Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2021-3843
Disclosure Date: November 12, 2021 (last updated October 07, 2023)
A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
1
Attacker Value
Unknown
CVE-2021-3599
Disclosure Date: November 12, 2021 (last updated October 07, 2023)
A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
1
Attacker Value
Unknown
CVE-2021-3718
Disclosure Date: November 12, 2021 (last updated October 07, 2023)
A denial of service vulnerability was reported in some ThinkPad models that could cause a system to crash when the Enhanced Biometrics setting is enabled in BIOS.
0
Attacker Value
Unknown
CVE-2021-3786
Disclosure Date: November 12, 2021 (last updated October 07, 2023)
A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak out data out of the SMRAM range.
0
Attacker Value
Unknown
CVE-2019-18619
Disclosure Date: July 22, 2020 (last updated November 28, 2024)
Incorrect parameter validation in the synaTee component of Synaptics WBF drivers using an SGX enclave (all versions prior to 2019-11-15) allows a local user to execute arbitrary code in the enclave (that can compromise confidentiality of enclave data) via APIs that accept invalid pointers.
0
Attacker Value
Unknown
CVE-2019-18618
Disclosure Date: July 22, 2020 (last updated November 28, 2024)
Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the confidentiality of sensor data via injection of an unverified partition table.
0
Attacker Value
Unknown
CVE-2020-8323
Disclosure Date: June 09, 2020 (last updated November 28, 2024)
A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution.
0
Attacker Value
Unknown
CVE-2020-8320
Disclosure Date: June 09, 2020 (last updated November 28, 2024)
An internal shell was included in BIOS image in some ThinkPad models that could allow escalation of privilege.
0