Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown
CVE-2021-3969
Disclosure Date: May 18, 2022 (last updated February 23, 2025)
A Time of Check Time of Use (TOCTOU) vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation, prior to version 1.1.20.3that could allow a local attacker to elevate privileges.
0
Attacker Value
Unknown
CVE-2021-3922
Disclosure Date: May 18, 2022 (last updated February 23, 2025)
A race condition vulnerability was reported in IMController, a software component of Lenovo System Interface Foundation, prior to version 1.1.20.3 that could allow a local attacker to connect and interact with the IMController child process' named pipe.
0
Attacker Value
Unknown
CVE-2021-45105
Disclosure Date: December 18, 2021 (last updated February 23, 2025)
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
0
Attacker Value
Unknown
CVE-2020-8346
Disclosure Date: September 15, 2020 (last updated February 22, 2025)
A denial of service vulnerability was reported in the Lenovo Vantage component called Lenovo System Interface Foundation prior to version 1.1.19.5 that could allow configuration files to be written to non-standard locations.
0
Attacker Value
Unknown
CVE-2020-8318
Disclosure Date: April 14, 2020 (last updated November 27, 2024)
A privilege escalation vulnerability was reported in the LenovoSystemUpdatePlugin for Lenovo System Interface Foundation prior to version that could allow an authenticated user to execute code with elevated privileges.
0
Attacker Value
Unknown
CVE-2020-8324
Disclosure Date: April 14, 2020 (last updated February 21, 2025)
A vulnerability was reported in LenovoAppScenarioPluginSystem for Lenovo System Interface Foundation prior to version 1.2.184.31 that could allow unsigned DLL files to be executed.
0
Attacker Value
Unknown
CVE-2020-8319
Disclosure Date: April 14, 2020 (last updated November 27, 2024)
A privilege escalation vulnerability was reported in Lenovo System Interface Foundation prior to version 1.1.19.3 that could allow an authenticated user to execute code with elevated privileges.
0
Attacker Value
Unknown
CVE-2019-6189
Disclosure Date: November 20, 2019 (last updated November 27, 2024)
A potential vulnerability was reported in Lenovo System Interface Foundation versions before v1.1.18.3 that could allow an administrative user to load an unsigned DLL.
0
Attacker Value
Unknown
CVE-2019-6186
Disclosure Date: November 20, 2019 (last updated November 27, 2024)
A potential vulnerability was reported in Lenovo System Interface Foundation versions before v1.1.18.3 that could allow an authenticated user to execute code as another user.
0
Attacker Value
Unknown
CVE-2016-8223
Disclosure Date: November 29, 2016 (last updated November 25, 2024)
During an internal security review, Lenovo identified a local privilege escalation vulnerability in Lenovo System Interface Foundation software installed on some Windows 10 PCs where a user with local privileges could run arbitrary code with administrator level privileges.
0