Vendor CVEs
Lenovo
All CVEs
486 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-4606 | 0.00 | — | 0.00 | Oct 24, 2023 | An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected. | |||
| CVE-2022-48183 | 0.00 | — | 0.00 | Oct 9, 2023 | A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access. | |||
| CVE-2022-48182 | 0.00 | — | 0.00 | Oct 9, 2023 | A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access. | |||
| CVE-2022-3728 | 0.00 | — | 0.00 | Oct 9, 2023 | A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access. | |||
| CVE-2022-3431 | 0.00 | — | 0.00 | Oct 9, 2023 | A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable. | |||
| CVE-2022-3746 | 0.00 | — | 0.00 | Aug 23, 2023 | A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to cause some peripherals to work abnormally due to an exposed Embedded Controller (EC) interface. | |||
| CVE-2022-3745 | 0.00 | — | 0.00 | Aug 23, 2023 | A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to view incoming and returned data from SMI. | |||
| CVE-2022-3744 | 0.00 | — | 0.00 | Aug 23, 2023 | A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to unlock UEFI variables due to a hard-coded SMI handler credential. | |||
| CVE-2022-3743 | 0.00 | — | 0.00 | Aug 23, 2023 | A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges under certain conditions the ability to enumerate Embedded Controller (EC) commands. | |||
| CVE-2022-3742 | 0.00 | — | 0.00 | Aug 23, 2023 | A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to execute arbitrary code due to improper buffer validation. | |||
| CVE-2023-34419 | 0.00 | — | 0.00 | Aug 17, 2023 | A buffer overflow has been identified in the SetupUtility driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code. | |||
| CVE-2023-4030 | 0.00 | — | 0.00 | Aug 17, 2023 | A vulnerability was reported in BIOS for ThinkPad P14s Gen 2, P15s Gen 2, T14 Gen 2, and T15 Gen 2 that could cause the system to recover to insecure settings if the BIOS becomes corrupt. | |||
| CVE-2023-4029 | 0.00 | — | 0.00 | Aug 17, 2023 | A buffer overflow has been identified in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products which may allow an attacker with local access and elevated privileges to execute arbitrary code. | |||
| CVE-2023-4028 | 0.00 | — | 0.00 | Aug 17, 2023 | A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code. | |||
| CVE-2023-3078 | 0.00 | — | 0.00 | Aug 17, 2023 | An uncontrolled search path vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local access to execute code with elevated privileges. | |||
| CVE-2023-34422 | 0.00 | — | 0.00 | Jun 26, 2023 | A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a specifically crafted web API call due to insufficient input validation. | |||
| CVE-2023-34421 | 0.00 | — | 0.00 | Jun 26, 2023 | A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically crafted web API call due to insufficient input validation. | |||
| CVE-2023-34420 | 0.00 | — | 0.01 | Jun 26, 2023 | A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted calls to a specific web API. | |||
| CVE-2023-34418 | 0.00 | — | 0.01 | Jun 26, 2023 | A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to a SQL injection vulnerability in a specific web API. | |||
| CVE-2023-3113 | 0.00 | — | 0.01 | Jun 26, 2023 | An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read-only access to specific files. | |||
| CVE-2023-2993 | 0.00 | — | 0.00 | Jun 26, 2023 | A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited number of commands on SMM v1, SMM v2, and FPC that the user does not normally have sufficient privileges to execute. | |||
| CVE-2023-2992 | 0.00 | — | 0.01 | Jun 26, 2023 | An unauthenticated denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered under crafted conditions. Rebooting SMM or FPC will restore access to the management web server. | |||
| CVE-2023-2290 | 0.00 | — | 0.00 | Jun 26, 2023 | A potential vulnerability in the LenovoFlashDeviceInterface SMI handler may allow an attacker with local access and elevated privileges to execute arbitrary code. | |||
| CVE-2022-48188 | 0.00 | — | 0.00 | Jun 5, 2023 | A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local access to elevate their privileges to execute arbitrary code. | |||
| CVE-2022-48181 | 0.00 | — | 0.00 | Jun 5, 2023 | An ErrorMessage driver stack-based buffer overflow vulnerability in BIOS of some ThinkPad models could allow an attacker with local access to elevate their privileges and execute arbitrary code. | |||
| CVE-2022-4569 | 0.00 | — | 0.00 | Jun 5, 2023 | A local privilege escalation vulnerability in the ThinkPad Hybrid USB-C with USB-A Dock Firmware Update Tool could allow an attacker with local access to execute code with elevated privileges during the package upgrade or installation. | |||
| CVE-2022-48186 | 0.00 | — | 0.00 | May 1, 2023 | A certificate validation vulnerability exists in the Baiying Android application which could lead to information disclosure. | |||
