Vulnerabilities > Intel

DATE CVE VULNERABILITY TITLE RISK
2019-06-13 CVE-2019-0130 Cross-site Scripting vulnerability in multiple products
Reflected XSS in web interface for Intel(R) Accelerated Storage Manager in Intel(R) RSTe before version 5.5.0.2015 may allow an unauthenticated user to potentially enable denial of service via network access.
network
low complexity
intel lenovo CWE-79
7.4
2019-06-13 CVE-2019-0128 Permissions, Privileges, and Access Controls vulnerability in Intel Chipset Device Software 10.1.1.14/10.1.1.38
Improper permissions in the installer for Intel(R) Chipset Device Software (INF Update Utility) before version 10.1.1.45 may allow an authenticated user to escalate privilege via local access.
local
low complexity
intel CWE-264
7.8
2019-06-13 CVE-2018-3702 Incorrect Permission Assignment for Critical Resource vulnerability in Intel ITE Tech Consumer Infrared Driver
Improper permissions in the installer for the ITE Tech* Consumer Infrared Driver for Windows 10 versions before 5.4.3.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-732
7.8
2019-06-13 CVE-2018-12147 Improper Input Validation vulnerability in Intel products
Insufficient input validation in HECI subsystem in Intel(R) CSME before version 11.21.55, Intel® Server Platform Services before version 4.0 and Intel® Trusted Execution Engine Firmware before version 3.1.55 may allow a privileged user to potentially enable escalation of privileges via local access.
local
low complexity
intel CWE-20
6.7
2019-05-30 CVE-2019-11091 Microarchitectural Data Sampling Uncacheable Memory (MDSUM): Uncacheable memory on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
local
high complexity
intel fedoraproject
5.6
2019-05-30 CVE-2018-12130 Information Exposure vulnerability in multiple products
Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
local
high complexity
intel fedoraproject CWE-200
5.6
2019-05-30 CVE-2018-12127 Information Exposure vulnerability in multiple products
Microarchitectural Load Port Data Sampling (MLPDS): Load ports on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
local
high complexity
intel fedoraproject CWE-200
5.6
2019-05-30 CVE-2018-12126 Information Exposure vulnerability in multiple products
Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
local
high complexity
intel fedoraproject CWE-200
5.6
2019-05-17 CVE-2019-11114 Improper Input Validation vulnerability in Intel Driver & Support Assistant 19.3.12.3/3.1.1/3.5.0.1
Insufficient input validation in Intel(R) Driver & Support Assistant version 19.3.12.3 and before may allow a privileged user to potentially enable denial of service via local access.
local
low complexity
intel CWE-20
4.4
2019-05-17 CVE-2019-11095 Unspecified vulnerability in Intel Driver & Support Assistant 19.3.12.3/3.1.1/3.5.0.1
Insufficient access control in Intel(R) Driver & Support Assistant version 19.3.12.3 and before may allow a privileged user to potentially enable information disclosure via local access.
local
low complexity
intel
4.4