Show filters
164 Total Results
Displaying 151-160 of 164
Sort by:
Attacker Value
Unknown
CVE-2016-8222
Disclosure Date: November 30, 2016 (last updated November 25, 2024)
A vulnerability has been identified in a signed kernel driver for the BIOS of some ThinkPad systems that can allow an attacker with Windows administrator-level privileges to call System Management Mode (SMM) services. This could lead to a denial of service attack or allow certain BIOS variables or settings to be altered (such as boot sequence). The setting or changing of BIOS passwords is not affected by this vulnerability.
0
Attacker Value
Unknown
CVE-2016-8224
Disclosure Date: November 29, 2016 (last updated November 25, 2024)
A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a system could install a program that circumvents Intel Management Engine (ME) protections. This could result in a denial of service or privilege escalation attack on the system.
0
Attacker Value
Unknown
CVE-2016-5247
Disclosure Date: September 22, 2016 (last updated November 25, 2024)
The BIOS for Lenovo ThinkCentre E93, M6500t/s, M6600, M6600q, M6600t/s, M73p, M800, M83, M8500t/s, M8600t/s, M900, M93, and M93P devices; ThinkServer RQ940, RS140, TS140, TS240, TS440, and TS540 devices; and ThinkStation E32, P300, and P310 devices might allow local users or physically proximate attackers to bypass the Secure Boot protection mechanism by leveraging an AMI test key.
0
Attacker Value
Unknown
CVE-2016-5729
Disclosure Date: June 30, 2016 (last updated November 25, 2024)
Lenovo BIOS EFI Driver allows local administrators to execute arbitrary code with System Management Mode (SMM) privileges via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-2890
Disclosure Date: August 01, 2015 (last updated November 25, 2024)
The BIOS implementation on Dell Latitude, OptiPlex, Precision Mobile Workstation, and Precision Workstation Client Solutions (CS) devices with model-dependent firmware before A21 does not enforce a BIOS_CNTL locking protection mechanism upon being woken from sleep, which allows local users to conduct EFI flash attacks by leveraging console access, a similar issue to CVE-2015-3692.
0
Attacker Value
Unknown
CVE-2012-2368
Disclosure Date: August 13, 2012 (last updated October 04, 2023)
Bytemark Symbiosis before Revision 1322 does not properly validate passwords, which allows remote attackers to gain access to email accounts via an arbitrary password.
0
Attacker Value
Unknown
CVE-2008-7096
Disclosure Date: August 27, 2009 (last updated October 04, 2023)
Intel Desktop and Intel Mobile Boards with BIOS firmware DQ35JO, DQ35MP, DP35DP, DG33FB, DG33BU, DG33TL, MGM965TW, D945GCPE, and DX38BT allows local administrators with ring 0 privileges to gain additional privileges and modify code that is running in System Management Mode, or access hypervisory memory as demonstrated at Black Hat 2008 by accessing certain remapping registers in Xen 3.3.
0
Attacker Value
Unknown
CVE-2009-2887
Disclosure Date: August 20, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in bios.php in PHP Scripts Now President Bios allows remote attackers to inject arbitrary web script or HTML via the rank parameter.
0
Attacker Value
Unknown
CVE-2009-2886
Disclosure Date: August 20, 2009 (last updated October 04, 2023)
SQL injection vulnerability in bios.php in PHP Scripts Now President Bios allows remote attackers to execute arbitrary SQL commands via the rank parameter.
0
Attacker Value
Unknown
CVE-2008-3900
Disclosure Date: September 03, 2008 (last updated October 04, 2023)
Intel firmware PE94510M.86A.0050.2007.0710.1559 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.
0