CVE-2022-1891
https://notcve.org/view.php?id=CVE-2022-1891
A buffer overflow in the SystemLoadDefaultDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code. • https://support.lenovo.com/us/en/product_security/LEN-91369 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') CWE-122: Heap-based Buffer Overflow •
CVE-2022-1890
https://notcve.org/view.php?id=CVE-2022-1890
A buffer overflow in the ReadyBootDxe driver in some Lenovo Notebook products may allow an attacker with local privileges to execute arbitrary code. • https://support.lenovo.com/us/en/product_security/LEN-91369 • CWE-122: Heap-based Buffer Overflow CWE-787: Out-of-bounds Write •
CVE-2022-1109
https://notcve.org/view.php?id=CVE-2022-1109
An incorrect default permissions vulnerability in Lenovo Leyun cloud music application could allow denial of service. Una vulnerabilidad de permisos predeterminados incorrectos en la aplicación de música en la nube Lenovo Leyun podría permitir la denegación de servicio. • https://iknow.lenovo.com.cn/detail/dc_204380.html • CWE-276: Incorrect Default Permissions •
CVE-2022-4435
https://notcve.org/view.php?id=CVE-2022-4435
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS LenovoRemoteConfigUpdateDxe driver that could allow a local attacker with elevated privileges to cause information disclosure. • https://support.lenovo.com/us/en/product_security/LEN-103709 • CWE-125: Out-of-bounds Read CWE-126: Buffer Over-read •
CVE-2022-4434
https://notcve.org/view.php?id=CVE-2022-4434
A buffer over-read vulnerability was reported in the ThinkPadX13s BIOS driver that could allow a local attacker with elevated privileges to cause information disclosure. • https://support.lenovo.com/us/en/product_security/LEN-103709 • CWE-125: Out-of-bounds Read CWE-126: Buffer Over-read •