intel CVE Vulnerabilities & Metrics

Focus on intel vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About intel Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with intel. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total intel CVEs: 1436
Earliest CVE date: 08 May 1999, 04:00 UTC
Latest CVE date: 13 Nov 2024, 21:15 UTC

Latest CVE reference: CVE-2024-41167

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 57

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -81.43%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -81.43%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical intel CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.73

Max CVSS: 10.0

Critical CVEs (≥9): 8

CVSS Range vs. Count

Range Count
0.0-3.9 854
4.0-6.9 512
7.0-8.9 109
9.0-10.0 8

CVSS Distribution Chart

Top 5 Highest CVSS intel CVEs

These are the five CVEs with the highest CVSS scores for intel, sorted by severity first and recency.

All CVEs for intel

CVE-2024-41167 intel vulnerability CVSS: 0 13 Nov 2024, 21:15 UTC

Improper input validation in UEFI firmware in some Intel(R) Server Board M10JNP2SB Family may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2024-39609 intel vulnerability CVSS: 0 13 Nov 2024, 21:15 UTC

Improper Access Control in UEFI firmware for some Intel(R) Server Board M70KLP may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2024-38668 intel vulnerability CVSS: 0 13 Nov 2024, 21:15 UTC

Uncontrolled search path for some Intel(R) Quartus(R) Prime Standard Edition software for Windows before version 23.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-38383 intel vulnerability CVSS: 0 13 Nov 2024, 21:15 UTC

Uncontrolled search path for some Intel(R) Quartus(R) Prime Pro Edition software for Windows before version 24.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-36488 intel vulnerability CVSS: 0 13 Nov 2024, 21:15 UTC

Improper Access Control in some Intel(R) DSA before version 24.3.26.8 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-36482 intel vulnerability CVSS: 0 13 Nov 2024, 21:15 UTC

Improper input validation in some Intel(R) CIP software before version 2.4.10852 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2024-36294 intel vulnerability CVSS: 0 13 Nov 2024, 21:15 UTC

Insecure inherited permissions for some Intel(R) DSA software before version 24.3.26.8 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-36276 intel vulnerability CVSS: 0 13 Nov 2024, 21:15 UTC

Insecure inherited permissions for some Intel(R) CIP software before version 2.4.10852 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-36253 intel vulnerability CVSS: 0 13 Nov 2024, 21:15 UTC

Uncontrolled search path in the Intel(R) SDP Tool for Windows software all version may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-35201 intel vulnerability CVSS: 0 13 Nov 2024, 21:15 UTC

Incorrect default permissions in the Intel(R) SDP Tool for Windows software all versions may allow an authenticated user to enable escalation of privilege via local access.

CVE-2024-32485 intel vulnerability CVSS: 0 13 Nov 2024, 21:15 UTC

Improper Input Validation in some Intel(R) VROC software before version 8.6.0.2003 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2024-29079 intel vulnerability CVSS: 0 13 Nov 2024, 21:15 UTC

Insufficient control flow management in some Intel(R) VROC software before version 8.6.0.3001 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-36261 intel vulnerability CVSS: 0 16 Sep 2024, 17:16 UTC

Improper access control in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable denial of service via adjacent access.

CVE-2024-36247 intel vulnerability CVSS: 0 16 Sep 2024, 17:16 UTC

Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable denial of service via adjacent access.

CVE-2024-34545 intel vulnerability CVSS: 0 16 Sep 2024, 17:16 UTC

Improper input validation in some Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable information disclosure via adjacent access.

CVE-2024-34543 intel vulnerability CVSS: 0 16 Sep 2024, 17:16 UTC

Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-34153 intel vulnerability CVSS: 0 16 Sep 2024, 17:16 UTC

Uncontrolled search path element in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-33848 intel vulnerability CVSS: 0 16 Sep 2024, 17:16 UTC

Uncaught exception in Intel(R) RAID Web Console software all versions may allow an authenticated user to potentially enable denial of service via local access.

CVE-2024-32940 intel vulnerability CVSS: 0 16 Sep 2024, 17:16 UTC

Improper access control in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable denial of service via adjacent access.

CVE-2024-32666 intel vulnerability CVSS: 0 16 Sep 2024, 17:16 UTC

NULL pointer dereference in Intel(R) RAID Web Console software for all versions may allow an authenticated user to potentially enable denial of service via local access.

