Vulnerabilities > Intel

DATE CVE VULNERABILITY TITLE RISK
2012-09-07 CVE-2010-5269 Unspecified vulnerability in Intel Threading Building Blocks 2.2.013
Untrusted search path vulnerability in tbb.dll in Intel Threading Building Blocks (TBB) 2.2.013 allows local users to gain privileges via a Trojan horse tbbmalloc.dll file in the current working directory, as demonstrated by a directory that contains a .pbk file.
local
intel
6.9
2011-06-30 CVE-2011-2604 Resource Management Errors vulnerability in Intel G41 Driver 6.14.10.5355
The Intel G41 driver 6.14.10.5355 on Windows XP SP3 allows remote attackers to cause a denial of service (system crash) via a crafted web page that is visited with Google Chrome or Mozilla Firefox, as demonstrated by the lots-of-polys-example.html test page in the Khronos WebGL SDK.
7.1
2010-12-22 CVE-2010-3268 Improper Input Validation vulnerability in multiple products
The GetStringAMSHandler function in prgxhndl.dll in hndlrsvc.exe in the Intel Alert Handler service (aka Symantec Intel Handler service) in Intel Alert Management System (AMS), as used in Symantec Antivirus Corporate Edition 10.1.4.4010 on Windows 2000 SP4 and Symantec Endpoint Protection before 11.x, does not properly validate the CommandLine field of an AMS request, which allows remote attackers to cause a denial of service (application crash) via a crafted request.
network
low complexity
intel symantec microsoft CWE-20
5.0
2010-02-08 CVE-2010-0560 Local Privilege Escalation vulnerability in Intel BIOS System Management Mode
Unspecified vulnerability in the BIOS in Intel Desktop Board DB, DG, DH, DP, and DQ Series allows local administrators to execute arbitrary code in System Management Mode (SSM) via unknown attack vectors.
local
low complexity
intel
4.6
2009-12-24 CVE-2009-4419 Configuration vulnerability in Intel products
Intel Q35, GM45, PM45 Express, Q45, and Q43 Express chipsets in the SINIT Authenticated Code Module (ACM), which allows local users to bypass the Trusted Execution Technology protection mechanism and gain privileges by modifying the MCHBAR register to point to an attacker-controlled region, which prevents the SENTER instruction from properly applying VT-d protection while an MLE is being loaded.
local
low complexity
intel CWE-16
7.2
2009-08-27 CVE-2008-7096 Permissions, Privileges, and Access Controls vulnerability in Intel Bios
Intel Desktop and Intel Mobile Boards with BIOS firmware DQ35JO, DQ35MP, DP35DP, DG33FB, DG33BU, DG33TL, MGM965TW, D945GCPE, and DX38BT allows local administrators with ring 0 privileges to gain additional privileges and modify code that is running in System Management Mode, or access hypervisory memory as demonstrated at Black Hat 2008 by accessing certain remapping registers in Xen 3.3.
local
intel CWE-264
6.9
2009-01-07 CVE-2009-0066 Security Bypass vulnerability in Intel Trusted Execution Technology NIL
Multiple unspecified vulnerabilities in Intel system software for Trusted Execution Technology (TXT) allow attackers to bypass intended loader integrity protections, as demonstrated by exploitation of tboot.
network
high complexity
intel
7.6
2008-09-11 CVE-2008-3635 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Stack-based buffer overflow in QuickTimeInternetExtras.qtx in an unspecified third-party Indeo v3.2 (aka IV32) codec for QuickTime, when used with Apple QuickTime before 7.5.5 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.
network
apple intel microsoft CWE-119
critical
9.3
2008-09-03 CVE-2008-3900 Information Exposure vulnerability in Intel Bios Pe94510M.86A.0050.2007.0710.1559
Intel firmware PE94510M.86A.0050.2007.0710.1559 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.
local
low complexity
intel CWE-200
2.1
2008-06-16 CVE-2008-2707 Permissions, Privileges, and Access Controls vulnerability in Intel Network Interface Controller 82571/82572
Unspecified vulnerability in the e1000g driver in Sun Solaris 10 and OpenSolaris before snv_93 allows remote attackers to cause a denial of service (network connectivity loss) via unknown vectors.
network
low complexity
sun intel CWE-264
7.8