Vulnerability index

Browse CVEs

332 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

330 14ast Firmware MEDIUM 6.7
CVE-2020-8323

A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models…

Mitigation only
Fix from $1,600 2020-06-09
Installation Package HIGH 7.3
CVE-2019-6196

A symbolic link vulnerability in some Lenovo installation packages, prior to version 1.2.9.3, could allow privileged file operations during file extr…

Fix: 1.2.9.3+
Fix from $1,950 2020-06-09
Installation Package MEDIUM 6.5
CVE-2019-6173

A DLL search path vulnerability could allow privilege escalation in some Lenovo installation packages, prior to version 1.2.9.3, during installation …

Fix: 1.2.9.3+
Fix from $1,600 2020-06-09
Lj4010dn Firmware HIGH 7.5
CVE-2020-8329

A denial of service vulnerability was reported in the firmware prior to version 1.01 used in Lenovo Printer LJ4010DN that could be triggered by a rem…

Fix: 1.01+
Fix from $1,950 2020-05-28
Lj4010dn Firmware HIGH 7.5
CVE-2020-8330

A denial of service vulnerability was reported in the firmware prior to version 1.01 used in Lenovo Printer LJ4010DN that could be triggered by a rem…

Fix: 1.01+
Fix from $1,950 2020-05-28
Vantage HIGH 7.8
CVE-2020-8327

A privilege escalation vulnerability was reported in LenovoBatteryGaugePackage for Lenovo System Interface Foundation bundled in Lenovo Vantage prior…

Fix: 10.2003.10.0+
Fix from $1,950 2020-04-14
System Interface Foundation MEDIUM 5.5
CVE-2020-8324

A vulnerability was reported in LenovoAppScenarioPluginSystem for Lenovo System Interface Foundation prior to version 1.2.184.31 that could allow uns…

Fix: 1.2.184.31+
Fix from $1,600 2020-04-14
System Interface Foundation HIGH 7.8
CVE-2020-8318

A privilege escalation vulnerability was reported in the LenovoSystemUpdatePlugin for Lenovo System Interface Foundation prior to version that could …

Fix: 2.0.0.92+
Fix from $1,950 2020-04-14
System Interface Foundation HIGH 7.8
CVE-2020-8319

A privilege escalation vulnerability was reported in Lenovo System Interface Foundation prior to version 1.1.19.3 that could allow an authenticated u…

Fix: 1.1.19.3+
Fix from $1,950 2020-04-14
B50 10 Firmware CRITICAL 9.8
CVE-2015-5684

MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A buffer overflow vulnerability was reported, (fixed and publicly…

Mitigation only
Fix from $2,300 2020-03-27
Solution Center HIGH 8.8
CVE-2015-8536

MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was discovered (fixed and publicly disclosed in 2…

Fix: 3.3.002+
Fix from $1,950 2020-03-27
System Update HIGH 7.8
CVE-2015-7333

MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed an…

Fix: after 5.07.0008
Fix from $1,950 2020-03-27
System Update HIGH 7.8
CVE-2015-7334

MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed an…

Fix: after 5.07.0008
Fix from $1,950 2020-03-27
Solution Center HIGH 7.8
CVE-2015-8534

MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was discovered (fixed …

Fix: 3.3.002+
Fix from $1,950 2020-03-27
Solution Center HIGH 7.8
CVE-2015-8535

MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A directory traversal vulnerability was discovered (fixed and pub…

Fix: 3.3.002+
Fix from $1,950 2020-03-27
System Update HIGH 7.5
CVE-2015-7336

MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was reported (fixed and publicly disclosed in 201…

Fix: after 5.07.0008
Fix from $1,950 2020-03-27
System Update HIGH 7.0
CVE-2015-7335

MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A race condition was reported (fixed and publicly disclosed in 20…

Fix: after 5.07.0008
Fix from $1,950 2020-03-27
Xclarity Administrator MEDIUM 6.0
CVE-2019-19756

An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered Windows OS credentials, used to perform driver updates of manag…

Mitigation only
Fix from $1,600 2020-03-13
Xclarity Administrator HIGH 7.5
CVE-2019-6193

An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow unauthenticated…

Fix: 2.6.6+
Fix from $1,950 2020-02-14
Xclarity Administrator MEDIUM 5.5
CVE-2019-6194

An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow i…

Fix: 2.6.6+
Fix from $1,600 2020-02-14
Thinkcentre E93 Firmware MEDIUM 5.5
CVE-2019-6190

Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and …

Mitigation only
Fix from $1,600 2020-02-14
Ez Media \& Backup Center Ix2 Firmware MEDIUM 6.1
CVE-2019-19758

A vulnerability in the web interface of Lenovo EZ Media & Backup Center, ix2 & ix2-dl version 4.1.406.34763 and prior could allow an unauthenticated,…

Fix: after 4.1.406.34763
Fix from $1,600 2020-02-14
Xclarity Administrator MEDIUM 5.4
CVE-2019-19757

An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered a Document Object Model (DOM) based cross-site scripting vulner…

Fix: 2.6.6+
Fix from $1,600 2020-02-14
Energy Management HIGH 7.5
CVE-2019-6183

A denial of service vulnerability has been reported in Lenovo Energy Management Driver for Windows 10 versions prior to 15.11.29.7 that could cause s…

Fix: 15.11.29.7+
Fix from $1,950 2019-12-10
System Interface Foundation HIGH 8.8
CVE-2019-6186

A potential vulnerability was reported in Lenovo System Interface Foundation versions before v1.1.18.3 that could allow an authenticated user to exec…

Fix: 1.1.18.3+
Fix from $1,950 2019-11-20
Customer Engagement Service HIGH 7.8
CVE-2019-6184

A potential vulnerability in the discontinued Customer Engagement Service (CCSDK) software version 2.0.21.1 may allow local privilege escalation.

No fix yet
Fix from $1,950 2019-11-20
System Interface Foundation HIGH 7.8
CVE-2019-6189

A potential vulnerability was reported in Lenovo System Interface Foundation versions before v1.1.18.3 that could allow an administrative user to loa…

Fix: 1.1.18.3+
Fix from $1,950 2019-11-20
Paper HIGH 7.8
CVE-2019-6191

A potential vulnerability in the discontinued LenovoPaper software version 1.0.0.22 may allow local privilege escalation.

Mitigation only
Fix from $1,950 2019-11-20
Thinkpad Usb C Dock Firmware HIGH 7.5
CVE-2019-6176

A potential vulnerability reported in ThinkPad USB-C Dock Firmware version 3.7.2 may allow a denial of service.

Patch available
Fix from $1,950 2019-11-20
Xclarity Controller MEDIUM 6.5
CVE-2019-6187

A stored CSV Injection vulnerability was reported in Lenovo XClarity Controller (XCC) that could allow an administrative or other appropriately permi…

Patch available
Fix from $1,600 2019-11-20