Vulnerability index

Browse CVEs

332 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2019-6188 The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W… 510 15ikl Firmware Mitigation only Fix from $2,3002019-11-12 MEDIUM 6.4 CVE-2019-6170 A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo Th… 510 15ikl Firmware Mitigation only Fix from $1,6002019-11-12 MEDIUM 6.4 CVE-2019-6172 A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo Th… 510 15ikl Firmware Mitigation only Fix from $1,6002019-11-12 HIGH 7.5 CVE-2019-6175 A denial of service vulnerability was reported in Lenovo System Update versions prior to 5.07.0088 that could allow configuration files to be written… System Update 5.07.0088+ Fix from $1,9502019-09-26 HIGH 7.5 CVE-2019-6161 An internal product security audit discovered a session handling vulnerability in the web interface of ThinkAgile CP-SB (Storage Block) BMC in firmwa… Cp Storage Block Firmware 1908.m+ Fix from $1,9502019-09-26 HIGH 7.5 CVE-2019-6179 An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) prior to version 2.5.0 , Lenovo XClarity I… Xclarity Administrator 2.5.0 / 6.1.0+ Fix from $1,9502019-09-03 MEDIUM 6.1 CVE-2019-6181 A reflected cross-site scripting (XSS) vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.5.0 that could allow a … Xclarity Administrator 2.5.0+ Fix from $1,6002019-09-03 MEDIUM 6.5 CVE-2019-10724 There is a vulnerability with the Dolby DAX2 API system services in which a low-privileged user can terminate arbitrary processes that are running at… Legion Y520t Z370 Firmware 6.0.1.8642+ Fix from $1,6002019-08-29 CRITICAL 9.8 CVE-2019-6177 A vulnerability reported in Lenovo Solution Center version 03.12.003, which is no longer supported, could allow log files to be written to non-standa… Solution Center Mitigation only Fix from $2,3002019-08-21 MEDIUM 5.3 CVE-2019-6178 An information leakage vulnerability in Iomega and LenovoEMC NAS products could allow disclosure of some device details such as Share names through t… Px12 350r Firmware Mitigation only Fix from $1,6002019-08-19 HIGH 7.8 CVE-2019-6165 A DLL search path vulnerability was reported in PaperDisplay Hotkey Service version 1.2.0.8 that could allow privilege escalation. Lenovo has ended s… Yoga 700 11isk Firmware Mitigation only Fix from $1,9502019-08-19 MEDIUM 6.8 CVE-2019-6171 A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or physical ac… 20f1 Firmware Mitigation only Fix from $1,6002019-08-19 MEDIUM 6.1 CVE-2019-6159 A stored cross-site scripting (XSS) vulnerability exists in various firmware versions of the legacy IBM System x IMM (IMM v1) embedded Baseboard Mana… Bladecenter Hs22 Firmware Mitigation only Fix from $1,6002019-08-19 HIGH 7.5 CVE-2019-6160 A vulnerability in various versions of Iomega and LenovoEMC NAS products could allow an unauthenticated user to access files on NAS shares via the AP… Px12 350r Firmware 2.1.50.30227 / 3.2.16.30221+ Fix from $1,9502019-07-16 CRITICAL 9.8 CVE-2019-6167 A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution. Service Bridge 4.1.0.1+ Fix from $2,3002019-06-26 CRITICAL 9.8 CVE-2019-6168 A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow remote code execution. Service Bridge 4.1.0.1+ Fix from $2,3002019-06-26 HIGH 8.8 CVE-2019-6166 A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow cross-site request forgery. Service Bridge 4.1.0.1+ Fix from $1,9502019-06-26 HIGH 7.5 CVE-2019-6163 A denial of service vulnerability was reported in Lenovo System Update before version 5.07.0084 that could allow service log files to be written to n… System Update 5.07.0084+ Fix from $1,9502019-06-26 HIGH 7.5 CVE-2019-6169 A vulnerability reported in Lenovo Service Bridge before version 4.1.0.1 could allow unencrypted downloads over FTP. Service Bridge 4.1.0.1+ Fix from $1,9502019-06-26 MEDIUM 5.9 CVE-2019-6158 An internal product security audit of Lenovo XClarity Administrator (LXCA) discovered HTTP proxy credentials being written to a log file in clear tex… Xclarity Administrator 2.4.0+ Fix from $1,6002019-05-03 HIGH 7.5 CVE-2019-6157 In various firmware versions of Lenovo System x, the integrated management module II (IMM2)'s first failure data capture (FFDC) includes the web serv… Flex System X240 M4 Firmware 5.30+ Fix from $1,9502019-04-22 HIGH 7.8 CVE-2019-6154 A DLL search path vulnerability was reported in Lenovo Bootable Generator, prior to version Mar-2019, that could allow a malicious user with local ac… Bootable Usb Patch available Fix from $1,9502019-04-10 MEDIUM 6.7 CVE-2019-6149 An unquoted search path vulnerability was identified in Lenovo Dynamic Power Reduction Utility prior to version 2.2.2.0 that could allow a malicious … Dynamic Power Reduction 2.2.2.0+ Fix from $1,6002019-03-18 HIGH 7.8 CVE-2018-16098 In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing Device driver which could all… Synaptics Thinkpad Ultranav Driver Patch available Fix from $1,9502019-01-24 MEDIUM 6.5 CVE-2018-16093 In versions prior to 5.5, LXCI for VMware allows an authenticated user to write to any system file due to insufficient sanitization during the upload… Xclarity Integrator 5.5+ Fix from $1,6002018-11-30 MEDIUM 6.5 CVE-2018-16097 LXCI for VMware versions prior to 5.5 and LXCI for Microsoft System Center versions prior to 3.5, allow an authenticated user to write to any system … Xclarity Integrator 3.5 / 5.5+ Fix from $1,6002018-11-30 MEDIUM 6.5 CVE-2018-9072 In versions prior to 5.5, LXCI for VMware allows an authenticated user to download any system file due to insufficient input sanitization during file… Xclarity Integrator 5.5+ Fix from $1,6002018-11-30 HIGH 8.1 CVE-2018-16091 In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable to several buffer overflows. System Management Module Firmware 1.06+ Fix from $1,9502018-11-27 HIGH 8.1 CVE-2018-16092 In System Management Module (SMM) versions prior to 1.06, the FFDC feature includes the collection of SMM system files containing sensitive informati… System Management Module Firmware 1.06+ Fix from $1,9502018-11-27 HIGH 8.1 CVE-2018-16094 In System Management Module (SMM) versions prior to 1.06, an internal SMM function that retrieves configuration settings is prone to a buffer overflo… System Management Module Firmware 1.06+ Fix from $1,9502018-11-27