mozilla Firefox 1.5.0.8
- Ubuntu Ubuntu Linux 5.10.0 Sparc
- Turbolinux Turbolinux Server 10.0.0
- Mandriva Corporate Server 3.0.0 X86 64
- Mozilla Firefox 2.0.0.1
- Mozilla Firefox 1.5.0.9
- Mozilla Camino 1.5
- Mozilla Firefox 1.0.4
- Mozilla Camino 0.8.4
Severity: HIGH
Description:
This signature detects attempts to exploit a known vulnerability against UpTime Monitoring. A successful attack can lead to arbitrary code execution.
Supported On:
idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, idp-4.2.0, idp-5.0.0, mx-9.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, isg-3.5.0, srx-9.2, srx-branch-9.4, j-series-9.5, idp-4.2.110100823, srx-10.0, srx-branch-10.0, idp-4.2.110101203, idp-5.1.0, idp-4.1.110110609, srx-11.4, srx-branch-11.4, idp-4.1.110110719, mx-11.4, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, isg-3.5.140773, idp-5.1.110140626, isg-3.5.140842, idp-5.1.110140822
References:
APP:MISC:SIMENS-GIGAST-DOS - APP: Siemens Gigaset SE361 WLAN Data Flood Denial of Service
Severity: MEDIUM
Description:
This signature detects attempts to exploit a known vulnerability against Siemens Gigaset SE361 WLAN Router. A successful attack can result in a denial of service condition.
Supported On:
idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, idp-4.2.0, idp-5.0.0, mx-9.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, isg-3.5.0, srx-9.2, srx-branch-9.4, j-series-9.5, idp-4.2.110100823, srx-10.0, srx-branch-10.0, idp-4.2.110101203, idp-5.1.0, idp-4.1.110110609, srx-11.4, srx-branch-11.4, idp-4.1.110110719, mx-11.4, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, isg-3.5.140773, idp-5.1.110140626, isg-3.5.140842, idp-5.1.110140822
References:
Affected Products:
- Siemens Siemens Gigaset SE361 WLAN
Severity: HIGH
Description:
This signature detects attempts to exploit a known vulnerability against Adobe Flash Player. A successful attack can lead to memory corruption and arbitrary code execution.
Supported On:
srx-branch-11.4, mx-11.4, idp-4.1.0, mx-9.4, srx-9.2, srx-branch-9.4, j-series-9.5, srx-12.1, srx-branch-12.1, srx-10.0, srx-branch-10.0, vsrx-12.1, isg-3.5.140773, idp-5.1.110140626, isg-3.5.140842, idp-5.1.110140822, srx-11.4
References:
Severity: HIGH
Description:
This signature detects attempts to exploit a known flaw in Adobe Reader. An attacker can entice a user to load a malicious file which can result in sandbox bypass, possibly leading to further attacks.
Supported On:
idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, idp-4.2.0, idp-5.0.0, mx-9.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, isg-3.5.0, srx-9.2, srx-branch-9.4, j-series-9.5, idp-4.2.110100823, srx-10.0, srx-branch-10.0, idp-4.2.110101203, idp-5.1.0, idp-4.1.110110609, srx-11.4, srx-branch-11.4, idp-4.1.110110719, mx-11.4, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, isg-3.5.140773, idp-5.1.110140626, isg-3.5.140842, idp-5.1.110140822
References:
HTTP:STC:NDROID-BROW-SAME-ORIGN - HTTP: Android Browser URL Parser NULL-byte Handling Same Origin Policy Bypass
Severity: HIGH
Description:
This signature detects attempts to exploit a known vulnerability against Google Android Browser. An attacker can exploit this vulnerability by enticing a user to open a web page. Successful exploitation can result in disclosure of information about other web pages opened by the user or stored in the browser cache.
