Vulnerabilities > Intel

DATE CVE VULNERABILITY TITLE RISK
2019-11-14 CVE-2019-11137 Improper Input Validation vulnerability in multiple products
Insufficient input validation in system firmware for Intel(R) Xeon(R) Scalable Processors, Intel(R) Xeon(R) Processors D Family, Intel(R) Xeon(R) Processors E5 v4 Family, Intel(R) Xeon(R) Processors E7 v4 Family and Intel(R) Atom(R) processor C Series may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.
local
low complexity
intel hpe CWE-20
8.2
2019-11-14 CVE-2019-11136 Insufficient access control in system firmware for Intel(R) Xeon(R) Scalable Processors, 2nd Generation Intel(R) Xeon(R) Scalable Processors and Intel(R) Xeon(R) Processors D Family may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.
local
low complexity
intel hpe
6.7
2019-10-11 CVE-2019-14570 Out-of-bounds Write vulnerability in Intel products
Memory corruption in system firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.
local
low complexity
intel CWE-787
7.8
2019-10-11 CVE-2019-14569 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Intel products
Pointer corruption in system firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.
local
low complexity
intel CWE-119
7.8
2019-10-11 CVE-2019-11167 Incorrect Permission Assignment for Critical Resource vulnerability in Intel Smart Connect Technology
Improper file permission in software installer for Intel(R) Smart Connect Technology for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-732
7.8
2019-10-11 CVE-2019-11120 Unspecified vulnerability in Intel Active System Console 8.0
Insufficient path checking in the installer for Intel(R) Active System Console before version 8.0 Build 24 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel
7.8
2019-09-16 CVE-2019-11184 Race Condition vulnerability in multiple products
A race condition in specific microprocessors using Intel (R) DDIO cache allocation and RDMA may allow an authenticated user to potentially enable partial information disclosure via adjacent access.
high complexity
intel netapp CWE-362
4.8
2019-09-16 CVE-2019-11166 Incorrect Permission Assignment for Critical Resource vulnerability in Intel Easy Streaming Wizard
Improper file permissions in the installer for Intel(R) Easy Streaming Wizard before version 2.1.0731 may allow an authenticated user to potentially enable escalation of privilege via local attack.
local
low complexity
intel CWE-732
6.7
2019-08-19 CVE-2019-11163 Unspecified vulnerability in Intel Processor Identification Utility
Insufficient access control in a hardware abstraction driver for Intel(R) Processor Identification Utility for Windows before version 6.1.0731 may allow an authenticated user to potentially enable escalation of privilege, denial of service or information disclosure via local access.
local
low complexity
intel
7.8
2019-08-19 CVE-2019-11162 Unspecified vulnerability in Intel Computing Improvement Program 2.1.03638/2.2.0.03942
Insufficient access control in hardware abstraction in SEMA driver for Intel(R) Computing Improvement Program before version 2.4.0.04733 may allow an authenticated user to potentially enable escalation of privilege, denial of service or information disclosure via local access.
local
low complexity
intel
7.8