4.7
CVE-2024-10253
- EPSS 0.02%
- Published 14.01.2025 22:15:25
- Last modified 14.01.2025 22:15:25
- Source psirt@lenovo.com
- Teams watchlist Login
- Open Login
A potential TOCTOU vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a system crash.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorLenovo
≫
Product
PC Manager
Default Statusunaffected
Version <
5.1.90.12092
Version
0
Status
affected
VendorLenovo
≫
Product
Browser
Default Statusunaffected
Version <
9.0.5.12181
Version
0
Status
affected
VendorLenovo
≫
Product
App Store
Default Statusunaffected
Version <
9.0.20
Version
0
Status
affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.02% | 0.031 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
psirt@lenovo.com | 4.7 | 1 | 3.6 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
|
CWE-122 Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().