Supported On:
idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, idp-4.2.0, idp-5.0.0, mx-9.4, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, isg-3.5.0, srx-9.2, srx-branch-9.4, j-series-9.5, idp-4.2.110100823, srx-10.0, srx-branch-10.0, idp-4.2.110101203, idp-5.1.0, idp-4.1.110110609, srx-11.4, srx-branch-11.4, idp-4.1.110110719, mx-11.4, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, isg-3.5.140773, idp-5.1.110140626, isg-3.5.140842, idp-5.1.110140822
References:
SCADA:EKTRON-CMS-XSLT-RCE - SCADA: Ektron CMS XslCompiledTransform Class Remote Code Execution
Severity: HIGH
Description:
This signature detects attempts to exploit a known vulnerability against Ektron CMS. A successful attack can lead to arbitrary code execution.
Supported On:
idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, idp-4.2.0, idp-5.0.0, mx-9.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, isg-3.5.0, srx-9.2, srx-branch-9.4, j-series-9.5, idp-4.2.110100823, srx-10.0, srx-branch-10.0, idp-4.2.110101203, idp-5.1.0, idp-4.1.110110609, srx-11.4, srx-branch-11.4, idp-4.1.110110719, mx-11.4, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, isg-3.5.140773, idp-5.1.110140626, isg-3.5.140842, idp-5.1.110140822
References:
APP:MISC:DSM-SLICEUPLOAD-RCE - APP: Synology DiskStation Manager SliceUpload Functionality Remote Command Execution
Severity: HIGH
Description:
This signature detects attempts to exploit a known vulnerability against Synology DiskStation Manager. A successful attack can lead to arbitrary command execution.
Supported On:
idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, idp-4.2.0, idp-5.0.0, mx-9.4, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, isg-3.5.0, srx-9.2, srx-branch-9.4, j-series-9.5, idp-4.2.110100823, srx-10.0, srx-branch-10.0, idp-4.2.110101203, idp-5.1.0, idp-4.1.110110609, srx-11.4, srx-branch-11.4, idp-4.1.110110719, mx-11.4, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, isg-3.5.140773, idp-5.1.110140626, isg-3.5.140842, idp-5.1.110140822
References:
Affected Products:
- synology diskstation_manager 4.3-3810
- synology diskstation_manager 4.2
- synology diskstation_manager 4.3
- synology diskstation_manager 4.0
Severity: HIGH
Description:
This signature detects attempts to exploit a known vulnerability in Adobe Acrobat software. Attackers can send malicious PDF files through SMTP communication channel to victims or direct them to a hostile Web server, which if the victim interacts with these files or servers, can result in remote code execution on the victim's system.
Supported On:
idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, idp-4.2.0, idp-5.0.0, mx-9.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, isg-3.5.0, srx-9.2, srx-branch-9.4, j-series-9.5, idp-4.2.110100823, srx-10.0, srx-branch-10.0, idp-4.2.110101203, idp-5.1.0, idp-4.1.110110609, srx-11.4, srx-branch-11.4, idp-4.1.110110719, mx-11.4, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, isg-3.5.140773, idp-5.1.110140626, isg-3.5.140842, idp-5.1.110140822
References:
Affected Products:
- Red Hat Desktop Extras 4
- Red Hat Desktop Extras 3
- Adobe Acrobat Professional 9
- Adobe Acrobat Professional 9.1.3
- Adobe Acrobat 7.0.9
- Adobe Acrobat 9.1.1
- Red Hat Enterprise Linux Extras 3
- Red Hat Enterprise Linux Extras 4
- Red Hat Enterprise Linux Supplementary 5 Server