| CVE-2022-4568 | 0.00 | — | 0.00 | May 1, 2023 | A directory permissions management vulnerability in Lenovo System Update may allow elevation of privileges. | |||
| CVE-2023-0683 | 0.00 | — | 0.01 | May 1, 2023 | A valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API call. | |||
| CVE-2023-25492 | 0.00 | — | 0.01 | May 1, 2023 | A valid, authenticated user may be able to trigger a denial of service of the XCC web user interface or other undefined behavior through a format string injection vulnerability in a web interface API. | |||
| CVE-2023-0896 | 0.00 | — | 0.00 | May 1, 2023 | A default password was reported in Lenovo Smart Clock Essential with Alexa Built In that could allow unauthorized device access to an attacker with local network access. | |||
| CVE-2023-25495 | 0.00 | — | 0.01 | Apr 28, 2023 | A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenticate to an external LDAP server in certain configurations. There is no exposure where no LDAP client password is configured | |||
| CVE-2023-25496 | 0.00 | — | 0.00 | Apr 28, 2023 | A privilege escalation vulnerability was reported in Lenovo Drivers Management Lenovo Driver Manager that could allow a local user to execute code with elevated privileges. | |||
| CVE-2023-29056 | 0.00 | — | 0.00 | Apr 28, 2023 | A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be configured to use an LDAP server for Authentication/Authorization and have the login permission attribute not defined. | |||
| CVE-2023-29057 | 0.00 | — | 0.01 | Apr 28, 2023 | A valid XCC user's local account permissions overrides their active directory permissions under specific configurations. This could lead to a privilege escalation. To be vulnerable, LDAP must be configured for authentication/authorization and logins configured as “Local First,… | |||
| CVE-2023-29058 | 0.00 | — | 0.00 | Apr 28, 2023 | A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through the XCC CLI. There is no exposure if SSH is disabled or if there are no users assigned optional read-only permissions. | |||
| CVE-2022-34404 | 0.00 | — | 0.00 | Feb 10, 2023 | Dell System Update, version 2.0.0 and earlier, contains an Improper Certificate Validation in data parser module. A local attacker with high privileges could potentially exploit this vulnerability, leading to credential theft and/or denial of service. | |||
| CVE-2022-34888 | 0.00 | — | 0.00 | Jan 30, 2023 | The Remote Mount feature can potentially be abused by valid, authenticated users to make connections to internal services that may not normally be accessible to users. Internal service access controls, as applicable, remain in effect. | |||
| CVE-2022-34884 | 0.00 | — | 0.01 | Jan 30, 2023 | A buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated users to cause a recoverable subsystem denial of service. | |||
| CVE-2022-40137 | 0.00 | — | 0.00 | Jan 30, 2023 | A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code. | |||
| CVE-2022-40136 | 0.00 | — | 0.00 | Jan 30, 2023 | An information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. | |||
| CVE-2022-40135 | 0.00 | — | 0.00 | Jan 30, 2023 | An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. | |||
| CVE-2022-40134 | 0.00 | — | 0.00 | Jan 30, 2023 | An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. | |||
| CVE-2022-4816 | 0.00 | — | 0.00 | Jan 23, 2023 | A denial-of-service vulnerability has been identified in Lenovo Safecenter that could allow a local user to crash the application. | |||
| CVE-2022-3432 | 0.00 | — | 0.00 | Jan 23, 2023 | A potential vulnerability in a driver used during manufacturing process on the Ideapad Y700-14ISK that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable. | |||
| CVE-2022-3430 | 0.00 | — | 0.00 | Jan 23, 2023 | A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable. | |||
| CVE-2022-1892 | 0.00 | — | 0.00 | Jan 23, 2023 | A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code. | |||
| CVE-2022-1891 | 0.00 | — | 0.00 | Jan 23, 2023 | A buffer overflow in the SystemLoadDefaultDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code. | |||
| CVE-2022-1890 | 0.00 | — | 0.00 | Jan 23, 2023 | A buffer overflow in the ReadyBootDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code. | |||
| CVE-2022-1109 | 0.00 | — | 0.00 | Jan 20, 2023 | An incorrect default permissions vulnerability in Lenovo Leyun cloud music application could allow denial of service. |
- CVE-2023-4606Oct 24, 2023risk 0.00cvss —epss 0.00
An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command. This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
- CVE-2022-48183Oct 9, 2023risk 0.00cvss —epss 0.00
A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access.
- CVE-2022-48182Oct 9, 2023risk 0.00cvss —epss 0.00
A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access.
- CVE-2022-3728Oct 9, 2023risk 0.00cvss —epss 0.00
A vulnerability was reported in ThinkPad T14s Gen 3 and X13 Gen3 that could cause the BIOS tamper detection mechanism to not trigger under specific circumstances which could allow unauthorized access.