CVE-2024-28170 intel vulnerability CVSS: 0 16 Sep 2024, 17:16 UTC

Improper access control in Intel(R) RAID Web Console all versions may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2024-34163 intel vulnerability CVSS: 0 14 Aug 2024, 14:15 UTC

Improper input validation in firmware for some Intel(R) NUC may allow a privileged user to potentially enableescalation of privilege via local access.

CVE-2024-29015 intel vulnerability CVSS: 0 14 Aug 2024, 14:15 UTC

Uncontrolled search path in some Intel(R) VTune(TM) Profiler software before versions 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-28947 intel vulnerability CVSS: 0 14 Aug 2024, 14:15 UTC

Improper input validation in kernel mode driver for some Intel(R) Server Board S2600ST Family firmware before version 02.01.0017 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2024-28887 intel vulnerability CVSS: 0 14 Aug 2024, 14:15 UTC

Uncontrolled search path in some Intel(R) IPP software before version 2021.11 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-28876 intel vulnerability CVSS: 0 14 Aug 2024, 14:15 UTC

Uncontrolled search path for some Intel(R) MPI Library software before version 2021.12 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-28172 intel vulnerability CVSS: 0 14 Aug 2024, 14:15 UTC

Uncontrolled search path for some Intel(R) Trace Analyzer and Collector software before version 2022.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-28050 intel vulnerability CVSS: 0 14 Aug 2024, 14:15 UTC

Improper access control in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.4824 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2024-28046 intel vulnerability CVSS: 0 14 Aug 2024, 14:15 UTC

Uncontrolled search path in some Intel(R) GPA software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-26025 intel vulnerability CVSS: 0 14 Aug 2024, 14:15 UTC

Incorrect default permissions for some Intel(R) Advisor software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-26022 intel vulnerability CVSS: 0 14 Aug 2024, 14:15 UTC

Improper access control in some Intel(R) UEFI Integrator Tools on Aptio V for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-25562 intel vulnerability CVSS: 0 14 Aug 2024, 14:15 UTC

Improper buffer restrictions in some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2024-25561 intel vulnerability CVSS: 0 14 Aug 2024, 14:15 UTC

Insecure inherited permissions in some Intel(R) HID Event Filter software installers before version 2.2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-24973 intel vulnerability CVSS: 0 14 Aug 2024, 14:15 UTC

Improper input validation for some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2024-24580 intel vulnerability CVSS: 0 14 Aug 2024, 14:15 UTC

Improper conditions check in some Intel(R) Data Center GPU Max Series 1100 and 1550 products may allow a privileged user to potentially enable denial of service via local access.

CVE-2024-23909 intel vulnerability CVSS: 0 14 Aug 2024, 14:15 UTC

Uncontrolled search path in some Intel(R) FPGA SDK for OpenCL(TM) software technology may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-23907 intel vulnerability CVSS: 0 14 Aug 2024, 14:15 UTC

Uncontrolled search path in some Intel(R) High Level Synthesis Compiler software before version 23.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-23495 intel vulnerability CVSS: 0 14 Aug 2024, 14:15 UTC

Incorrect default permissions in some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-23491 intel vulnerability CVSS: 0 14 Aug 2024, 14:15 UTC

Uncontrolled search path in some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-23489 intel vulnerability CVSS: 0 14 Aug 2024, 14:15 UTC

Uncontrolled search path for some Intel(R) VROC software before version 8.6.0.1191 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-22184 intel vulnerability CVSS: 0 14 Aug 2024, 14:15 UTC

Uncontrolled search path for some Intel(R) Quartus(R) Prime Pro Edition Design Software before version 24.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-43489 intel vulnerability CVSS: 0 14 Aug 2024, 14:15 UTC

Improper access control for some Intel(R) CIP software before version 2.4.10717 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2024-21862 intel vulnerability CVSS: 0 16 May 2024, 21:16 UTC

Uncontrolled search path in some Intel(R) Quartus(R) Prime Standard Edition Design software before version 23.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-21861 intel vulnerability CVSS: 0 16 May 2024, 21:16 UTC

