Show filters
106 Total Results
Displaying 21-30 of 106
Sort by:
Attacker Value
Unknown

CVE-2020-8322

Disclosure Date: June 09, 2020 (last updated November 28, 2024)
A potential vulnerability in the SMI callback function used in the Legacy USB driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution.
Attacker Value
Unknown

CVE-2019-19245

Disclosure Date: December 02, 2019 (last updated November 27, 2024)
NAPC Xinet Elegant 6 Asset Library 6.1.655 allows Pre-Authentication SQL Injection via the /elegant6/login LoginForm[username] field when double quotes are used.
Attacker Value
Unknown

A potential vulnerability in some Lenovo ThinkPads may allow an attacker to exe…

Disclosure Date: November 12, 2019 (last updated November 27, 2024)
A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo ThinkPad models may allow arbitrary code execution.
Attacker Value
Unknown

ThinkPad T460p and T470p BIOS Tamper Mechanism

Disclosure Date: November 12, 2019 (last updated November 27, 2024)
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access.
Attacker Value
Unknown

A potential vulnerability in the SMI callback function in some Lenovo ThinkPad …

Disclosure Date: November 12, 2019 (last updated November 27, 2024)
A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad models may allow arbitrary code execution.
Attacker Value
Unknown

CVE-2019-10746

Disclosure Date: August 23, 2019 (last updated November 08, 2023)
mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
Attacker Value
Unknown

CVE-2018-7364

Disclosure Date: December 07, 2018 (last updated November 27, 2024)
All versions up to ZXINOS-RESV1.01.43 of the ZTE ZXIN10 product European region are impacted by improper access control vulnerability. Due to improper access control to devcomm process, an unauthorized remote attacker can exploit this vulnerability to execute arbitrary code with root privileges.
Attacker Value
Unknown

BIOS Write Protection Race Condition

Disclosure Date: October 02, 2018 (last updated November 27, 2024)
In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS.
Attacker Value
Unknown

CVE-2018-3719

Disclosure Date: June 07, 2018 (last updated November 26, 2024)
mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects.
Attacker Value
Unknown

CVE-2017-16618

Disclosure Date: November 08, 2017 (last updated November 26, 2024)
An exploitable vulnerability exists in the YAML loading functionality of util.py in OwlMixin before 2.0.0a12. A "Load YAML" string or file (aka load_yaml or load_yamlf) can execute arbitrary Python commands resulting in command execution because load is used where safe_load should have been used. An attacker can insert Python into loaded YAML to trigger this vulnerability.
0