- CVE-2022-3431Oct 9, 2023risk 0.00cvss —epss 0.00
A potential vulnerability in a driver used during manufacturing process on some consumer Lenovo Notebook devices that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
- CVE-2022-3746Aug 23, 2023risk 0.00cvss —epss 0.00
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to cause some peripherals to work abnormally due to an exposed Embedded Controller (EC) interface.
- CVE-2022-3745Aug 23, 2023risk 0.00cvss —epss 0.00
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to view incoming and returned data from SMI.
- CVE-2022-3744Aug 23, 2023risk 0.00cvss —epss 0.00
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to unlock UEFI variables due to a hard-coded SMI handler credential.
- CVE-2022-3743Aug 23, 2023risk 0.00cvss —epss 0.00
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges under certain conditions the ability to enumerate Embedded Controller (EC) commands.
- CVE-2022-3742Aug 23, 2023risk 0.00cvss —epss 0.00
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to execute arbitrary code due to improper buffer validation.
- CVE-2023-34419Aug 17, 2023risk 0.00cvss —epss 0.00
A buffer overflow has been identified in the SetupUtility driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.
- CVE-2023-4030Aug 17, 2023risk 0.00cvss —epss 0.00
A vulnerability was reported in BIOS for ThinkPad P14s Gen 2, P15s Gen 2, T14 Gen 2, and T15 Gen 2 that could cause the system to recover to insecure settings if the BIOS becomes corrupt.
- CVE-2023-4029Aug 17, 2023risk 0.00cvss —epss 0.00
A buffer overflow has been identified in the BoardUpdateAcpiDxe driver in some Lenovo ThinkPad products which may allow an attacker with local access and elevated privileges to execute arbitrary code.
- CVE-2023-4028Aug 17, 2023risk 0.00cvss —epss 0.00
A buffer overflow has been identified in the SystemUserMasterHddPwdDxe driver in some Lenovo Notebook products which may allow an attacker with local access and elevated privileges to execute arbitrary code.
- CVE-2023-3078Aug 17, 2023risk 0.00cvss —epss 0.00
An uncontrolled search path vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local access to execute code with elevated privileges.
- CVE-2023-34422Jun 26, 2023risk 0.00cvss —epss 0.00
A valid, authenticated LXCA user with elevated privileges may be able to delete folders in the LXCA filesystem through a specifically crafted web API call due to insufficient input validation.
- CVE-2023-34421Jun 26, 2023risk 0.00cvss —epss 0.00
A valid, authenticated LXCA user with elevated privileges may be able to replace filesystem data through a specifically crafted web API call due to insufficient input validation.
- CVE-2023-34420Jun 26, 2023risk 0.00cvss —epss 0.01
A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted calls to a specific web API.
- CVE-2023-34418Jun 26, 2023risk 0.00cvss —epss 0.01
A valid, authenticated LXCA user may be able to gain unauthorized access to events and other data stored in LXCA due to a SQL injection vulnerability in a specific web API.
- CVE-2023-3113Jun 26, 2023risk 0.00cvss —epss 0.01
An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read-only access to specific files.
- CVE-2023-2993Jun 26, 2023risk 0.00cvss —epss 0.00
A valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limited number of commands on SMM v1, SMM v2, and FPC that the user does not normally have sufficient privileges to execute.
- CVE-2023-2992Jun 26, 2023risk 0.00cvss —epss 0.01
An unauthenticated denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered under crafted conditions. Rebooting SMM or FPC will restore access to the management web server.
- CVE-2023-2290Jun 26, 2023risk 0.00cvss —epss 0.00
A potential vulnerability in the LenovoFlashDeviceInterface SMI handler may allow an attacker with local access and elevated privileges to execute arbitrary code.
- CVE-2022-48188Jun 5, 2023risk 0.00cvss —epss 0.00
A buffer overflow vulnerability in the SecureBootDXE BIOS driver of some Lenovo Desktop and ThinkStation models could allow an attacker with local access to elevate their privileges to execute arbitrary code.
- CVE-2022-48181Jun 5, 2023risk 0.00cvss —epss 0.00
An ErrorMessage driver stack-based buffer overflow vulnerability in BIOS of some ThinkPad models could allow an attacker with local access to elevate their privileges and execute arbitrary code.
- CVE-2022-4569Jun 5, 2023risk 0.00cvss —epss 0.00
A local privilege escalation vulnerability in the ThinkPad Hybrid USB-C with USB-A Dock Firmware Update Tool could allow an attacker with local access to execute code with elevated privileges during the package upgrade or installation.
