CVE-2019-6163
https://notcve.org/view.php?id=CVE-2019-6163
A denial of service vulnerability was reported in Lenovo System Update before version 5.07.0084 that could allow service log files to be written to non-standard locations. Se comunicó una vulnerabilidad de denegación de servicio en Lenovo System Update en versiones anteriores a la 5.07.0084 que podría permitir que los archivos de registro de servicio sean escritos en ubicaciones no standard. • https://support.lenovo.com/solutions/LEN-27348 • CWE-404: Improper Resource Shutdown or Release •
CVE-2019-6156
https://notcve.org/view.php?id=CVE-2019-6156
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). Lenovo was notified that after resuming from S3 sleep mode in various versions of BIOS for Lenovo systems, the PRx is not set. This does not impact the SMM BIOS Write Protection, which keeps systems protected. En los sistemas Lenovo, SMM BIOS Write Protection se utiliza para evitar la escritura en SPI Flash. • https://support.lenovo.com/solutions/LEN-26332 • CWE-667: Improper Locking •
CVE-2019-6154
https://notcve.org/view.php?id=CVE-2019-6154
A DLL search path vulnerability was reported in Lenovo Bootable Generator, prior to version Mar-2019, that could allow a malicious user with local access to execute code on the system. Se informó de una vulnerabilidad en la ruta de búsqueda de DLL en Lenovo Bootable Generator, anterior a la versión Mar-2019, que podría permitir a un usuario malicioso con acceso local ejecute código en el sistema. • https://support.lenovo.com/solutions/LEN-25401 • CWE-426: Untrusted Search Path •
CVE-2019-6149
https://notcve.org/view.php?id=CVE-2019-6149
An unquoted search path vulnerability was identified in Lenovo Dynamic Power Reduction Utility prior to version 2.2.2.0 that could allow a malicious user with local access to execute code with administrative privileges. Se ha identificado una vulnerabilidad de ruta de búsqueda sin entrecomillar en Lenovo Dynamic Power Reduction Utility, en versiones anteriores a la 2.2.2.0, que podría permitir que un usuario malicioso con acceso local ejecute código con privilegios de administrador. • http://www.securityfocus.com/bid/107438 https://support.lenovo.com/solutions/LEN-25674 • CWE-428: Unquoted Search Path or Element •
CVE-2018-16098
https://notcve.org/view.php?id=CVE-2018-16098
In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing Device driver which could allow unauthorized code execution as a low privilege user. En algunos ThinkPads de Lenovo se ha detectado una vulnerabilidad de ruta de búsqueda sin entrecomillar, en varias versiones del controlador de Synaptics Pointing Device, que podría permitir la ejecución de código como usuario con bajos privilegios. • https://support.lenovo.com/bg/en/product_security/len-24573 https://support.lenovo.com/us/en/solutions/LEN-24573 • CWE-428: Unquoted Search Path or Element •