CVE-2019-19705
- EPSS 0.04%
- Published 26.12.2022 21:15:10
- Last modified 14.04.2025 17:15:22
Realtek Audio Drivers for Windows, as used on the Lenovo ThinkPad X1 Carbon 20A7, 20A8, 20BS, and 20BT before 6.0.8882.1 and 20KH and 20KG before 6.0.8907.1 (and on many other Lenovo and non-Lenovo products), mishandles DLL preloading.
CVE-2021-4210
- EPSS 0.11%
- Published 22.04.2022 21:15:09
- Last modified 21.11.2024 06:37:09
A potential vulnerability in the SMI callback function used in the NVME driver in some Lenovo Desktop, ThinkStation, and ThinkEdge models may allow an attacker with local access and elevated privileges to execute arbitrary code.
CVE-2020-8353
- EPSS 0.05%
- Published 11.11.2020 18:15:11
- Last modified 21.11.2024 05:38:45
Prior to August 10, 2020, some Lenovo Desktop and Workstation systems were shipped with the Embedded Host Based Configuration (EHBC) feature of Intel AMT enabled. This could allow an administrative user with local access to configure Intel AMT.
CVE-2019-6190
- EPSS 0.12%
- Published 14.02.2020 17:15:12
- Last modified 21.11.2024 04:46:08
Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and ThinkStation, that could cause PCRs to be cleared intermittently after resuming from sleep (S3) on sy...
CVE-2019-6170
- EPSS 0.07%
- Published 12.11.2019 21:15:12
- Last modified 21.11.2024 04:46:04
A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo ThinkPad models may allow arbitrary code execution.
CVE-2019-6172
- EPSS 0.09%
- Published 12.11.2019 21:15:12
- Last modified 21.11.2024 04:46:05
A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad models may allow arbitrary code execution.
CVE-2019-6188
- EPSS 0.62%
- Published 12.11.2019 21:15:12
- Last modified 21.11.2024 04:46:07
The BIOS tamper detection mechanism was not triggered in Lenovo ThinkPad T460p, BIOS versions up to R07ET90W, and T470p, BIOS versions up to R0FET50W, which may allow for unauthorized access.
CVE-2019-10724
- EPSS 0.31%
- Published 29.08.2019 00:15:10
- Last modified 21.11.2024 04:19:48
There is a vulnerability with the Dolby DAX2 API system services in which a low-privileged user can terminate arbitrary processes that are running at a higher privilege. The following are affected products and versions: Legion Y520T_Z370 6.0.1.8642, ...
CVE-2019-6156
- EPSS 0.04%
- Published 10.04.2019 17:29:00
- Last modified 21.11.2024 04:46:02
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). Lenovo was notified that after resum...