Show filters
432 Total Results
Displaying 101-110 of 432
Sort by:
Attacker Value
Unknown

CVE-2023-43570

Disclosure Date: November 08, 2023 (last updated November 17, 2023)
A potential vulnerability was reported in the SMI callback function of the OemSmi driver that may allow a local attacker with elevated permissions to execute arbitrary code.
Attacker Value
Unknown

CVE-2023-43569

Disclosure Date: November 08, 2023 (last updated November 17, 2023)
A buffer overflow was reported in the OemSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code. 
Attacker Value
Unknown

CVE-2023-43568

Disclosure Date: November 08, 2023 (last updated November 17, 2023)
A buffer over-read was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to disclose sensitive information.
Attacker Value
Unknown

CVE-2023-43567

Disclosure Date: November 08, 2023 (last updated November 17, 2023)
A buffer overflow was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
Attacker Value
Unknown

CVE-2022-4575

Disclosure Date: October 30, 2023 (last updated November 08, 2023)
A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with physical or local access and elevated privileges the ability to bypass Secure Boot.
Attacker Value
Unknown

CVE-2022-4574

Disclosure Date: October 30, 2023 (last updated November 08, 2023)
An SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code.  
Attacker Value
Unknown

CVE-2022-4573

Disclosure Date: October 30, 2023 (last updated November 04, 2023)
An SMI handler input validation vulnerability in the ThinkPad X1 Fold Gen 1 could allow an attacker with local access and elevated privileges to execute arbitrary code.
Attacker Value
Unknown

CVE-2022-48189

Disclosure Date: October 30, 2023 (last updated November 04, 2023)
An SMM driver input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code.
Attacker Value
Unknown

CVE-2022-3702

Disclosure Date: October 27, 2023 (last updated November 08, 2023)
A denial of service vulnerability was reported in Lenovo Vantage HardwareScan Plugin version 1.3.0.5 and earlier that could allow a local attacker to delete contents of an arbitrary directory under certain conditions.
Attacker Value
Unknown

CVE-2022-3701

Disclosure Date: October 27, 2023 (last updated November 08, 2023)
A privilege elevation vulnerability was reported in the Lenovo Vantage SystemUpdate plugin version 2.0.0.212 and earlier that could allow a local attacker to execute arbitrary code with elevated privileges.