Show filters
432 Total Results
Displaying 1-10 of 432
Sort by:
Attacker Value
Very High
CVE-2017-5638
Disclosure Date: March 11, 2017 (last updated July 26, 2024)
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload attempts, which allows remote attackers to execute arbitrary commands via a crafted Content-Type, Content-Disposition, or Content-Length HTTP header, as exploited in the wild in March 2017 with a Content-Type header containing a #cmd= string.
1
Attacker Value
Unknown
CVE-2021-3599
Disclosure Date: November 12, 2021 (last updated October 07, 2023)
A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
1
Attacker Value
Unknown
CVE-2021-3843
Disclosure Date: November 12, 2021 (last updated October 07, 2023)
A potential vulnerability in the SMI function to access EEPROM in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
1
Attacker Value
Unknown
CVE-2021-3519
Disclosure Date: November 12, 2021 (last updated October 07, 2023)
A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Device List" BIOS setting is Yes.
1
Attacker Value
Unknown
CVE-2024-12673
Disclosure Date: February 12, 2025 (last updated February 13, 2025)
An improper privilege vulnerability was reported in a BIOS customization feature of Lenovo Vantage on SMB notebook devices which could allow a local attacker to elevate privileges on the system.
This vulnerability only affects Vantage installed on these devices:
* Lenovo V Series (Gen 5)
* ThinkBook 14 (Gen 6, 7)
* ThinkBook 16 (Gen 6, 7)
* ThinkPad E Series (Gen 1)
0
Attacker Value
Unknown
CVE-2024-45102
Disclosure Date: January 14, 2025 (last updated January 15, 2025)
A privilege escalation vulnerability was discovered that could allow a valid, authenticated LXCA user to escalate their permissions for a connected XCC instance when using LXCA as a Single Sign On (SSO) provider for XCC instances.
0
Attacker Value
Unknown
CVE-2024-10254
Disclosure Date: January 14, 2025 (last updated January 15, 2025)
A potential buffer overflow vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a system crash.
0
Attacker Value
Unknown
CVE-2024-10253
Disclosure Date: January 14, 2025 (last updated January 15, 2025)
A potential TOCTOU vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a system crash.
0
Attacker Value
Unknown
CVE-2024-8058
Disclosure Date: December 16, 2024 (last updated December 18, 2024)
An improper parsing vulnerability was reported in the FileZ client that could allow a crafted file in the FileZ directory to read arbitrary files on the device due to URL preloading.
0
Attacker Value
Unknown
CVE-2024-6001
Disclosure Date: December 16, 2024 (last updated December 18, 2024)
An improper certificate validation vulnerability was reported in LADM that could allow a network attacker with the ability to redirect an update request to a remote server and execute code with elevated privileges.
0