Show filters
37 Total Results
Displaying 31-37 of 37
Sort by:
Attacker Value
Unknown

CVE-2015-8110

Disclosure Date: April 24, 2017 (last updated November 26, 2024)
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by navigating to (1) "Click here to learn more" or (2) "View privacy policy" within the Tvsukernel.exe GUI application in the context of a temporary administrator account, aka a "local privilege escalation vulnerability."
0
Attacker Value
Unknown

CVE-2015-2234

Disclosure Date: May 12, 2015 (last updated October 05, 2023)
Race condition in Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses world-writable permissions for the update files directory, which allows local users to gain privileges by writing to an update file after the signature is validated.
0
Attacker Value
Unknown

CVE-2015-2233

Disclosure Date: May 12, 2015 (last updated October 05, 2023)
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 does not properly validate CA chains during signature validation, which allows man-in-the-middle attackers to upload and execute arbitrary files via a crafted certificate.
0
Attacker Value
Unknown

CVE-2015-2219

Disclosure Date: May 12, 2015 (last updated October 05, 2023)
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allows local users to gain privileges by sending a valid token with a command to the System Update service (SUService.exe) through an unspecified named pipe.
0
Attacker Value
Unknown

CVE-2014-4835

Disclosure Date: January 17, 2015 (last updated October 05, 2023)
IBM ServerGuide before 9.63, UpdateXpress System Packs Installer (UXSPI) before 9.63, and ToolsCenter Suite before 9.63 place credentials in logs, which allows local users to obtain sensitive information by reading a file.
0
Attacker Value
Unknown

CVE-2008-3249

Disclosure Date: July 21, 2008 (last updated October 04, 2023)
The client in Lenovo System Update before 3.14 does not properly validate the certificate when establishing an SSL connection, which allows remote attackers to install arbitrary packages via an SSL certificate whose X.509 headers match a public certificate used by IBM.
0
Attacker Value
Unknown

CVE-2005-3566

Disclosure Date: November 16, 2005 (last updated February 22, 2025)
Buffer overflow in various ha commands of VERITAS Cluster Server for UNIX before 4.0MP2 allows local users to execute arbitrary code via a long VCSI18N_LANG environment variable to (1) haagent, (2) haalert, (3) haattr, (4) hacli, (5) hacli_runcmd, (6) haclus, (7) haconf, (8) hadebug, (9) hagrp, (10) hahb, (11) halog, (12) hareg, (13) hares, (14) hastatus, (15) hasys, (16) hatype, (17) hauser, and (18) tststew.
0