VYPR

Vendor CVEs

Intel

All CVEs

2,357 total · sorted by risk
  • CVE-2024-21781HigSep 16, 2024
    risk 0.47cvss 7.2epss 0.00

    Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to enable information disclosure or denial of service via local access.

  • CVE-2024-24853HigAug 14, 2024
    risk 0.47cvss 7.2epss 0.00

    Incorrect behavior order in transition between executive monitor and SMI transfer monitor (STM) in some Intel(R) Processor may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2024-22095HigMay 16, 2024
    risk 0.47cvss 7.2epss 0.00

    Improper input validation in PlatformVariableInitDxe driver in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged user to enable escalation of privilege via local access.

  • CVE-2023-40071HigMay 16, 2024
    risk 0.47cvss 7.3epss 0.00

    Improper access control in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-28402HigMay 16, 2024
    risk 0.47cvss 7.2epss 0.00

    Improper input validation in some Intel(R) BIOS Guard firmware may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-27504HigMay 16, 2024
    risk 0.47cvss 7.2epss 0.00

    Improper conditions check in some Intel(R) BIOS Guard firmware may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2022-37341HigMay 16, 2024
    risk 0.47cvss 7.2epss 0.00

    Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-32666HigMar 14, 2024
    risk 0.47cvss 7.2epss 0.00

    On-chip debug and test interface with improper access control in some 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-32282HigMar 14, 2024
    risk 0.47cvss 7.2epss 0.00

    Race condition in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2021-33161HigFeb 23, 2024
    risk 0.47cvss 7.2epss 0.00

    Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2021-33158HigFeb 23, 2024
    risk 0.47cvss 7.2epss 0.00

    Improper neutralization in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2021-33157HigFeb 23, 2024
    risk 0.47cvss 7.2epss 0.00

    Insufficient control flow management in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2021-33145HigFeb 23, 2024
    risk 0.47cvss 7.2epss 0.00

    Uncaught exception in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-32544HigJan 19, 2024
    risk 0.47cvss 7.3epss 0.00

    Improper access control in some Intel HotKey Services for Windows 10 for Intel NUC P14E Laptop Element software installers before version 1.1.45 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2023-32641HigNov 14, 2023
    risk 0.47cvss 7.3epss 0.00

    Improper input validation in firmware for Intel(R) QAT before version QAT20.L.1.0.40-00004 may allow escalation of privilege and denial of service via adjacent access.

  • CVE-2023-24592HigNov 14, 2023
    risk 0.47cvss 7.3epss 0.00

    Path traversal in the some Intel(R) oneAPI Toolkits and Component software before version 2023.1 may allow authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-22292HigNov 14, 2023
    risk 0.47cvss 7.3epss 0.00

    Uncaught exception for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-41689HigNov 14, 2023
    risk 0.47cvss 7.3epss 0.00

    Improper access control in some Intel In-Band Manageability software before version 3.0.14 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2023-25757HigAug 11, 2023
    risk 0.47cvss 7.3epss 0.00

    Improper access control in some Intel(R) Unison(TM) software before version 10.12 may allow a privileged user to potentially enable escalation of privilege via network access.

  • CVE-2022-45112HigAug 11, 2023
    risk 0.47cvss 7.3epss 0.00

    Improper access control in some Intel(R) VROC software before version 8.0.0.4035 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-41804HigAug 11, 2023
    risk 0.47cvss 7.2epss 0.00

    Unauthorized error injection in Intel(R) SGX or Intel(R) TDX for some Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2022-38102HigAug 11, 2023
    risk 0.47cvss 7.2epss 0.00

    Improper Input validation in firmware for some Intel(R) Converged Security and Management Engine before versions 15.0.45, and 16.1.27 may allow a privileged user to potentially enable denial of service via local access.

  • CVE-2022-37343HigAug 11, 2023
    risk 0.47cvss 7.2epss 0.00

    Improper access control in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-30763HigMay 12, 2023
    risk 0.47cvss 7.2epss 0.00

    Heap-based overflow in Intel(R) SoC Watch based software before version 2021.1 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2023-22312HigMay 10, 2023
    risk 0.47cvss 7.2epss 0.00

    Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2022-42465HigMay 10, 2023
    risk 0.47cvss 7.2epss 0.00

    Improper access control in kernel mode driver for the Intel(R) OFU software before version 14.1.30 may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2022-32766HigMay 10, 2023
    risk 0.47cvss 7.2epss 0.00

    Improper input validation for some Intel(R) BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2022-36397HigFeb 16, 2023
    risk 0.47cvss 7.3epss 0.00

    Incorrect default permissions in the software installer for some Intel(R) QAT drivers for Linux before version 4.17 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-33196HigFeb 16, 2023
    risk 0.47cvss 7.2epss 0.00