- Adobe Acrobat Professional 9.1
- Adobe Acrobat Standard 9.1
- Adobe Acrobat Professional 8.1.4
- SuSE openSUSE 11.0
- Adobe Acrobat Standard 9.1.2
- Adobe Acrobat Professional 8.1.6
- Adobe Reader 9.1.2
- Adobe Acrobat Professional 9.1.2
- Adobe Acrobat Standard 8.1.6
- Adobe Reader 8.1.6
- Nortel Networks Self-Service MPS 500
- Nortel Networks Self-Service MPS 1000
- SuSE SUSE Linux Enterprise 10 SP2
- Nortel Networks Self-Service Speech Server
- Adobe Acrobat Standard 8.1.4
- Nortel Networks CallPilot 1005R
- Nortel Networks CallPilot 600R
- Adobe Reader 9.1.3
- SuSE SUSE Linux Enterprise Desktop 11
- Nortel Networks CallPilot 703T
- Adobe Reader 8.1.5
- Nortel Networks CallPilot 1002Rp
- Nortel Networks CallPilot 200I
- Red Hat Enterprise Linux Desktop Supplementary 5 Client
- Adobe Acrobat Professional 8.1.7
- Nortel Networks Self-Service Peri Application
- Adobe Acrobat Standard 9
- Adobe Reader 8.1
- Adobe Acrobat Professional 8.1
- Adobe Acrobat Standard 8.1
- Adobe Reader 7.0.9
- Adobe Acrobat Standard 8.1.7
- Adobe Reader 8.1.4
- Adobe Acrobat Standard 8.1.3
- Red Hat Enterprise Linux AS Extras 3
- Adobe Acrobat Standard 8.1.1
- Nortel Networks CallPilot 201I
- Adobe Acrobat Standard 8.1.2
- Adobe Acrobat Professional 8.1.2
- Adobe Reader 8.1.3
- Adobe Reader 9
- Adobe Reader 9.2
- Adobe Acrobat Professional 9.2
- Adobe Acrobat Standard 9.2
- Adobe Reader 8.0
- Adobe Acrobat Standard 9.1.3
- Adobe Acrobat Standard 8.0
- Adobe Reader 8.1.7
- Adobe Acrobat Professional 8.1.3
- Red Hat Enterprise Linux ES Extras 3
- Adobe Reader 9.1.1
- Adobe Acrobat Professional 8.0
- Adobe Reader 9.1
- Red Hat Enterprise Linux WS Extras 4
- Adobe Reader 6.0.1
- SuSE SUSE Linux Enterprise 10 SP3
- Adobe Acrobat 6.0.1
- Red Hat Enterprise Linux ES Extras 4
- SuSE openSUSE 11.2
- Nortel Networks Self-Service Media Processing Server
- SuSE openSUSE 11.1
- Adobe Reader 8.1.1
- Adobe Acrobat Professional 8.1.1
- Red Hat Enterprise Linux WS Extras 3
- Adobe Acrobat 9.2
- Adobe Reader 8.1.2
- Red Hat Enterprise Linux AS Extras 4
Severity: HIGH
Description:
This signature detects attempts to exploit a known vulnerability against Adobe Reader. A successful attack can lead to arbitrary code execution.
Supported On:
srx-branch-11.4, mx-11.4, idp-4.1.0, mx-9.4, srx-9.2, srx-branch-9.4, j-series-9.5, srx-12.1, srx-branch-12.1, srx-10.0, srx-branch-10.0, vsrx-12.1, isg-3.5.140773, idp-5.1.110140626, isg-3.5.140842, idp-5.1.110140822, srx-11.4
References:
Severity: MEDIUM
Description:
Mambo CMS is prone to a password disclosure vulnerability. Local attackers can exploit this issue to disclose sensitive information.
Supported On:
idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, idp-4.2.0, idp-5.0.0, mx-9.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, isg-3.5.0, srx-9.2, srx-branch-9.4, j-series-9.5, idp-4.2.110100823, srx-10.0, srx-branch-10.0, idp-4.2.110101203, idp-5.1.0, idp-4.1.110110609, srx-11.4, srx-branch-11.4, idp-4.1.110110719, mx-11.4, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, isg-3.5.140773, idp-5.1.110140626, isg-3.5.140842, idp-5.1.110140822
References:
Severity: MEDIUM
Description:
This signature detects attempts to exploit a known vulnerability against IOServer. A successful attack can lead to unauthorized information disclosure and loss of sensitive information.
