Vulnerability index

Browse CVEs

332 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Vantage HIGH 7.8
CVE-2023-6043

A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker to bypass integrity checks and execute arbitrar…

Fix: 4.0.49.0+
Fix from $1,950 2024-01-19
Vantage MEDIUM 6.8
CVE-2023-6044

A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker with physical access to impersonate Lenovo Vant…

Fix: 4.0.49.0+
Fix from $1,600 2024-01-19
App Store MEDIUM 5.5
CVE-2023-6450

An incorrect permissions vulnerability was reported in the Lenovo App Store app that could allow an attacker to use system resources, resulting in a …

Fix: 12.4.20+
Fix from $1,600 2024-01-19
Universal Device Client HIGH 7.8
CVE-2023-6338

Uncontrolled search path vulnerabilities were reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local access to …

Fix: 23.10+
Fix from $1,950 2024-01-03
Browser Hd HIGH 7.5
CVE-2023-6540

A vulnerability was reported in the Lenovo Browser Mobile and Lenovo Browser HD Apps for Android that could allow an attacker to craft a payload that…

Fix: 2.1.4.1 / 9.1.3.1+
Fix from $1,950 2024-01-03
Ideacentre C5 14imb05 Firmware MEDIUM 6.7
CVE-2023-45076

A memory leakage vulnerability was reported in the 534D0140 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM var…

Mitigation only
Fix from $1,600 2023-11-08
Ideacentre C5 14imb05 Firmware MEDIUM 6.7
CVE-2023-45077

A memory leakage vulnerability was reported in the 534D0740 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM var…

Mitigation only
Fix from $1,600 2023-11-08
Ideacentre C5 14imb05 Firmware MEDIUM 6.7
CVE-2023-45078

A memory leakage vulnerability was reported in the DustFilterAlertSmm SMM driver that may allow a local attacker with elevated privileges to write to…

Mitigation only
Fix from $1,600 2023-11-08
Ideacentre C5 14imb05 Firmware MEDIUM 6.7
CVE-2023-45079

A memory leakage vulnerability was reported in the NvmramSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM va…

Mitigation only
Fix from $1,600 2023-11-08
Ideacentre C5 14imb05 Firmware MEDIUM 6.7
CVE-2023-43578

A buffer overflow was reported in the SmiFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to exe…

Mitigation only
Fix from $1,600 2023-11-08
Ideacentre C5 14imb05 Firmware MEDIUM 6.7
CVE-2023-43579

A buffer overflow was reported in the SmuV11Dxe driver in some Lenovo Desktop products that may allow a local attacker with elevated privileges to ex…

Mitigation only
Fix from $1,600 2023-11-08
Ideacentre C5 14imb05 Firmware MEDIUM 6.7
CVE-2023-43580

A buffer overflow was reported in the SmuV11DxeVMR module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to…

Mitigation only
Fix from $1,600 2023-11-08
Ideacentre C5 14imb05 Firmware MEDIUM 6.7
CVE-2023-43581

A buffer overflow was reported in the Update_WMI module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to e…

Mitigation only
Fix from $1,600 2023-11-08
Ideacentre C5 14imb05 Firmware MEDIUM 6.7
CVE-2023-45075

A memory leakage vulnerability was reported in the SWSMI_Shadow DXE driver that may allow a local attacker with elevated privileges to write to NVRAM…

Mitigation only
Fix from $1,600 2023-11-08
Ideacentre C5 14imb05 Firmware MEDIUM 6.7
CVE-2023-43573

A buffer overflow was reported in the LEMALLDriversConnectedEventHook module in some Lenovo Desktop products that may allow a local attacker with ele…

Mitigation only
Fix from $1,600 2023-11-08
Ideacentre C5 14imb05 Firmware MEDIUM 6.7
CVE-2023-43575

A buffer overflow was reported in the UltraFunctionTable module in some Lenovo Desktop products that may allow a local attacker with elevated privile…

Mitigation only
Fix from $1,600 2023-11-08
Ideacentre C5 14imb05 Firmware MEDIUM 6.7
CVE-2023-43576

A buffer overflow was reported in the WMISwSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to exe…

Mitigation only
Fix from $1,600 2023-11-08
Ideacentre C5 14imb05 Firmware MEDIUM 6.7
CVE-2023-43577

A buffer overflow was reported in the ReFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to exec…

Mitigation only
Fix from $1,600 2023-11-08
Ideacentre C5 14imb05 Firmware MEDIUM 6.7
CVE-2023-43571

A buffer overflow was reported in the BiosExtensionLoader module in some Lenovo Desktop products that may allow a local attacker with elevated privil…

Mitigation only
Fix from $1,600 2023-11-08
Lecloud HIGH 7.5
CVE-2023-5079

Lenovo LeCloud App improper input validation allows attackers to access arbitrary components and arbitrary file downloads, which could result in info…

Fix: 7.0.25.99+
Fix from $1,950 2023-11-08
System Update HIGH 7.8
CVE-2023-4632

An uncontrolled search path vulnerability was reported in Lenovo System Update that could allow an attacker with local access to execute code with el…

Fix: 5.08.02.25+
Fix from $1,950 2023-11-08
Preload Directory HIGH 7.8
CVE-2023-4706

A privilege escalation vulnerability was reported in Lenovo preloaded devices deployed using Microsoft AutoPilot under a standard user account due to…

Mitigation only
Fix from $1,950 2023-11-08
Ideapad Duet 3 10igl5 Firmware MEDIUM 6.7
CVE-2023-5075

A buffer overflow was reported in the FmpSipoCapsuleDriver driver in the IdeaPad Duet 3-10IGL5 that may allow a local attacker with elevated privileg…

Mitigation only
Fix from $1,600 2023-11-08
Thinkpad X13 Gen 3 Firmware MEDIUM 6.7
CVE-2023-5078

A vulnerability was reported in some ThinkPad BIOS that could allow a physical or local attacker with elevated privileges to tamper with BIOS firmwar…

Fix: 1.19+
Fix from $1,600 2023-11-08
View Driver MEDIUM 5.5
CVE-2023-4891

A potential use-after-free vulnerability was reported in the Lenovo View driver that could result in denial of service.

Fix: 2.3.18.1+
Fix from $1,600 2023-11-08
Ideacentre C5 14imb05 Firmware MEDIUM 6.7
CVE-2023-43570

A potential vulnerability was reported in the SMI callback function of the OemSmi driver that may allow a local attacker with elevated permissions to…

Mitigation only
Fix from $1,600 2023-11-08
Ideacentre C5 14imb05 Firmware MEDIUM 6.7
CVE-2023-43567

A buffer overflow was reported in the LemSecureBootForceKey module in some Lenovo Desktop products that may allow a local attacker with elevated priv…

Mitigation only
Fix from $1,600 2023-11-08
Ideacentre C5 14imb05 Firmware MEDIUM 6.7
CVE-2023-43569

A buffer overflow was reported in the OemSmi module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execu…

Mitigation only
Fix from $1,600 2023-11-08
Thinkpad X13 Yoga Gen 2 Firmware MEDIUM 6.7
CVE-2022-4574

An SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges t…

Fix: 1.26 / 1.30+
Fix from $1,600 2023-10-30
Thinkpad 25 Firmware MEDIUM 6.7
CVE-2022-4575

A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attacker with phys…

Fix: 1.45 / 1.49+
Fix from $1,600 2023-10-30