Show filters
91 Total Results
Displaying 21-30 of 91
Sort by:
Attacker Value
Unknown
CVE-2019-19705
Disclosure Date: December 26, 2022 (last updated February 24, 2025)
Realtek Audio Drivers for Windows, as used on the Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS, and 20BT before 6.0.8882.1 and 20KH and 20KG before 6.0.8907.1 (and on many other Lenovo and non-Lenovo products), mishandles DLL preloading.
0
Attacker Value
Unknown
CVE-2022-3088
Disclosure Date: November 22, 2022 (last updated February 24, 2025)
UC-8100A-ME-T System Image: Versions v1.0 to v1.6, UC-2100 System Image: Versions v1.0 to v1.12, UC-2100-W System Image: Versions v1.0 to v 1.12, UC-3100 System Image: Versions v1.0 to v1.6, UC-5100 System Image: Versions v1.0 to v1.4, UC-8100 System Image: Versions v3.0 to v3.5, UC-8100-ME-T System Image: Versions v3.0 and v3.1, UC-8200 System Image: v1.0 to v1.5, AIG-300 System Image: v1.0 to v1.4, UC-8410A with Debian 9 System Image: Versions v4.0.2 and v4.1.2, UC-8580 with Debian 9 System Image: Versions v2.0 and v2.1, UC-8540 with Debian 9 System Image: Versions v2.0 and v2.1, and DA-662C-16-LX (GLB) System Image: Versions v1.0.2 to v1.1.2 of Moxa's ARM-based computers have an execution with unnecessary privileges vulnerability, which could allow an attacker with user-level privileges to gain root privileges.
0
Attacker Value
Unknown
CVE-2022-31800
Disclosure Date: June 20, 2022 (last updated February 23, 2025)
An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.
0
Attacker Value
Unknown
CVE-2021-42852
Disclosure Date: May 18, 2022 (last updated February 23, 2025)
A command injection vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an authenticated user to execute operating system commands by sending a crafted packet to the device.
0
Attacker Value
Unknown
CVE-2021-42851
Disclosure Date: May 18, 2022 (last updated February 23, 2025)
A vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to create a standard user account.
0
Attacker Value
Unknown
CVE-2021-42850
Disclosure Date: May 18, 2022 (last updated February 23, 2025)
A weak default administrator password for the web interface and serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical or local network access.
0
Attacker Value
Unknown
CVE-2021-42849
Disclosure Date: May 18, 2022 (last updated February 23, 2025)
A weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device access to an attacker with physical access.
0
Attacker Value
Unknown
CVE-2021-42848
Disclosure Date: May 18, 2022 (last updated February 23, 2025)
An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to retrieve device and networking details.
0
Attacker Value
Unknown
CVE-2022-1108
Disclosure Date: April 22, 2022 (last updated February 23, 2025)
A potential vulnerability due to improper buffer validation in the SMI handler LenovoFlashDeviceInterface in Thinkpad X1 Fold Gen 1 could be exploited by an attacker with local access and elevated privileges to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2022-1107
Disclosure Date: April 22, 2022 (last updated February 23, 2025)
During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.
0