Vulnerabilities > HP > Zbook X2 G4 Firmware > 1.43

DATE CVE VULNERABILITY TITLE RISK
2023-06-14 CVE-2022-31640 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in HP products
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
local
high complexity
hp CWE-367
7.0
2023-06-14 CVE-2022-31641 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in HP products
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
local
high complexity
hp CWE-367
7.0
2023-06-14 CVE-2022-31642 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in HP products
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
local
high complexity
hp CWE-367
7.0
2023-06-12 CVE-2022-43777 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in HP products
Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.
local
high complexity
hp CWE-367
7.8
2023-06-12 CVE-2022-43778 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in HP products
Potential Time-of-Check to Time-of Use (TOCTOU) vulnerabilities have been identified in the HP BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure.
local
high complexity
hp CWE-367
7.8
2020-08-12 CVE-2020-15596 Uncontrolled Search Path Element vulnerability in HP products
The ALPS ALPINE touchpad driver before 8.2206.1717.634, as used on various Dell, HP, and Lenovo laptops, allows attackers to conduct Path Disclosure attacks via a "fake" DLL file.
local
low complexity
hp CWE-427
6.7