<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IE Action Handler Overflow in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ie-action-handler-overflow/m-p/557567#M90222</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just waiting on the tuned sig - I hope, I hope, I hope. If it doesn't come soon, we'll have to filter it or turn it off.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 23 Mar 2006 19:07:58 GMT</pubDate>
    <dc:creator>hendetl</dc:creator>
    <dc:date>2006-03-23T19:07:58Z</dc:date>
    <item>
      <title>IE Action Handler Overflow</title>
      <link>https://community.cisco.com/t5/network-security/ie-action-handler-overflow/m-p/557566#M90221</link>
      <description>&lt;P&gt;Has anyone else been seeing large occurences of this signature from what appears to be normal web application/browsing activity? No further tuning of the sig has been performed. &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:56:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ie-action-handler-overflow/m-p/557566#M90221</guid>
      <dc:creator>mcartoz33</dc:creator>
      <dc:date>2019-03-10T09:56:45Z</dc:date>
    </item>
    <item>
      <title>Re: IE Action Handler Overflow</title>
      <link>https://community.cisco.com/t5/network-security/ie-action-handler-overflow/m-p/557567#M90222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just waiting on the tuned sig - I hope, I hope, I hope. If it doesn't come soon, we'll have to filter it or turn it off.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Mar 2006 19:07:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ie-action-handler-overflow/m-p/557567#M90222</guid>
      <dc:creator>hendetl</dc:creator>
      <dc:date>2006-03-23T19:07:58Z</dc:date>
    </item>
    <item>
      <title>Re: IE Action Handler Overflow</title>
      <link>https://community.cisco.com/t5/network-security/ie-action-handler-overflow/m-p/557568#M90223</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you are seeing that signature firing, that means you or your users are browsing a web page including more than 2000 script action handlers.&lt;/P&gt;&lt;P&gt;That is possible but shouldn't be so common. I'd suggest to increase the Event Count value to something bigger.&lt;/P&gt;&lt;P&gt;The risk in this case would be to miss a real attack. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 Mar 2006 15:36:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ie-action-handler-overflow/m-p/557568#M90223</guid>
      <dc:creator>jdal</dc:creator>
      <dc:date>2006-03-24T15:36:48Z</dc:date>
    </item>
  </channel>
</rss>