    Incorrect default permissions in some memory controller configurations for some Intel(R) Xeon(R) Processors when using Intel(R) Software Guard Extensions which may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2022-33902HigFeb 16, 2023
    risk 0.47cvss 7.3epss 0.00

    Insufficient control flow management in the Intel(R) Quartus Prime Pro and Standard edition software may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-33892HigFeb 16, 2023
    risk 0.47cvss 7.3epss 0.00

    Path traversal in the Intel(R) Quartus Prime Pro and Standard edition software may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-30704HigFeb 16, 2023
    risk 0.47cvss 7.2epss 0.00

    Improper initialization in the Intel(R) TXT SINIT ACM for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

  • CVE-2022-26840HigFeb 16, 2023
    risk 0.47cvss 7.3epss 0.00

    Improper neutralization in the Intel(R) Quartus Prime Pro and Standard edition software may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-29466HigNov 11, 2022
    risk 0.47cvss 7.3epss 0.00

    Improper input validation in firmware for Intel(R) SPS before version SPS_E3_04.01.04.700.0 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2022-40246HigSep 20, 2022
    risk 0.47cvss 7.2epss 0.00

    A potential attacker can write one byte by arbitrary address at the time of the PEI phase (only during S3 resume boot mode) and influence the subsequent boot stages. This can lead to the mitigations bypassing, physical memory contents disclosure, discovery of any secrets from…

  • CVE-2022-32579HigAug 18, 2022
    risk 0.47cvss 7.2epss 0.00

    Improper initialization in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentially enable escalation of privilege via physical access.

  • CVE-2022-22139HigMay 12, 2022
    risk 0.47cvss 7.3epss 0.00

    Uncontrolled search path in the Intel(R) XTU software before version 7.3.0.33 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2021-0194HigMay 12, 2022
    risk 0.47cvss 7.2epss 0.01

    Improper access control in the Intel(R) In-Band Manageability software before version 2.13.0 may allow a privileged user to potentially enable escalation of privilege via network access.

  • CVE-2021-0193HigMay 12, 2022
    risk 0.47cvss 7.2epss 0.01

    Improper authentication in the Intel(R) In-Band Manageability software before version 2.13.0 may allow a privileged user to potentially enable escalation of privilege via network access.

  • CVE-2021-0112HigJun 9, 2021
    risk 0.47cvss 7.3epss 0.00

    Unquoted service path in the Intel Unite(R) Client for Windows before version 4.2.25031 may allow an authenticated user to potentially enable an escalation of privilege via local access.

  • CVE-2021-0108HigJun 9, 2021
    risk 0.47cvss 7.3epss 0.00

    Uncontrolled search path in the Intel Unite(R) Client for Windows before version 4.2.25031 may allow an authenticated user to potentially enable an escalation of privilege via local access.

  • CVE-2021-0090HigJun 9, 2021
    risk 0.47cvss 7.3epss 0.00

    Uncontrolled search path element in Intel(R) DSA before version 20.11.50.9 may allow an authenticated user to potentially enable an escalation of privilege via local access.

  • CVE-2021-0105HigJun 9, 2021
    risk 0.47cvss 7.3epss 0.00

    Insecure inherited permissions in some Intel(R) ProSet/Wireless WiFi drivers may allow an authenticated user to potentially enable information disclosure and denial of service via adjacent access.

  • CVE-2020-8702HigJun 9, 2021
    risk 0.47cvss 7.3epss 0.00

    Uncontrolled search path element in the Intel(R) Processor Diagnostic Tool before version 4.1.5.37 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2020-24451HigFeb 17, 2021
    risk 0.47cvss 7.3epss 0.00

    Uncontrolled search path in the Intel(R) Optane(TM) DC Persistent Memory installer for Windows* before version 1.00.00.3506 may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2019-0164HigJun 13, 2019
    risk 0.47cvss 7.3epss 0.00

    Improper permissions in the installer for Intel(R) Turbo Boost Max Technology 3.0 driver version 1.0.0.1035 and before may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2018-18098HigJan 10, 2019
    risk 0.47cvss 7.3epss 0.00

    Improper file verification in install routine for Intel(R) SGX SDK and Platform Software for Windows before 2.2.100 may allow an escalation of privilege via local access.

  • CVE-2018-3655HigSep 12, 2018
    risk 0.47cvss 7.3epss 0.00

    A vulnerability in a subsystem in Intel CSME before version 11.21.55, Intel Server Platform Services before version 4.0 and Intel Trusted Execution Engine Firmware before version 3.1.55 may allow an unauthenticated user to potentially modify or disclose information via physical…

  • CVE-2017-5753MedJan 4, 2018
    risk 0.47cvss 5.6epss 0.93

    Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.

  • CVE-2017-5712HigNov 21, 2017
    risk 0.47cvss 7.2epss 0.04

    Buffer overflow in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allows attacker with remote Admin access to the system to execute arbitrary code with AMT execution privilege.

Page 16 of 48