ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-oem/ipmi-oem-dell.c (cmc-ipv6-info subcommand to dell get-system-info).
CVSS
9.8
Update availability
Security update available
Affected: azl3 freeipmi 1.6.18-1 on Azure Linux 3.0
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.
CVSS
9.8
Update availability
Security update available
Affected: azl3 freeipmi 1.6.18-1 on Azure Linux 3.0
Review the authoritative advisory for the vulnerability description and applicability.
CVSS
9.1
Update availability
Security update available
Affected: Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8) · Microsoft Visual Studio 2019 version 16.11 (includes 16.0 - 16.10) · +4 more
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to execute code over a network.
CVSS
8.1
Update availability
Security update available
Affected: Windows Server 2016 · Windows Server 2016 (Server Core installation) · +6 more
Improper neutralization of special elements in data query logic in Microsoft Discovery Studio allows an unauthorized attacker to disclose information over a network.
Improper neutralization of special elements in output used by a downstream component ('injection') in SQL Server allows an unauthorized attacker to elevate privileges over a network.
The collection starts with 90 days of Microsoft updates and CISA additions, plus older Microsoft vulnerabilities still listed by CISA. Older entries do not imply that a product remains supported. Counts describe this collection, not every vulnerability or any customer environment.
Griffin Technology Partners managed customers may receive additional environment-specific security guidance and remediation assistance through their managed services relationship.
Security bulletins are provided for informational purposes and compiled from authoritative public sources. Vulnerability applicability varies by environment. Validate affected products, configuration, compatibility requirements, and vendor guidance before making production changes.