Skip to main content

Daily materialized evidence profile

Vendor lenovo

This factual profile is rebuilt from stored cvebuzz evidence each day. It is a timestamped snapshot, not an immutable publication.

Refreshed UTC

Stored evidence summary

Sample size
400
CVEs with mentions
58
Total mentions
162
CVEs with KEV
1
CVEs with PoC
0

Attack vector counts

Network
142
Adjacent network
16
Local
217
Physical
25

Top snapshot Buzz entries

Up to five denormalized entries captured by the same daily profile refresh.

CVE-2017-5638

Published Mar 11, 2017

The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception handling and error-message generation during file-upload atte…

CVSS 9.8 · Critical
evidence mentions
76
Buzz score
75.0
KEV listed

CVE-2021-3970

Published Apr 22, 2022

A potential vulnerability in LenovoVariable SMI Handler due to insufficient validation in some Lenovo Notebook models BIOS may allow an attacker with local access and elevated pri…

CVSS 6.7 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2021-3971

Published Apr 22, 2022

A potential vulnerability by a driver used during older manufacturing processes on some consumer Lenovo Notebook devices that was mistakenly included in the BIOS image could allow…

CVSS 6.7 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2021-3972

Published Apr 22, 2022

A potential vulnerability by a driver used during manufacturing process on some consumer Lenovo Notebook devices' BIOS that was mistakenly not deactivated may allow an attacker wi…

CVSS 6.7 · Medium
evidence mentions
4
Buzz score
29.1

CVE-2019-6160

Published Jul 16, 2019

A vulnerability in various versions of Iomega and LenovoEMC NAS products could allow an unauthenticated user to access files on NAS shares via the API.

CVSS 8.8 · High
evidence mentions
3
Buzz score
21.9