Show filters
432 Total Results
Displaying 21-30 of 432
Sort by:
Attacker Value
Unknown

CVE-2024-33579

Disclosure Date: October 11, 2024 (last updated January 06, 2025)
A DLL hijack vulnerability was reported in Lenovo Baiying that could allow a local attacker to execute code with elevated privileges.
0
Attacker Value
Unknown

CVE-2024-33578

Disclosure Date: October 11, 2024 (last updated January 06, 2025)
A DLL hijack vulnerability was reported in Lenovo Leyun that could allow a local attacker to execute code with elevated privileges.
0
Attacker Value
Unknown

CVE-2024-8281

Disclosure Date: September 13, 2024 (last updated January 05, 2025)
An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection through specially crafted command line input in the XCC SSH captive shell.
0
Attacker Value
Unknown

CVE-2024-8280

Disclosure Date: September 13, 2024 (last updated January 05, 2025)
An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection or cause a recoverable denial of service using a specially crafted file.
0
Attacker Value
Unknown

CVE-2024-8279

Disclosure Date: September 13, 2024 (last updated January 05, 2025)
A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially crafted file uploads.
0
Attacker Value
Unknown

CVE-2024-8278

Disclosure Date: September 13, 2024 (last updated January 05, 2025)
A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially crafted IPMI commands.
0
Attacker Value
Unknown

CVE-2024-8059

Disclosure Date: September 13, 2024 (last updated September 14, 2024)
IPMI credentials may be captured in XCC audit log entries when the account username length is 16 characters.
Attacker Value
Unknown

CVE-2024-7756

Disclosure Date: September 13, 2024 (last updated January 05, 2025)
A potential vulnerability was reported in the ThinkPad L390 Yoga and 10w Notebook that could allow a local attacker to escalate privileges by accessing an embedded UEFI shell.
0
Attacker Value
Unknown

CVE-2024-4550

Disclosure Date: September 13, 2024 (last updated January 05, 2025)
A potential buffer overflow vulnerability was reported in some Lenovo ThinkSystem and ThinkStation products that could allow a local attacker with elevated privileges to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2024-45105

Disclosure Date: September 13, 2024 (last updated January 05, 2025)
An internal product security audit discovered a UEFI SMM (System Management Mode) callout vulnerability in some ThinkSystem servers that could allow a local attacker with elevated privileges to execute arbitrary code.
0