Vulnerabilities > HP > Elitebook X360 1020 G2 Firmware

DATE CVE VULNERABILITY TITLE RISK
2023-06-12 CVE-2022-27539 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in HP products
Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.
local
high complexity
hp CWE-367
7.8
2023-06-12 CVE-2022-27541 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in HP products
Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.
local
high complexity
hp CWE-367
7.8
2023-02-01 CVE-2021-3439 Unspecified vulnerability in HP products
HP has identified a potential vulnerability in BIOS firmware of some Workstation products.
local
low complexity
hp
7.8
2023-02-01 CVE-2021-3808 Unspecified vulnerability in HP products
Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution.
local
low complexity
hp
7.8
2023-02-01 CVE-2021-3809 Unspecified vulnerability in HP products
Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution.
local
low complexity
hp
7.8
2022-12-12 CVE-2022-37018 Unspecified vulnerability in HP products
A potential vulnerability has been identified in the system BIOS for certain HP PC products which may allow escalation of privileges and code execution.
local
low complexity
hp
8.4
2020-08-12 CVE-2020-15596 Uncontrolled Search Path Element vulnerability in HP products
The ALPS ALPINE touchpad driver before 8.2206.1717.634, as used on various Dell, HP, and Lenovo laptops, allows attackers to conduct Path Disclosure attacks via a "fake" DLL file.
local
low complexity
hp CWE-427
6.7
2020-07-22 CVE-2019-18618 Incorrect access control in the firmware of Synaptics VFS75xx family fingerprint sensors that include external flash (all versions prior to 2019-11-15) allows a local administrator or physical attacker to compromise the confidentiality of sensor data via injection of an unverified partition table.
local
low complexity
synaptics lenovo hp
6.0