Vulnerabilities > Lenovo > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-01-09 | CVE-2016-8106 | Improper Input Validation vulnerability in multiple products A Denial of Service in Intel Ethernet Controller's X710/XL710 with Non-Volatile Memory Images before version 5.05 allows a remote attacker to stop the controller from processing network traffic working under certain network use conditions. | 4.3 |
2016-11-30 | CVE-2016-8222 | Improper Access Control vulnerability in Lenovo products A vulnerability has been identified in a signed kernel driver for the BIOS of some ThinkPad systems that can allow an attacker with Windows administrator-level privileges to call System Management Mode (SMM) services. | 4.7 |
2016-11-29 | CVE-2016-8224 | Cryptographic Issues vulnerability in Lenovo products A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a system could install a program that circumvents Intel Management Engine (ME) protections. | 4.6 |
2016-06-30 | CVE-2016-5729 | Permissions, Privileges, and Access Controls vulnerability in Lenovo Bios EFI Driver Lenovo BIOS EFI Driver allows local administrators to execute arbitrary code with System Management Mode (SMM) privileges via unspecified vectors. | 6.8 |
2016-05-23 | CVE-2016-4783 | Cross-site Scripting vulnerability in Lenovo Shareit 3.5.98Ww Cross-site scripting (XSS) vulnerability in Lenovo SHAREit before 3.5.98_ww on Android before 4.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka "Universal XSS (UXSS)." | 4.3 |
2016-04-12 | CVE-2015-8108 | 7PK - Security Features vulnerability in Lenovo EMC Firmware 4.1.204.33661 The management interface in LenovoEMC EZ Media & Backup (hm3), ix2/ix2-dl, ix4-300d, px12-400r/450r, px6-300d, px2-300d, px4-300r, px4-400d, px4-400r, and px4-300d NAS devices with firmware before 4.1.204.33661 allows remote attackers to obtain sensitive device information via unspecified vectors. | 5.0 |
2016-01-26 | CVE-2016-1491 | Credentials Management vulnerability in Lenovo Shareit 2.5.1.1 The Wifi hotspot in Lenovo SHAREit before 3.2.0 for Windows, when configured to receive files, has a hardcoded password of 12345678, which makes it easier for remote attackers to obtain access by leveraging a position within the WLAN coverage area. | 5.4 |
2016-01-26 | CVE-2016-1489 | Information Exposure vulnerability in Lenovo Shareit 2.5.1.1/3.0.18Ww Lenovo SHAREit before 3.2.0 for Windows and SHAREit before 3.5.48_ww for Android transfer files in cleartext, which allows remote attackers to (1) obtain sensitive information by sniffing the network or (2) conduct man-in-the-middle (MITM) attacks via unspecified vectors. | 4.3 |
2015-11-12 | CVE-2015-7819 | Credentials Management vulnerability in multiple products The DB service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain sensitive administrator-account information via a request on port 40999, as demonstrated by an improperly encrypted password. | 5.0 |
2015-05-12 | CVE-2015-2234 | Race Condition vulnerability in Lenovo System Update 5.06.0027 Race condition in Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses world-writable permissions for the update files directory, which allows local users to gain privileges by writing to an update file after the signature is validated. | 6.9 |