← Back

Lenovo

lenovo

395 CVEs • 4,474 products

Products (4,474)

Click to collapse
Toggle
Pcmanager
pcmanager
System Update
system_update

CVEs (395)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lenovo
1System Update
May 6, 2026
May 12, 2015
N/A· v4
N/A· v3
8.3 HIGH· v2
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 does not properly validate CA chains during signature validation, which allows man-in-the-middle attackers to upload and execute arbitrary files...Show more
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 does not properly validate CA chains during signature validation, which allows man-in-the-middle attackers to upload and execute arbitrary files via a crafted certificate.Show less
1Lenovo
1System Update
May 6, 2026
May 12, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allows local users to gain privileges by sending a valid token with a command to the System Update servi...Show more
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allows local users to gain privileges by sending a valid token with a command to the System Update service (SUService.exe) through an unspecified named pipe.Show less
1Lenovo
1Thinkserver System Manager Baseboard Management Controller Firmware
May 6, 2026
Apr 16, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 does not validate server certificates during an "encrypted remote KVM...Show more
The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 does not validate server certificates during an "encrypted remote KVM session," which allows man-in-the-middle attackers to spoof servers.Show less
1Lenovo
1Thinkserver System Manager Baseboard Management Controller Firmware
May 6, 2026
Apr 16, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 allows remote attackers to cause a denial of service (web interface cr...Show more
The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 allows remote attackers to cause a denial of service (web interface crash) via a malformed HTTP request during authentication.Show less
1Lenovo
10Thinkserver Rd350
Thinkserver Rd350 FirmwareThinkserver Rd450+7 more
May 6, 2026
Apr 16, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Lenovo ThinkServer RD350, RD450, RD550, RD650, and TD350 servers before 1.26.0 use weak encryption to store (1) user and (2) administrator BIOS passwords, which allows attackers to decrypt the passwords via unspecified v...Show more
Lenovo ThinkServer RD350, RD450, RD550, RD650, and TD350 servers before 1.26.0 use weak encryption to store (1) user and (2) administrator BIOS passwords, which allows attackers to decrypt the passwords via unspecified vectors.Show less
1Lenovo
1Usb Enhanced Performance Keyboard
May 6, 2026
Apr 16, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
Lenovo USB Enhanced Performance Keyboard software before 2.0.2.2 includes active debugging code in SKHOOKS.DLL, which allows local users to obtain keypress information by accessing debug output.
2Google
Lenovo
2Android
Shareit
Apr 29, 2026
Mar 3, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchBoxImpl class, which allows attackers to execute arbitrary Java code by...Show more
java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchBoxImpl class, which allows attackers to execute arbitrary Java code by leveraging access to the searchBoxJavaBridge_ interface at certain Android API levels.Show less
1Lenovo
1Thinkpad Bluetooth With Enhanced Data Rate Software
Apr 29, 2026
Jan 21, 2014
N/A· v4
N/A· v3
9.3 HIGH· v2
Untrusted search path vulnerability in Lenovo Thinkpad Bluetooth with Enhanced Data Rate Software 6.4.0.2900 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijack...Show more
Untrusted search path vulnerability in Lenovo Thinkpad Bluetooth with Enhanced Data Rate Software 6.4.0.2900 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL that is located in the same folder as a file that is processed by Lenovo Bluetooth.Show less
1Lenovo
1Veriface
Apr 23, 2026
Feb 20, 2009
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Lenovo Veriface III allows physically proximate attackers to login to a Windows account by presenting a "plain image" of the authorized user.
1Lenovo
1Resuce And Recovery
Apr 23, 2026
Oct 15, 2008
N/A· v4
N/A· v3
7.2 HIGH· v2
Heap-based buffer overflow in the tvtumin.sys kernel driver in Lenovo Rescue and Recovery 4.20, including 4.20.0511 and 4.20.0512, allows local users to execute arbitrary code via a long file name.
1Lenovo
1Thinkvantage System Update
Apr 23, 2026
Jul 21, 2008
N/A· v4
N/A· v3
5.1 MEDIUM· v2
The client in Lenovo System Update before 3.14 does not properly validate the certificate when establishing an SSL connection, which allows remote attackers to install arbitrary packages via an SSL certificate whose X.50...Show more
The client in Lenovo System Update before 3.14 does not properly validate the certificate when establishing an SSL connection, which allows remote attackers to install arbitrary packages via an SSL certificate whose X.509 headers match a public certificate used by IBM.Show less
1Lenovo
2Access Support
Automated Solutions
Apr 23, 2026
Aug 15, 2007
N/A· v4
N/A· v3
5.8 MEDIUM· v2
The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), exposes unsafe methods to arb...Show more
The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), exposes unsafe methods to arbitrary web domains, which allows remote attackers to download arbitrary code onto a client system and execute this code.Show less
1Lenovo
2Access Support
Automated Solutions
Apr 23, 2026
Aug 15, 2007
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Format string vulnerability in the IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1)...Show more
Format string vulnerability in the IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), allows remote attackers to execute arbitrary code via format string specifiers in unknown data.Show less
1Lenovo
2Access Support
Automated Solutions
Apr 23, 2026
Aug 15, 2007
N/A· v4
N/A· v3
5.8 MEDIUM· v2
The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), does not properly validate di...Show more
The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), does not properly validate digital signatures of downloaded software, which makes it easier for remote attackers to spoof a download.Show less
2Intel
Lenovo
2Pro 1000 Lan Adapter
Thinkpad
Apr 23, 2026
Mar 7, 2007
N/A· v4
N/A· v3
10.0 HIGH· v2
Unspecified vulnerability in Lenovo Intel PRO/1000 LAN adapter before Build 135400, as used on IBM Lenovo ThinkPad systems, has unknown impact and attack vectors.