Supported On:
idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, idp-4.2.0, idp-5.0.0, mx-9.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, isg-3.5.0, srx-9.2, srx-branch-9.4, j-series-9.5, idp-4.2.110100823, srx-10.0, srx-branch-10.0, idp-4.2.110101203, idp-5.1.0, idp-4.1.110110609, srx-11.4, srx-branch-11.4, idp-4.1.110110719, mx-11.4, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, isg-3.5.140773, idp-5.1.110140626, isg-3.5.140842, idp-5.1.110140822
References:
Severity: MEDIUM
Description:
This signature detects attempts to send commands to the Apache Tomcat AJP12 Connector process. This process has no authentication and can be used to shut down the Web-server.
Supported On:
idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, idp-4.2.0, idp-5.0.0, mx-9.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, isg-3.5.0, srx-9.2, srx-branch-9.4, j-series-9.5, idp-4.2.110100823, srx-10.0, srx-branch-10.0, idp-4.2.110101203, idp-5.1.0, idp-4.1.110110609, srx-11.4, srx-branch-11.4, idp-4.1.110110719, mx-11.4, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, isg-3.5.140773, idp-5.1.110140626, isg-3.5.140842, idp-5.1.110140822
References:
Affected Products:
- Sun Solaris 9 X86
- Apache Software Foundation Tomcat 4.0.6
- Apache Software Foundation Tomcat 4.0.1
- Apache Software Foundation Tomcat 4.0.0
- Sun Solaris 10 Sparc
- Apache Software Foundation Tomcat 4.0.4
- Apache Software Foundation Tomcat 4.0.5
- Apache Software Foundation Tomcat 4.0.3
- Apache Software Foundation Tomcat 4.0.2
- Sun Solaris 9 Sparc
- Sun Solaris 10 X86
Severity: HIGH
Description:
This signature detects attempts to exploit a known vulnerability in the SENKAS Kolibri Webserver 2.0. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the SENKAS Kolibri Webserver 2.0
Supported On:
idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, idp-4.2.0, idp-5.0.0, mx-9.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, isg-3.5.0, srx-9.2, srx-branch-9.4, j-series-9.5, idp-4.2.110100823, srx-10.0, srx-branch-10.0, idp-4.2.110101203, idp-5.1.0, idp-4.1.110110609, srx-11.4, srx-branch-11.4, idp-4.1.110110719, mx-11.4, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, isg-3.5.140773, idp-5.1.110140626, isg-3.5.140842, idp-5.1.110140822
References:
Severity: CRITICAL
Description:
This signature detects attempts to exploit a known vulnerability against GNU Bash in HTTP URL. A successful attack can lead to arbitrary code execution.
Supported On:
DI-Base, DI-Server, idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, idp-4.2.0, idp-5.0.0, mx-9.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, isg-3.5.0, srx-9.2, srx-branch-9.4, j-series-9.5, idp-4.2.110100823, srx-10.0, srx-branch-10.0, idp-4.2.110101203, idp-5.1.0, idp-4.1.110110609, srx-11.4, srx-branch-11.4, idp-4.1.110110719, mx-11.4, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, isg-3.5.140773, idp-5.1.110140626, isg-3.5.140842, idp-5.1.110140822
References:
Severity: CRITICAL
Description:
This signature detects attempts to exploit a known vulnerability against GNU Bash in HTTP Header. A successful attack can lead to arbitrary code execution.
Supported On:
DI-Base, DI-Server, idp-4.0.0, idp-4.0.110090709, idp-4.0.110090831, idp-4.1.0, idp-4.2.0, idp-5.0.0, mx-9.4, isg-3.0.0, isg-3.1.134269, isg-3.1.135801, isg-3.4.0, isg-3.5.0, srx-9.2, srx-branch-9.4, j-series-9.5, idp-4.2.110100823, srx-10.0, srx-branch-10.0, idp-4.2.110101203, idp-5.1.0, idp-4.1.110110609, srx-11.4, srx-branch-11.4, idp-4.1.110110719, mx-11.4, isg-3.4.139899, idp-5.0.110121210, srx-12.1, srx-branch-12.1, isg-3.4.140032, idp-5.0.110130325, vsrx-12.1, isg-3.5.140773, idp-5.1.110140626, isg-3.5.140842, idp-5.1.110140822
References: