Vulnerability index

Browse CVEs

332 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2016-8236 Reset to default settings may occur in Lenovo ThinkServer TSM RD350, RD450, RD550, RD650, TD350 during a prolonged broadcast storm in TSM versions ea… Thinkserver Firmware after 3.76.208 Fix from $1,9502017-03-03 CRITICAL 9.8 CVE-2016-8233 Log files generated by Lenovo XClarity Administrator (LXCA) versions earlier than 1.2.2 may contain user credentials in a non-secure, clear text form… Xclarity Administrator after 1.2.1 Fix from $2,3002017-03-01 HIGH 7.8 CVE-2016-8225 Unquoted service path vulnerability in Lenovo Edge and Lenovo Slim USB Keyboard Driver versions earlier than 1.21 allows local users to execute code … Edge Keyboard Driver after 1.20 Fix from $1,9502017-01-26 HIGH 7.8 CVE-2016-8227 Privilege escalation vulnerability in Lenovo Transition application used in Lenovo Yoga, Flex and Miix systems running Windows allows local users to … Transition Mitigation only Fix from $1,9502017-01-26 HIGH 7.0 CVE-2016-8221 Privilege Escalation in Lenovo XClarity Administrator earlier than 1.2.0, if LXCA is used to manage rack switches or chassis with embedded input/outp… Xclarity Administrator after 1.1.1 Fix from $1,9502017-01-12 HIGH 7.8 CVE-2016-8223 During an internal security review, Lenovo identified a local privilege escalation vulnerability in Lenovo System Interface Foundation software insta… System Interface Foundation after 1.0.66.0 Fix from $1,9502016-11-29 HIGH 7.8 CVE-2016-5247 The BIOS for Lenovo ThinkCentre E93, M6500t/s, M6600, M6600q, M6600t/s, M73p, M800, M83, M8500t/s, M8600t/s, M900, M93, and M93P devices; ThinkServer… Bios Mitigation only Fix from $1,9502016-09-22 HIGH 8.2 CVE-2016-5729 Lenovo BIOS EFI Driver allows local administrators to execute arbitrary code with System Management Mode (SMM) privileges via unspecified vectors. Bios Efi Driver Mitigation only Fix from $1,9502016-06-30 HIGH 7.8 CVE-2016-5249 Lenovo Solution Center (LSC) before 3.3.003 allows local users to execute arbitrary code with LocalSystem privileges via vectors involving the LSC.Se… Solution Center after 3.3.002 Fix from $1,9502016-06-30 MEDIUM 5.5 CVE-2016-5248 The StopProxy command in LSC.Services.SystemService in Lenovo Solution Center before 3.3.003 allows local users to terminate arbitrary processes via … Solution Center after 3.3.002 Fix from $1,6002016-06-30 HIGH 7.5 CVE-2016-3944 UpdateAgent in Lenovo Accelerator Application allows man-in-the-middle attackers to execute arbitrary code by spoofing an update response from susapi… Accelerator Application Mitigation only Fix from $1,9502016-06-03 MEDIUM 6.1 CVE-2016-4783 Cross-site scripting (XSS) vulnerability in Lenovo SHAREit before 3.5.98_ww on Android before 4.4 allows remote attackers to inject arbitrary web scr… Shareit Mitigation only Fix from $1,6002016-05-23 HIGH 8.8 CVE-2016-4782 Lenovo SHAREit before 3.5.98_ww on Android before 4.2 allows remote attackers to have unspecified impact via a crafted intent: URL, aka an "intent sc… Shareit Mitigation only Fix from $1,9502016-05-23 MEDIUM 5.3 CVE-2015-8108 The management interface in LenovoEMC EZ Media & Backup (hm3), ix2/ix2-dl, ix4-300d, px12-400r/450r, px6-300d, px2-300d, px4-300r, px4-400d, px4-400r… Emc Firmware Mitigation only Fix from $1,6002016-04-12 HIGH 7.8 CVE-2016-2393 Lenovo Fingerprint Manager before 8.01.57 and Touch Fingerprint before 1.00.08 use weak ACLs for unspecified (1) services and (2) files, which allows… Fingerprint Manager after 8.01.56 Fix from $1,9502016-04-11 MEDIUM 6.1 CVE-2016-1492 The Wifi hotspot in Lenovo SHAREit before 3.5.48_ww for Android, when configured to receive files, does not require a password, which makes it easier… Shareit No fix yet Fix from $1,6002016-01-26 HIGH 8.8 CVE-2016-1491 The Wifi hotspot in Lenovo SHAREit before 3.2.0 for Windows, when configured to receive files, has a hardcoded password of 12345678, which makes it e… Shareit after 2.5.1.1 Fix from $1,9502016-01-26 HIGH 8.0 CVE-2016-1489 Lenovo SHAREit before 3.2.0 for Windows and SHAREit before 3.5.48_ww for Android transfer files in cleartext, which allows remote attackers to (1) ob… Shareit after 3.0.18_ww Fix from $1,9502016-01-26 HIGH 7.1 CVE-2015-7820 Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8… Switch Center after 8.1.1.0 Fix from $1,9502015-11-12 MEDIUM 5.0 CVE-2015-7819 The DB service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain… Switch Center after 8.1.1.0 Fix from $1,6002015-11-12 MEDIUM 6.9 CVE-2015-2234 Race condition in Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses world-writable permissions for the update files di… System Update after 5.06.0027 Fix from $1,6002015-05-12 HIGH 8.3 CVE-2015-2233 Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 does not properly validate CA chains during signature validation, which a… System Update after 5.06.0027 Fix from $1,9502015-05-12 HIGH 7.2 CVE-2015-2219 Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allows local users to gain privil… System Update after 5.06.0027 Fix from $1,9502015-05-12 MEDIUM 5.0 CVE-2015-3323 The ThinkServer System Manager (TSM) Baseboard Management Controller before firmware 1.27.73476 for ThinkServer RD350, RD450, RD550, RD650, and TD350… Thinkserver System Manager Baseboard Management Controller Firmware after 118.71532. Fix from $1,6002015-04-16 MEDIUM 5.0 CVE-2015-3322 Lenovo ThinkServer RD350, RD450, RD550, RD650, and TD350 servers before 1.26.0 use weak encryption to store (1) user and (2) administrator BIOS passw… Thinkserver Rd650 Firmware after 1.25.0 Fix from $1,6002015-04-16 HIGH 9.3 CVE-2013-1361EPSS 6% Untrusted search path vulnerability in Lenovo Thinkpad Bluetooth with Enhanced Data Rate Software 6.4.0.2900 and earlier allows local users, and poss… Thinkpad Bluetooth With Enhanced Data Rate Software after 6.4.0.2900 Fix from $1,9502014-01-21 MEDIUM 6.9 CVE-2009-0655 Lenovo Veriface III allows physically proximate attackers to login to a Windows account by presenting a "plain image" of the authorized user. Veriface No fix yet Fix from $1,6002009-02-20 HIGH 7.2 CVE-2008-4589 Heap-based buffer overflow in the tvtumin.sys kernel driver in Lenovo Rescue and Recovery 4.20, including 4.20.0511 and 4.20.0512, allows local users… Resuce And Recovery Patch available Fix from $1,9502008-10-15 MEDIUM 5.1 CVE-2008-3249 The client in Lenovo System Update before 3.14 does not properly validate the certificate when establishing an SSL connection, which allows remote at… Thinkvantage System Update after 3.13.0005 Fix from $1,6002008-07-21 MEDIUM 5.8 CVE-2007-2240 The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Au… Access Support Mitigation only Fix from $1,6002007-08-15