Vulnerabilities > Lenovo

DATE CVE VULNERABILITY TITLE RISK
2015-04-16 CVE-2015-3320 Information Exposure vulnerability in Lenovo USB Enhanced Performance Keyboard
Lenovo USB Enhanced Performance Keyboard software before 2.0.2.2 includes active debugging code in SKHOOKS.DLL, which allows local users to obtain keypress information by accessing debug output.
local
low complexity
lenovo CWE-200
2.1
2014-03-03 CVE-2014-1939 Code Injection vulnerability in multiple products
java/android/webkit/BrowserFrame.java in Android before 4.4 uses the addJavascriptInterface API in conjunction with creating an object of the SearchBoxImpl class, which allows attackers to execute arbitrary Java code by leveraging access to the searchBoxJavaBridge_ interface at certain Android API levels.
network
low complexity
google lenovo CWE-94
7.5
2014-01-21 CVE-2013-1361 DLL Loading Arbitrary Code Execution vulnerability in Lenovo Thinkpad Bluetooth With Enhanced Data Rate Software 6.4.0.2900
Untrusted search path vulnerability in Lenovo Thinkpad Bluetooth with Enhanced Data Rate Software 6.4.0.2900 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL that is located in the same folder as a file that is processed by Lenovo Bluetooth.
network
lenovo
critical
9.3
2009-02-20 CVE-2009-0655 Improper Authentication vulnerability in Lenovo Veriface III
Lenovo Veriface III allows physically proximate attackers to login to a Windows account by presenting a "plain image" of the authorized user.
local
lenovo CWE-287
6.9
2008-10-15 CVE-2008-4589 Buffer Errors vulnerability in Lenovo Resuce and Recovery 4.20/4.20.0511/4.20.0512
Heap-based buffer overflow in the tvtumin.sys kernel driver in Lenovo Rescue and Recovery 4.20, including 4.20.0511 and 4.20.0512, allows local users to execute arbitrary code via a long file name.
local
low complexity
lenovo CWE-119
7.2
2008-07-21 CVE-2008-3249 Credentials Management vulnerability in Lenovo Thinkvantage System Update 3.13
The client in Lenovo System Update before 3.14 does not properly validate the certificate when establishing an SSL connection, which allows remote attackers to install arbitrary packages via an SSL certificate whose X.509 headers match a public certificate used by IBM.
network
high complexity
lenovo CWE-255
5.1
2007-08-15 CVE-2007-2929 Multiple vulnerability in Lenovo Access Support and Automated Solutions
The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), exposes unsafe methods to arbitrary web domains, which allows remote attackers to download arbitrary code onto a client system and execute this code.
network
lenovo
5.8
2007-08-15 CVE-2007-2928 Multiple vulnerability in Lenovo Access Support and Automated Solutions
Format string vulnerability in the IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), allows remote attackers to execute arbitrary code via format string specifiers in unknown data.
network
lenovo
5.8
2007-08-15 CVE-2007-2240 Multiple vulnerability in Lenovo Access Support and Automated Solutions
The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), does not properly validate digital signatures of downloaded software, which makes it easier for remote attackers to spoof a download.
network
lenovo
5.8
2007-03-07 CVE-2007-1307 Unspecified vulnerability in IBM ThinkPad Intel PRO/1000 LAN Adapter Software
Unspecified vulnerability in Lenovo Intel PRO/1000 LAN adapter before Build 135400, as used on IBM Lenovo ThinkPad systems, has unknown impact and attack vectors.
network
low complexity
intel lenovo
critical
10.0