Vulnerability index

Browse CVEs

332 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2017-3764 A vulnerability was identified in Lenovo XClarity Administrator (LXCA) before 1.4.0 where LXCA user account names may be exposed to unauthenticated u… Xclarity Administrator 1.4.0+ Fix from $1,6002017-11-30 HIGH 7.5 CVE-2017-3771 System boot process is not adequately secured In Lenovo E95 and ThinkCentre M710s/M710t because systems were shipped from factory without completing … Thinkcentre M710s Firmware Mitigation only Fix from $1,9502017-10-26 CRITICAL 9.8 CVE-2017-3758 Improper access controls on several Android components in the Lenovo Service Framework application can be exploited to enable remote code execution. Service Framework Patch available Fix from $2,3002017-10-17 CRITICAL 9.8 CVE-2017-3761 The Lenovo Service Framework Android application executes some system commands without proper sanitization of external input. In certain cases, this … Service Framework Patch available Fix from $2,3002017-10-17 HIGH 8.1 CVE-2017-3759 The Lenovo Service Framework Android application accepts some responses from the server without proper validation. This exposes the application to ma… Service Framework Patch available Fix from $1,9502017-10-17 HIGH 8.1 CVE-2017-3760 The Lenovo Service Framework Android application uses a set of nonsecure credentials when performing integrity verification of downloaded application… Service Framework Patch available Fix from $1,9502017-10-17 HIGH 7.8 CVE-2015-6971 Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0013 allows local users to submit commands to the System Update service (SUSer… System Update after 5.06.0034 Fix from $1,9502017-10-03 MEDIUM 6.7 CVE-2015-3321 Services and files in Lenovo Fingerprint Manager before 8.01.42 have incorrect ACLs, which allows local users to invalidate local checks and gain pri… Fingerprint Manager after 8.01.41 Fix from $1,6002017-10-03 HIGH 8.8 CVE-2017-3770 Privilege escalation vulnerability in LXCA versions earlier than 1.3.2 where an authenticated user may be able to abuse certain web interface functio… Xclarity Administrator after 1.3.1 Fix from $1,9502017-09-22 MEDIUM 6.7 CVE-2017-3763 An attacker who obtains access to the location where the LXCA file system is stored may be able to access credentials of local LXCA accounts in LXCA … Xclarity Administrator after 1.3.1 Fix from $1,6002017-09-22 HIGH 7.8 CVE-2017-3746 ThinkPad USB 3.0 Ethernet Adapter (part number 4X90E51405) driver, various versions, was found to contain a privilege escalation vulnerability that c… Thinkpad Usb 3.0 Ethernet Adapter Driver Patch available Fix from $1,9502017-08-29 HIGH 7.8 CVE-2017-3756 A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attac… Thinkpad 10 Ella 2 Bios Mitigation only Fix from $1,9502017-08-18 HIGH 7.8 CVE-2017-3751 An unquoted service path vulnerability was identified in the driver for the ThinkPad Compact USB Keyboard with TrackPoint versions earlier than 1.5.5… Thinkpad Compact Usb Keyboard Driver Patch available Fix from $1,9502017-08-10 MEDIUM 6.8 CVE-2017-3753 A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnera… Ideacentre 300 20ish Firmware Mitigation only Fix from $1,6002017-08-10 MEDIUM 6.7 CVE-2017-3754 Some Lenovo brand notebook systems do not have write protections properly configured in the system BIOS. This could enable an attacker with physical … Bios Mitigation only Fix from $1,6002017-07-17 MEDIUM 5.5 CVE-2017-3747 Privilege escalation vulnerability in Lenovo Nerve Center for Windows 10 on Desktop systems (Lenovo Nerve Center for notebook systems is not affected… Nerve Center Mitigation only Fix from $1,6002017-06-29 HIGH 7.8 CVE-2017-3745 In Lenovo XClarity Administrator (LXCA) before 1.3.0, if service data is downloaded from LXCA, a non-administrative user may have access to password … Xclarity Administrator after 1.2.2 Fix from $1,9502017-06-20 HIGH 7.5 CVE-2017-3743 If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced Settings Utili… Advanced Settings Utility after 10.2 Fix from $1,9502017-06-20 MEDIUM 6.5 CVE-2017-3744 In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture … Integrated Management Module Firmware after 6.19 Fix from $1,6002017-06-20 HIGH 7.8 CVE-2015-4596 Lenovo Mouse Suite before 6.73 allows local users to run arbitrary code with administrator privileges. Mouse Suite after 6.72 Fix from $1,9502017-06-13 HIGH 8.8 CVE-2016-8229 A cross-site request forgery vulnerability in Lenovo Service Bridge before version 4 could be exploited by an attacker with access to the DHCP server… Lenovo Service Bridge Mitigation only Fix from $1,9502017-06-04 HIGH 7.8 CVE-2016-8228 In Lenovo Service Bridge before version 4, a user with local privileges on a system could execute code with administrative privileges. Lenovo Service Bridge Mitigation only Fix from $1,9502017-06-04 HIGH 7.5 CVE-2016-8230 In Lenovo Service Bridge before version 4, an insecure HTTP connection is used by LSB to send system serial number, machine type and model and produc… Lenovo Service Bridge Mitigation only Fix from $1,9502017-06-04 HIGH 7.5 CVE-2016-8231 In Lenovo Service Bridge before version 4, a bug found in the signature verification logic of the code signing certificate could be exploited by an a… Lenovo Service Bridge Mitigation only Fix from $1,9502017-06-04 MEDIUM 5.5 CVE-2017-3740 In Lenovo Active Protection System before 1.82.0.14, an attacker with local privileges could send commands to the system's embedded controller, which… Active Protection System Mitigation only Fix from $1,6002017-06-04 HIGH 7.8 CVE-2016-1876 The backend service process in Lenovo Solution Center (aka LSC) before 3.3.0002 allows local users to gain SYSTEM privileges via unspecified vectors. Solution Center after 3.3.0001 Fix from $1,9502017-05-23 HIGH 7.8 CVE-2015-8110 Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by navigating to (1) "Click here to… Lenovo System Update after 5.07.0013 Fix from $1,9502017-04-24 HIGH 7.0 CVE-2015-8109 Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by making a prediction of tvsu_tmp_… Lenovo System Update after 5.07.0013 Fix from $1,9502017-04-24 HIGH 8.1 CVE-2016-8237 Remote code execution in Lenovo Updates (not Lenovo System Update) allows man-in-the-middle attackers to execute arbitrary code. Updates Mitigation only Fix from $1,9502017-04-10 HIGH 7.8 CVE-2016-8235 Privilege escalation in Lenovo Customer Care Software Development Kit (CCSDK) versions earlier than 2.0.16.3 allows local users to execute code with … Customer Care Software Development Kit after 2.0.16 Fix from $1,9502017-04-10