Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Unknown

CVE-2022-3431

Disclosure Date: October 09, 2023 (last updated October 14, 2023)
A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
Attacker Value
Unknown

CVE-2022-1892

Disclosure Date: January 26, 2023 (last updated October 08, 2023)
A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
Attacker Value
Unknown

CVE-2022-1891

Disclosure Date: January 26, 2023 (last updated October 08, 2023)
A buffer overflow in the SystemLoadDefaultDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
Attacker Value
Unknown

CVE-2022-1890

Disclosure Date: January 26, 2023 (last updated October 08, 2023)
A buffer overflow in the ReadyBootDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
Attacker Value
Unknown

CVE-2022-3430

Disclosure Date: January 23, 2023 (last updated October 08, 2023)
A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
Attacker Value
Unknown

CVE-2021-4212

Disclosure Date: April 22, 2022 (last updated October 07, 2023)
A potential vulnerability in the SMI callback function used in the Legacy BIOS mode driver in some Lenovo Notebook models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Attacker Value
Unknown

CVE-2019-18619

Disclosure Date: July 22, 2020 (last updated February 21, 2025)
Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise confidentiality of enclave data) via APIs that accept invalid pointers.
Attacker Value
Unknown

CVE-2019-18618

Disclosure Date: July 22, 2020 (last updated November 28, 2024)
Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the confidentiality of sensor data via injection of an unverified partition table.
Attacker Value
Unknown

CVE-2020-8323

Disclosure Date: June 09, 2020 (last updated November 28, 2024)
A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution.
Attacker Value
Unknown

CVE-2020-8321

Disclosure Date: June 09, 2020 (last updated November 28, 2024)
A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution.