← Back

Lenovo

lenovo

395 CVEs • 4,474 products

Products (4,474)

Click to collapse
Toggle
Pcmanager
pcmanager
System Update
system_update

CVEs (395)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lenovo
98Thinkagile Hx1021 Firmware
Thinkagile Hx1320 FirmwareThinkagile Hx1321 Firmware+95 more
Nov 21, 2024
Jan 30, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated users to cause a recoverable subsystem denial of service.
1Lenovo
1Ideapad Y700 14isk Firmware
Nov 21, 2024
Jan 26, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
A potential vulnerability in a driver used during manufacturing process on the Ideapad Y700-14ISK that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modify...Show more
A potential vulnerability in a driver used during manufacturing process on the Ideapad Y700-14ISK that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.Show less
1Lenovo
70100e 2nd Gen Firmware
100w Gen 3 Firmware13w Yoga Firmware+67 more
Nov 21, 2024
Jan 26, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
1Lenovo
6Thinkbook 14 Iil Firmware
Thinkbook 14 Iml FirmwareThinkbook 15 Iil Firmware+3 more
Nov 21, 2024
Jan 26, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A buffer overflow in the SystemLoadDefaultDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
1Lenovo
6Thinkbook 14 Iil Firmware
Thinkbook 14 Iml FirmwareThinkbook 15 Iil Firmware+3 more
Nov 21, 2024
Jan 26, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
A buffer overflow in the ReadyBootDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
1Lenovo
1Safecenter
Nov 21, 2024
Jan 23, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A denial-of-service vulnerability has been identified in Lenovo Safecenter that could allow a local user to crash the application.
1Lenovo
44D330 10igl Firmware
Ideapad 5 Pro 16arh7 FirmwareIdeapad 5 Pro 16iah7 Firmware+41 more
Nov 21, 2024
Jan 23, 2023
N/A· v4
6.7 MEDIUM· v3
N/A· v2
A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
1Lenovo
1Leyun
Nov 21, 2024
Jan 20, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An incorrect default permissions vulnerability in Lenovo Leyun cloud music application could allow denial of service.
1Lenovo
1Thinkpad X13s Firmware
Nov 21, 2024
Jan 5, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoRemoteConfigUpdateDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.
1Lenovo
1Thinkpad X13s Firmware
Nov 21, 2024
Jan 5, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS driver that could allow a local attacker with elevated privileges to cause information disclosure.
1Lenovo
1Thinkpad X13s Firmware
Nov 21, 2024
Jan 5, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoSetupConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.
1Lenovo
1Thinkpad X13s Firmware
Nov 21, 2024
Jan 5, 2023
N/A· v4
4.4 MEDIUM· v3
N/A· v2
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS PersistenceConfigDxe driver that could allow a local attacker with elevated privileges to cause information disclosure.
1Lenovo
136Aio300 23isu Firmware
Aio310 20iap FirmwareAio510 22ish Firmware+133 more
Apr 14, 2025
Dec 26, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Realtek Audio Drivers for Windows, as used on the Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS, and 20BT before 6.0.8882.1 and 20KH and 20KG before 6.0.8907.1 (and on many other Lenovo and non-Lenovo products), mishandles...Show more
Realtek Audio Drivers for Windows, as used on the Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS, and 20BT before 6.0.8882.1 and 20KH and 20KG before 6.0.8907.1 (and on many other Lenovo and non-Lenovo products), mishandles DLL preloading.Show less
1Lenovo
1Elan Miniport Touchpad Driver
May 2, 2025
Nov 7, 2022
N/A· v4
4.7 MEDIUM· v3
N/A· v2
ELAN Miniport touchpad Windows driver before 24.21.51.2, as used in PC hardware from multiple manufacturers, allows local users to cause a system crash by sending a certain IOCTL request, because that request is handled...Show more
ELAN Miniport touchpad Windows driver before 24.21.51.2, as used in PC hardware from multiple manufacturers, allows local users to cause a system crash by sending a certain IOCTL request, because that request is handled twice.Show less
1Lenovo
1Pcmanager
Nov 21, 2024
Aug 23, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A potential vulnerability was reported in Lenovo PCManager prior to version 5.0.10.4191 that may allow code execution when visiting a specially crafted website.
1Lenovo
1Smart Standby Driver
Nov 21, 2024
May 18, 2022
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
A buffer overflow vulnerability in Lenovo Smart Standby Driver prior to version 4.1.50.0 could allow a local attacker to cause denial of service.
1Lenovo
5A1 Firmware
T1 FirmwareT2 Firmware+2 more
Nov 21, 2024
May 18, 2022
N/A· v4
8.0 HIGH· v3
7.7 HIGH· v2
A command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authenticated user to execute operating system commands by sending a crafted packet to the device.
1Lenovo
5A1 Firmware
T1 FirmwareT2 Firmware+2 more
Nov 21, 2024
May 18, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to create a standard user account.
1Lenovo
5A1 Firmware
T1 FirmwareT2 Firmware+2 more
Nov 21, 2024
May 18, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local net...Show more
A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local network access.Show less
1Lenovo
5A1 Firmware
T1 FirmwareT2 Firmware+2 more
Nov 21, 2024
May 18, 2022
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical access.