Vulnerabilities > Lenovo > Thinkcentre M900Z Firmware > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-02-14 CVE-2019-6190 Improper Initialization vulnerability in Lenovo products
Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and ThinkStation, that could cause PCRs to be cleared intermittently after resuming from sleep (S3) on systems with Intel TXT enabled.
local
low complexity
lenovo CWE-665
5.5
2019-11-12 CVE-2019-6172 Unspecified vulnerability in Lenovo products
A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad models may allow arbitrary code execution.
local
high complexity
lenovo
6.4
2019-11-12 CVE-2019-6170 Unspecified vulnerability in Lenovo products
A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo ThinkPad models may allow arbitrary code execution.
local
high complexity
lenovo
6.4
2019-08-29 CVE-2019-10724 Unspecified vulnerability in Lenovo products
There is a vulnerability with the Dolby DAX2 API system services in which a low-privileged user can terminate arbitrary processes that are running at a higher privilege.
network
low complexity
lenovo
6.5
2017-08-10 CVE-2017-3753 Code Injection vulnerability in Lenovo products
A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc.
low complexity
lenovo CWE-94
6.8