Unable to send or receive email with Plesk Email Security extension installed
This is a Plesk Email Security product issue with ID #EXTPLESK-10075. The issue was fixed in Plesk Email Security 1.5.23
VulnWatch اطلاعات آسیبپذیری، امتیازها، نسخههای درگیر، راهکارها و دستورهای منتشرشده را از منابعی که در سامانه معرفی شدهاند گردآوری و برای دسترسی سادهتر نمایش میدهد. VulnWatch تولیدکننده یا مرجع اصلی این اطلاعات نیست.
ممکن است اطلاعات یک منبع ناقص، با تأخیر، تغییرکرده یا متناسب با محیط شما نباشد. VulnWatch صحت، کاملبودن، بهروز بودن یا نتیجه اجرای اطلاعات و دستورهای استخراجشده را تضمین نمیکند و مسئولیتی در قبال تصمیم، تغییر، اختلال یا خسارتی که صرفاً بر پایه این اطلاعات انجام شود نمیپذیرد.
پیش از نصب بهروزرسانی، اجرای دستور، تغییر تنظیمات یا هر اقدام عملیاتی، منبع اصلی را باز کنید، نسخه و محصول خود را تطبیق دهید، از اطلاعات مهم نسخه پشتیبان داشته باشید و تغییر را در محیط مناسب ارزیابی کنید.
آسیبپذیریها را بر اساس دستهبندی، سازنده، محصول، CVE، شدت، EPSS، اولویت و منبع پیدا کنید.
This is a Plesk Email Security product issue with ID #EXTPLESK-10075. The issue was fixed in Plesk Email Security 1.5.23
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Return error for inconsistent extended attributes ntfs_read_ea is called when we want to read extended attributes. There are some sanity checks for the validity of the EAs. However, it fails to return a proper error code for the inconsistent attributes, which might lead to…
Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager.
Windows msiexec failed to update ModSecurity IIS module. Code 1603 is generic error, and issue could be caused by various reasons (which might be logged in Plesk autoinstaller3.log file).
Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.
Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks can result in takeover of Oracle Concurrent Processing.
Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure.
Oracle Agile Product Lifecycle Management (PLM) contains a deserialization vulnerability that allows a low-privileged attacker with network access via HTTP to compromise the system.
Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an unspecified vulnerability exploitable by an unauthenticated attacker with network access via IIOP or T3.
Question How can I add Content Security Policies to a WordPress installation? Answer Locate the functions.php file for your WordPress theme. Open functions.php with your favorite editor and add the following code: function add_custom_security_headers() { header("Strict-Transport-Security: max-age=31536000; includeSubDomains;…
Oracle Agile Product Lifecycle Management (PLM) contains an incorrect authorization vulnerability in the Process Extension component of the Software Development Kit. Successful exploitation of this vulnerability may result in unauthenticated file disclosure.
Nostromo nhttpd contains a directory traversal vulnerability in the http_verify() function in a non-chrooted nhttpd server allowing for remote code execution.
Oracle ADF Faces library, included with Oracle JDeveloper Distribution, contains a deserialization of untrusted data vulnerability leading to unauthenticated remote code execution.
Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deserialization vulnerability. Unauthenticated attackers with network access via T3 or IIOP can exploit this vulnerability to achieve remote code execution.
Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an OS command injection vulnerability that allows an attacker to execute arbitrary code via a specially crafted HTTP request that includes a malicious XML document.
Very large headers can cause resource exhaustion when parsing message. The message-parser normally reads reasonably sized chunks of the message. However, when it feeds them to message-header-parser, it starts building up "full_value" buffer out of the smaller chunks. The full_value buffer has no size limit, so large headers can cause large memory usage. It…
Oracle Fusion Middleware contains an unspecified vulnerability in the WLS Core Components that allows an unauthenticated attacker with network access via IIOP to compromise the WebLogic Server.
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Oracle Java SE and JRockit contains an unspecified vulnerability that allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Java Management Extensions (JMX). This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data…