Uncontrolled search path in some Intel(R) GPA Framework software before version 2023.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-21837 intel vulnerability CVSS: 0 16 May 2024, 21:16 UTC

Uncontrolled search path in some Intel(R) Quartus(R) Prime Lite Edition Design software before version 23.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-21835 intel vulnerability CVSS: 0 16 May 2024, 21:16 UTC

Insecure inherited permissions in some Intel(R) XTU software before version 7.14.0.15 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-21814 intel vulnerability CVSS: 0 16 May 2024, 21:16 UTC

Uncontrolled search path for some Intel(R) Chipset Device Software before version 10.1.19444.8378 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-21809 intel vulnerability CVSS: 0 16 May 2024, 21:16 UTC

Improper conditions check for some Intel(R) Quartus(R) Prime Lite Edition Design software before version 23.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-21788 intel vulnerability CVSS: 0 16 May 2024, 21:16 UTC

Uncontrolled search path in some Intel(R) GPA software before version 2023.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-21777 intel vulnerability CVSS: 0 16 May 2024, 21:16 UTC

Uncontrolled search path in some Intel(R) Quartus(R) Prime Pro Edition Design software before version 23.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-45743 intel vulnerability CVSS: 0 16 May 2024, 21:15 UTC

Uncontrolled search path in some Intel(R) DSA software uninstallers before version 23.4.39.10 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-43748 intel vulnerability CVSS: 0 16 May 2024, 21:15 UTC

Improper access control in some Intel(R) GPA Framework software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-43629 intel vulnerability CVSS: 0 16 May 2024, 21:15 UTC

Incorrect default permissions in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-41961 intel vulnerability CVSS: 0 16 May 2024, 21:15 UTC

Uncontrolled search path in some Intel(R) GPA software before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-40071 intel vulnerability CVSS: 0 16 May 2024, 21:15 UTC

Improper access control in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-35192 intel vulnerability CVSS: 0 16 May 2024, 21:15 UTC

Uncontrolled search path in some Intel(R) GPA Framework software before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-24460 intel vulnerability CVSS: 0 16 May 2024, 21:15 UTC

Incorrect default permissions in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2024-28084 intel vulnerability CVSS: 0 03 Mar 2024, 21:15 UTC

p2putil.c in iNet wireless daemon (IWD) through 2.15 allows attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact because of initialization issues in situations where parsing of advertised service information fails.

CVE-2023-52161 intel vulnerability CVSS: 0 22 Feb 2024, 17:15 UTC

The Access Point functionality in eapol_auth_key_handle in eapol.c in iNet wireless daemon (IWD) before 2.14 allows attackers to gain unauthorized access to a protected Wi-Fi network. An attacker can complete the EAPOL handshake by skipping Msg2/4 and instead sending Msg4/4 with an all-zero key.

CVE-2023-42776 intel vulnerability CVSS: 0 14 Feb 2024, 14:16 UTC

Improper input validation in some Intel(R) SGX DCAP software for Windows before version 1.19.100.3 may allow an authenticateed user to potentially enable information disclosure via local access.

CVE-2023-41252 intel vulnerability CVSS: 0 14 Feb 2024, 14:16 UTC

Out-of-bounds read in some Intel(R) QAT software drivers for Windows before version QAT1.7-W-1.11.0 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2023-41091 intel vulnerability CVSS: 0 14 Feb 2024, 14:16 UTC

Uncontrolled search path for some Intel(R) MPI Library Software before version 2021.11 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-40161 intel vulnerability CVSS: 0 14 Feb 2024, 14:16 UTC

Improper access control in some Intel Unite(R) Client software before version 4.2.35041 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-40156 intel vulnerability CVSS: 0 14 Feb 2024, 14:16 UTC

Uncontrolled search path element in some Intel(R) SSU software before version 3.0.0.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-40154 intel vulnerability CVSS: 0 14 Feb 2024, 14:16 UTC

Incorrect default permissions in the Intel(R) SUR for Gameplay Software before version 2.0.1901 may allow privillaged user to potentially enable escalation of privilege via local access.