- CVE-2022-48186May 1, 2023risk 0.00cvss —epss 0.00
A certificate validation vulnerability exists in the Baiying Android application which could lead to information disclosure.
- CVE-2022-4568May 1, 2023risk 0.00cvss —epss 0.00
A directory permissions management vulnerability in Lenovo System Update may allow elevation of privileges.
- CVE-2023-0683May 1, 2023risk 0.00cvss —epss 0.01
A valid, authenticated XCC user with read only access may gain elevated privileges through a specifically crafted API call.
- CVE-2023-25492May 1, 2023risk 0.00cvss —epss 0.01
A valid, authenticated user may be able to trigger a denial of service of the XCC web user interface or other undefined behavior through a format string injection vulnerability in a web interface API.
- CVE-2023-0896May 1, 2023risk 0.00cvss —epss 0.00
A default password was reported in Lenovo Smart Clock Essential with Alexa Built In that could allow unauthorized device access to an attacker with local network access.
- CVE-2023-25495Apr 28, 2023risk 0.00cvss —epss 0.01
A valid, authenticated administrative user can query a web interface API to reveal the configured LDAP client password used by XCC to authenticate to an external LDAP server in certain configurations. There is no exposure where no LDAP client password is configured
- CVE-2023-25496Apr 28, 2023risk 0.00cvss —epss 0.00
A privilege escalation vulnerability was reported in Lenovo Drivers Management Lenovo Driver Manager that could allow a local user to execute code with elevated privileges.
- CVE-2023-29056Apr 28, 2023risk 0.00cvss —epss 0.00
A valid LDAP user, under specific conditions, will default to read-only permissions when authenticating into XCC. To be vulnerable, XCC must be configured to use an LDAP server for Authentication/Authorization and have the login permission attribute not defined.
- CVE-2023-29057Apr 28, 2023risk 0.00cvss —epss 0.01
A valid XCC user's local account permissions overrides their active directory permissions under specific configurations. This could lead to a privilege escalation. To be vulnerable, LDAP must be configured for authentication/authorization and logins configured as “Local First,…
- CVE-2023-29058Apr 28, 2023risk 0.00cvss —epss 0.00
A valid, authenticated XCC user with read-only permissions can modify custom user roles on other user accounts and the user trespass message through the XCC CLI. There is no exposure if SSH is disabled or if there are no users assigned optional read-only permissions.
- CVE-2022-34404Feb 10, 2023risk 0.00cvss —epss 0.00
Dell System Update, version 2.0.0 and earlier, contains an Improper Certificate Validation in data parser module. A local attacker with high privileges could potentially exploit this vulnerability, leading to credential theft and/or denial of service.
- CVE-2022-34888Jan 30, 2023risk 0.00cvss —epss 0.00
The Remote Mount feature can potentially be abused by valid, authenticated users to make connections to internal services that may not normally be accessible to users. Internal service access controls, as applicable, remain in effect.
- CVE-2022-34884Jan 30, 2023risk 0.00cvss —epss 0.01
A buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated users to cause a recoverable subsystem denial of service.
- CVE-2022-40137Jan 30, 2023risk 0.00cvss —epss 0.00
A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.
- CVE-2022-40136Jan 30, 2023risk 0.00cvss —epss 0.00
An information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
- CVE-2022-40135Jan 30, 2023risk 0.00cvss —epss 0.00
An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
- CVE-2022-40134Jan 30, 2023risk 0.00cvss —epss 0.00
An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
- CVE-2022-4816Jan 23, 2023risk 0.00cvss —epss 0.00
A denial-of-service vulnerability has been identified in Lenovo Safecenter that could allow a local user to crash the application.
- CVE-2022-3432Jan 23, 2023risk 0.00cvss —epss 0.00
A potential vulnerability in a driver used during manufacturing process on the Ideapad Y700-14ISK that was mistakenly not deactivated may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
- CVE-2022-3430Jan 23, 2023risk 0.00cvss —epss 0.00
A potential vulnerability in the WMI Setup driver on some consumer Lenovo Notebook devices may allow an attacker with elevated privileges to modify secure boot setting by modifying an NVRAM variable.
- CVE-2022-1892Jan 23, 2023risk 0.00cvss —epss 0.00
A buffer overflow in the SystemBootManagerDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
- CVE-2022-1891Jan 23, 2023risk 0.00cvss —epss 0.00
A buffer overflow in the SystemLoadDefaultDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
- CVE-2022-1890Jan 23, 2023risk 0.00cvss —epss 0.00
A buffer overflow in the ReadyBootDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code.
- CVE-2022-1109Jan 20, 2023risk 0.00cvss —epss 0.00
An incorrect default permissions vulnerability in Lenovo Leyun cloud music application could allow denial of service.
Page 6 of 10