Lenovo
lenovo
395 CVEs • 4,474 products
Products (4,474)
Click to collapseToggle
Products (4,474)
Click to collapse
CVEs (395)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Lenovo 8Thinkpad A275 Firmware Thinkpad A285 FirmwareThinkpad A475 Firmware+5 moreNov 21, 2024 Sep 1, 2020 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad A285, BIOS versions up to r0xuj70w; A485, BIOS versions up to r0wuj65w; T495 BIOS versions up to r12uj55w; T495s/X395, BIOS versions up to r13uj47w...Show more |
An unquoted service path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevated privileges. |
A DLL search path vulnerability was reported in Lenovo Drivers Management prior to version 2.7.1128.1046 that could allow an authenticated user to execute code with elevated privileges. |
3Hp LenovoSynaptics112Envy 13t Ah100 Firmware Envy 13t Aq100 FirmwareEnvy 17t Bw000 Firmware+109 moreNov 21, 2024 Jul 22, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise c...Show more |
3Hp LenovoSynaptics133Elite Slice Firmware Elite X2 1012 G2 FirmwareElite X2 1013 G3 Firmware+130 moreNov 21, 2024 Jul 22, 2020 N/A· v4 6.0 MEDIUM· v3 3.6 LOW· v2 Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the...Show more |
1Lenovo 38Thinkpad E14 Firmware Thinkpad E15 FirmwareThinkpad E490 Firmware+35 moreNov 21, 2024 Jun 9, 2020 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 Lenovo implemented Intel CSME Anti-rollback ARB protections on some ThinkPad models to prevent roll back of CSME Firmware in flash. |
1Lenovo 7Thinkpad A275 Firmware Thinkpad A285 FirmwareThinkpad A475 Firmware+4 moreNov 21, 2024 Jun 9, 2020 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T495s, X395, T495, A485, A285, A475, A275 which may allow for unauthorized access. |
1Lenovo 17214iwl Firmware 330 14ast Firmware330 15ast Firmware+169 moreNov 21, 2024 Jun 9, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution. |
1Lenovo 5114iwl Firmware 330 14ast Firmware330 15ast Firmware+48 moreNov 21, 2024 Jun 9, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 A potential vulnerability in the SMI callback function used in the Legacy USB driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution. |
1Lenovo 172130 14ast Firmware 130 14ikb Firmware130 15ast Firmware+169 moreNov 21, 2024 Jun 9, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution. |
1Lenovo 100Thinkpad 11e Firmware Thinkpad 11e Yoga Gen 6 FirmwareThinkpad 13 2nd Gen Firmware+97 moreNov 21, 2024 Jun 9, 2020 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege. |
A symbolic link vulnerability in some Lenovo installation packages, prior to version 1.2.9.3, could allow privileged file operations during file extraction and installation. |
A DLL search path vulnerability could allow privilege escalation in some Lenovo installation packages, prior to version 1.2.9.3, during installation if an attacker already has administrative privileges. |
1Lenovo 3Lj4010dn Firmware Lj6700dn FirmwareM8960dnf FirmwareNov 21, 2024 May 28, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A denial of service vulnerability was reported in the firmware prior to version 1.01 used in Lenovo Printer LJ4010DN that could be triggered by a remote user sending a crafted packet to the device, preventing subsequent...Show more |
1Lenovo 3Lj4010dn Firmware Lj6700dn FirmwareM8960dnf FirmwareNov 21, 2024 May 28, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A denial of service vulnerability was reported in the firmware prior to version 1.01 used in Lenovo Printer LJ4010DN that could be triggered by a remote user sending a crafted packet to the device, causing an error to be...Show more |
A privilege escalation vulnerability was reported in LenovoBatteryGaugePackage for Lenovo System Interface Foundation bundled in Lenovo Vantage prior to version 10.2003.10.0 that could allow an authenticated user to exec...Show more |
1Lenovo 1System Interface Foundation Nov 21, 2024 Apr 14, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A vulnerability was reported in LenovoAppScenarioPluginSystem for Lenovo System Interface Foundation prior to version 1.2.184.31 that could allow unsigned DLL files to be executed. |
1Lenovo 1System Interface Foundation Nov 21, 2024 Apr 14, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A privilege escalation vulnerability was reported in Lenovo System Interface Foundation prior to version 1.1.19.3 that could allow an authenticated user to execute code with elevated privileges. |
1Lenovo 1System Interface Foundation Nov 21, 2024 Apr 14, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A privilege escalation vulnerability was reported in the LenovoSystemUpdatePlugin for Lenovo System Interface Foundation prior to version that could allow an authenticated user to execute code with elevated privileges. |
A vulnerability was reported in Lenovo Vantage prior to version 10.2003.10.0 that could allow an authenticated user to read files on the system with elevated privileges. |