
CVE-2019-6172
https://notcve.org/view.php?id=CVE-2019-6172
12 Nov 2019 — A potential vulnerability in the SMI callback function used in Legacy USB driver using passed parameter without sufficient checking in some Lenovo ThinkPad models may allow arbitrary code execution. Una posible vulnerabilidad en la función de retrollamada SMI utilizada en el controlador USB heredado que utiliza el parámetro de paso sin suficiente comprobación en algunos modelos de ThinkPad de Lenovo puede permitir la ejecución de códigos arbitrarios • https://support.lenovo.com/us/en/product_security/LEN-27714 •

CVE-2019-10724
https://notcve.org/view.php?id=CVE-2019-10724
28 Aug 2019 — There is a vulnerability with the Dolby DAX2 API system services in which a low-privileged user can terminate arbitrary processes that are running at a higher privilege. The following are affected products and versions: Legion Y520T_Z370 6.0.1.8642, AIO310-20IAP 6.0.1.8642, AIO510-22ISH 6.0.1.8642, AIO510-23ISH 6.0.1.8642, AIO520-22IKL 6.0.1.8642, AIO520-22IKU 6.0.1.8642, AIO520-24IKL 6.0.1.8642, AIO520-24IKU 6.0.1.8642, AIO520-27IKL 6.0.1.8642, AIO720-24IKB 6.0.1.8642, IdeaCentre 520S-23IKU 6.0.1.8642, Thi... • https://lenovomobilesupport.lenovo.com/us/en/product_security/home •

CVE-2018-16098
https://notcve.org/view.php?id=CVE-2018-16098
24 Jan 2019 — In some Lenovo ThinkPads, an unquoted search path vulnerability was found in various versions of the Synaptics Pointing Device driver which could allow unauthorized code execution as a low privilege user. En algunos ThinkPads de Lenovo se ha detectado una vulnerabilidad de ruta de búsqueda sin entrecomillar, en varias versiones del controlador de Synaptics Pointing Device, que podría permitir la ejecución de código como usuario con bajos privilegios. • https://support.lenovo.com/bg/en/product_security/len-24573 • CWE-428: Unquoted Search Path or Element •

CVE-2018-9062 – BIOS Modules Unprotected by Intel Boot Guard Vulnerable to Physical Attack
https://notcve.org/view.php?id=CVE-2018-9062
19 Jul 2018 — In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code. En algunos ThinkPads de Lenovo, una región de BIOS no se incluye correctamente en las comprobaciones, lo que permite la inyección de código arbitrario. • http://www.securityfocus.com/bid/105387 • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') •