Show filters
35 Total Results
Displaying 11-20 of 35
Sort by:
Attacker Value
Unknown

CVE-2022-34399

Disclosure Date: January 18, 2023 (last updated November 08, 2023)
Dell Alienware m17 R5 BIOS version prior to 1.2.2 contain a buffer access vulnerability. A malicious user with admin privileges could potentially exploit this vulnerability by sending input larger than expected in order to leak certain sections of SMRAM.
Attacker Value
Unknown

CVE-2022-34401

Disclosure Date: January 18, 2023 (last updated November 08, 2023)
Dell BIOS contains a stack based buffer overflow vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to send larger than expected input to a parameter in order to gain arbitrary code execution in SMRAM.
Attacker Value
Unknown

CVE-2022-23824

Disclosure Date: November 08, 2022 (last updated February 04, 2024)
IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.
Attacker Value
Unknown

CVE-2022-31765

Disclosure Date: October 11, 2022 (last updated October 08, 2023)
Affected devices do not properly authorize the change password function of the web interface. This could allow low privileged users to escalate their privileges.
Attacker Value
Unknown

CVE-2022-23825

Disclosure Date: July 12, 2022 (last updated November 08, 2023)
Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.
Attacker Value
Unknown

CVE-2022-29900

Disclosure Date: July 12, 2022 (last updated October 18, 2023)
Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.
Attacker Value
Unknown

CVE-2022-23823

Disclosure Date: June 14, 2022 (last updated February 23, 2025)
A potential vulnerability in some AMD processors using frequency scaling may allow an authenticated attacker to execute a timing attack to potentially enable information disclosure.
Attacker Value
Unknown

CVE-2021-4211

Disclosure Date: April 22, 2022 (last updated February 23, 2025)
A potential vulnerability in the SMI callback function used in the SMBIOS event log driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Attacker Value
Unknown

CVE-2021-4210

Disclosure Date: April 22, 2022 (last updated February 23, 2025)
A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Attacker Value
Unknown

CVE-2021-3972

Disclosure Date: April 22, 2022 (last updated February 23, 2025)
A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.