Show filters
432 Total Results
Displaying 131-140 of 432
Sort by:
Attacker Value
Unknown

CVE-2023-4030

Disclosure Date: August 17, 2023 (last updated October 08, 2023)
A vulnerability was reported in BIOS for ThinkPad P14s Gen 2, P15s Gen 2, T14 Gen 2, and T15 Gen 2 that could cause the system to recover to insecure settings if the BIOS becomes corrupt.
Attacker Value
Unknown

CVE-2023-4029

Disclosure Date: August 17, 2023 (last updated October 08, 2023)
A buffer overflow has been identified in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products which may allow an attacker with local access and elevated privileges to execute arbitrary code.
Attacker Value
Unknown

CVE-2023-4028

Disclosure Date: August 17, 2023 (last updated October 08, 2023)
A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.
Attacker Value
Unknown

CVE-2023-3078

Disclosure Date: August 17, 2023 (last updated January 03, 2024)
An uncontrolled search path vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local access to execute code with elevated privileges.
Attacker Value
Unknown

CVE-2023-34419

Disclosure Date: August 17, 2023 (last updated October 08, 2023)
A buffer overflow has been identified in the SetupUtility driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.
Attacker Value
Unknown

CVE-2023-3113

Disclosure Date: June 26, 2023 (last updated October 08, 2023)
An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read-only access to specific files.
Attacker Value
Unknown

CVE-2023-34422

Disclosure Date: June 26, 2023 (last updated October 08, 2023)
A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a specifically crafted web API call due to insufficient input validation.
Attacker Value
Unknown

CVE-2023-34421

Disclosure Date: June 26, 2023 (last updated October 08, 2023)
A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically crafted web API call due to insufficient input validation.
Attacker Value
Unknown

CVE-2023-34420

Disclosure Date: June 26, 2023 (last updated October 08, 2023)
A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted calls to a specific web API.
Attacker Value
Unknown

CVE-2023-34418

Disclosure Date: June 26, 2023 (last updated October 08, 2023)
A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to a SQL injection vulnerability in a specific web API.