Show filters
1,987 Total Results
Displaying 451-460 of 1,987
Sort by:
Attacker Value
Unknown

CVE-2022-34398

Disclosure Date: February 01, 2023 (last updated February 24, 2025)
Dell BIOS contains a Time-of-check Time-of-use vulnerability. A local authenticated malicious user could\u00a0potentially exploit this vulnerability by using a specifically timed DMA transaction during an SMI to gain arbitrary code execution on the system.
Attacker Value
Unknown

CVE-2022-40137

Disclosure Date: January 30, 2023 (last updated February 24, 2025)
A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.
Attacker Value
Unknown

CVE-2022-40136

Disclosure Date: January 30, 2023 (last updated February 24, 2025)
An information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
Attacker Value
Unknown

CVE-2022-40135

Disclosure Date: January 30, 2023 (last updated February 24, 2025)
An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
Attacker Value
Unknown

CVE-2022-40134

Disclosure Date: January 30, 2023 (last updated February 24, 2025)
An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
Attacker Value
Unknown

CVE-2022-34888

Disclosure Date: January 30, 2023 (last updated February 24, 2025)
The Remote Mount feature can potentially be abused by valid, authenticated users to make connections to internal services that may not normally be accessible to users. Internal service access controls, as applicable, remain in effect.
Attacker Value
Unknown

CVE-2022-34884

Disclosure Date: January 30, 2023 (last updated February 24, 2025)
A buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated users to cause a recoverable subsystem denial of service.
Attacker Value
Unknown

CVE-2023-21796

Disclosure Date: January 24, 2023 (last updated January 11, 2025)
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2023-21795

Disclosure Date: January 24, 2023 (last updated February 24, 2025)
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2023-21775

Disclosure Date: January 24, 2023 (last updated January 11, 2025)
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability