Vulnerabilities > Intel > High

DATE CVE VULNERABILITY TITLE RISK
2019-11-14 CVE-2019-14602 Incorrect Default Permissions vulnerability in Intel Nuvoton Consumer Infrared 1.02.1002
Improper permissions in the installer for the Nuvoton* CIR Driver versions 1.02.1002 and before may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-276
7.8
2019-11-14 CVE-2019-14566 Improper Input Validation vulnerability in Intel Software Guard Extensions SDK
Insufficient input validation in Intel(R) SGX SDK multiple Linux and Windows versions may allow an authenticated user to enable information disclosure, escalation of privilege or denial of service via local access.
local
low complexity
intel CWE-20
7.8
2019-11-14 CVE-2019-14565 Improper Initialization vulnerability in Intel Software Guard Extensions SDK
Insufficient initialization in Intel(R) SGX SDK Windows versions 2.4.100.51291 and earlier, and Linux versions 2.6.100.51363 and earlier, may allow an authenticated user to enable information disclosure, escalation of privilege or denial of service via local access.
local
low complexity
intel CWE-665
7.8
2019-11-14 CVE-2019-11182 Out-of-bounds Write vulnerability in Intel Baseboard Management Controller Firmware 2.09
Memory corruption in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of service via network access.
network
low complexity
intel CWE-787
7.5
2019-11-14 CVE-2019-11181 Out-of-bounds Read vulnerability in Intel Baseboard Management Controller Firmware 2.09
Out of bound read in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable escalation of privilege via network access.
local
low complexity
intel CWE-125
7.8
2019-11-14 CVE-2019-11180 Improper Input Validation vulnerability in Intel Baseboard Management Controller Firmware 2.09
Insufficient input validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of service via network access.
network
low complexity
intel CWE-20
7.5
2019-11-14 CVE-2019-11178 Classic Buffer Overflow vulnerability in Intel Baseboard Management Controller Firmware 2.09
Stack overflow in Intel(R) Baseboard Management Controller firmware may allow an authenticated user to potentially enable information disclosure and/or denial of service via network access.
network
low complexity
intel CWE-120
8.1
2019-11-14 CVE-2019-11177 Improper Handling of Exceptional Conditions vulnerability in Intel Baseboard Management Controller Firmware 2.09
Unhandled exception in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of service via network access.
network
low complexity
intel CWE-755
7.5
2019-11-14 CVE-2019-11175 Improper Input Validation vulnerability in Intel Baseboard Management Controller Firmware 2.09
Insufficient input validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of service via network access.
network
low complexity
intel CWE-20
7.5
2019-11-14 CVE-2019-11173 Unspecified vulnerability in Intel Baseboard Management Controller Firmware 2.09
Insufficient session validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure and/or denial of service via local access.
local
low complexity
intel
7.1