Show filters
30 Total Results
Displaying 21-30 of 30
Sort by:
Attacker Value
Unknown

CVE-2020-8321

Disclosure Date: June 09, 2020 (last updated November 28, 2024)
A potential vulnerability in the SMI callback function used in the System Lock Preinstallation driver in some Lenovo Notebook and ThinkStation models may allow arbitrary code execution.
Attacker Value
Unknown

A potential vulnerability in some Lenovo ThinkPads may allow an attacker to exe…

Disclosure Date: November 12, 2019 (last updated November 27, 2024)
A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo ThinkPad models may allow arbitrary code execution.
Attacker Value
Unknown

ThinkPad T460p and T470p BIOS Tamper Mechanism

Disclosure Date: November 12, 2019 (last updated November 27, 2024)
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access.
Attacker Value
Unknown

A potential vulnerability in the SMI callback function in some Lenovo ThinkPad …

Disclosure Date: November 12, 2019 (last updated November 27, 2024)
A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad models may allow arbitrary code execution.
Attacker Value
Unknown

BIOS Write Protection Race Condition

Disclosure Date: October 02, 2018 (last updated November 27, 2024)
In some Lenovo IdeaPad consumer notebook models, a race condition in the BIOS flash device locking mechanism is not adequately protected against, potentially allowing an attacker with administrator access to alter the contents of BIOS.
Attacker Value
Unknown

CVE-2014-5628

Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The Wonder Zoo - Animal rescue ! (aka com.gameloft.android.ANMP.GloftZRHM) application 1.6.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2009-1790

Disclosure Date: May 26, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in CGI RESCUE Trees before 2.11 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
0
Attacker Value
Unknown

CVE-2009-1589

Disclosure Date: May 08, 2009 (last updated October 04, 2023)
Unspecified vulnerability in CGI RESCUE MiniBBS22 before 1.01 allows remote attackers to send email to arbitrary recipients via unknown vectors.
0
Attacker Value
Unknown

CVE-2009-1588

Disclosure Date: May 08, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in CGI RESCUE MiniBBS 8t before 8.95t, 8 before 8.95, 9 before 9.08, and 10 before 10.32 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2008-1633

Disclosure Date: April 02, 2008 (last updated October 04, 2023)
Unspecified vulnerability in Mondo Rescue before 2.2.5 has unknown impact and attack vectors, related to the use of (1) /tmp and (2) MINDI_CACHE.
0