Lenovo
lenovo
395 CVEs • 4,474 products
Products (4,474)
Click to collapseToggle
Products (4,474)
Click to collapse
CVEs (395)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 does not properly validate CA chains during signature validation, which allows man-in-the-middle attackers to upload and execute arbitrary files...Show more |
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allows local users to gain privileges by sending a valid token with a command to the System Update servi...Show more |
1Lenovo 1Thinkserver System Manager Baseboard Management Controller Firmware May 6, 2026 Apr 16, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 does not validate server certificates during an "encrypted remote KVM...Show more |
1Lenovo 1Thinkserver System Manager Baseboard Management Controller Firmware May 6, 2026 Apr 16, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350 allows remote attackers to cause a denial of service (web interface cr...Show more |
1Lenovo 10Thinkserver Rd350 Thinkserver Rd350 FirmwareThinkserver Rd450+7 moreMay 6, 2026 Apr 16, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Lenovo ThinkServer RD350, RD450, RD550, RD650, and TD350 servers before 1.26.0 use weak encryption to store (1) user and (2) administrator BIOS passwords, which allows attackers to decrypt the passwords via unspecified v...Show more |
1Lenovo 1Usb Enhanced Performance Keyboard May 6, 2026 Apr 16, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 Lenovo USB Enhanced Performance Keyboard software before 2.0.2.2 includes active debugging code in SKHOOKS.DLL, which allows local users to obtain keypress information by accessing debug output. |
java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchBoxImpl class, which allows attackers to execute arbitrary Java code by...Show more |
1Lenovo 1Thinkpad Bluetooth With Enhanced Data Rate Software Apr 29, 2026 Jan 21, 2014 N/A· v4 N/A· v3 9.3 HIGH· v2 Untrusted search path vulnerability in Lenovo Thinkpad Bluetooth with Enhanced Data Rate Software 6.4.0.2900 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijack...Show more |
Lenovo Veriface III allows physically proximate attackers to login to a Windows account by presenting a "plain image" of the authorized user. |
Heap-based buffer overflow in the tvtumin.sys kernel driver in Lenovo Rescue and Recovery 4.20, including 4.20.0511 and 4.20.0512, allows local users to execute arbitrary code via a long file name. |
The client in Lenovo System Update before 3.14 does not properly validate the certificate when establishing an SSL connection, which allows remote attackers to install arbitrary packages via an SSL certificate whose X.50...Show more |
1Lenovo 2Access Support Automated SolutionsApr 23, 2026 Aug 15, 2007 N/A· v4 N/A· v3 5.8 MEDIUM· v2 The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), exposes unsafe methods to arb...Show more |
1Lenovo 2Access Support Automated SolutionsApr 23, 2026 Aug 15, 2007 N/A· v4 N/A· v3 5.8 MEDIUM· v2 Format string vulnerability in the IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1)...Show more |
1Lenovo 2Access Support Automated SolutionsApr 23, 2026 Aug 15, 2007 N/A· v4 N/A· v3 5.8 MEDIUM· v2 The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), does not properly validate di...Show more |
2Intel Lenovo2Pro 1000 Lan Adapter ThinkpadApr 23, 2026 Mar 7, 2007 N/A· v4 N/A· v3 10.0 HIGH· v2 Unspecified vulnerability in Lenovo Intel PRO/1000 LAN adapter before Build 135400, as used on IBM Lenovo ThinkPad systems, has unknown impact and attack vectors. |