CVE-2023-39425 intel vulnerability CVSS: 0 14 Feb 2024, 14:16 UTC

Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-38561 intel vulnerability CVSS: 0 14 Feb 2024, 14:16 UTC

Improper access control in some Intel(R) XTU software before version 7.12.0.29 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-38135 intel vulnerability CVSS: 0 14 Feb 2024, 14:16 UTC

Improper authorization in some Intel(R) PM software may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2023-36493 intel vulnerability CVSS: 0 14 Feb 2024, 14:16 UTC

Uncontrolled search path in some Intel(R) SDK for OpenCL(TM) Applications software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-35769 intel vulnerability CVSS: 0 14 Feb 2024, 14:16 UTC

Uncontrolled search path in some Intel(R) CIP software before version 2.4.10577 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-35062 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Improper access control in some Intel(R) DSA software before version 23.4.33 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2023-35060 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Uncontrolled search path in some Intel(R) Battery Life Diagnostic Tool software before version 2.3.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-35003 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Path transversal in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-34983 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2023-34315 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Incorrect default permissions in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-33875 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Improper access control for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via local access..

CVE-2023-33870 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Insecure inherited permissions in some Intel(R) Ethernet tools and driver install software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-32651 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Improper validation of specified type of input for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2023-32647 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Improper access control in some Intel(R) XTU software before version 7.12.0.29 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-32646 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Uncontrolled search path element in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-32644 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Protection mechanism failure for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2023-32642 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Insufficient adherence to expected conventions for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2023-32618 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-31271 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Improper access control in some Intel(R) VROC software before version 8.0.8.1001 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-28739 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Incorrect default permissions in some Intel(R) Chipset Driver Software before version 10.1.19444.8378 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-28720 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Improper initialization for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access..

CVE-2023-28715 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.2 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2023-28407 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Uncontrolled search path in some Intel(R) XTU software before version 7.12.0.29 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-28374 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2023-27308 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2023-27307 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2023-27303 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2023-27301 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-27300 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2023-26596 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2023-26592 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Deserialization of untrusted data in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable a denial of service via local access.

CVE-2023-26591 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Unchecked return value in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an unauthenticated user to potentially enable denial of service via physical access.

CVE-2023-26586 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Uncaught exception for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2023-26585 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2023-25951 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Improper input validation for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2023-25945 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Protection mechanism failure in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-25779 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Uncontrolled search path element in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-25777 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-25769 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2023-25174 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Improper access control in some Intel(R) Chipset Driver Software before version 10.1.19444.8378 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-25073 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2023-24591 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Uncontrolled search path in some Intel(R) Binary Configuration Tool software before version 3.4.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-24589 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2023-24542 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Unquoted search path or element in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-24481 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-24463 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Improper input validation in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.

CVE-2023-22848 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2023-22390 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2023-22342 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Improper input validation in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-22311 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Improper access control in some Intel(R) Optane(TM) PMem 100 Series Management Software before version 01.00.00.3547 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-22293 intel vulnerability CVSS: 0 14 Feb 2024, 14:15 UTC

Improper access control in the Intel(R) Thunderbolt(TM) DCH drivers for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-42766 intel vulnerability CVSS: 0 19 Jan 2024, 20:15 UTC

Improper input validation in some Intel NUC 8 Compute Element BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2023-42429 intel vulnerability CVSS: 0 19 Jan 2024, 20:15 UTC

Improper buffer restrictions in some Intel NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2023-38587 intel vulnerability CVSS: 0 19 Jan 2024, 20:15 UTC

Improper input validation in some Intel NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2023-38541 intel vulnerability CVSS: 0 19 Jan 2024, 20:15 UTC

Insecure inherited permissions in some Intel HID Event Filter drivers for Windows 10 for some Intel NUC laptop software installers before version 2.2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-32544 intel vulnerability CVSS: 0 19 Jan 2024, 20:15 UTC

Improper access control in some Intel HotKey Services for Windows 10 for Intel NUC P14E Laptop Element software installers before version 1.1.45 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2023-32272 intel vulnerability CVSS: 0 19 Jan 2024, 20:15 UTC

Uncontrolled search path in some Intel NUC Pro Software Suite Configuration Tool software installers before version 3.0.0.6 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2023-29495 intel vulnerability CVSS: 0 19 Jan 2024, 20:15 UTC

Improper input validation for some Intel NUC BIOS firmware before version IN0048 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2023-29244 intel vulnerability CVSS: 0 19 Jan 2024, 20:15 UTC

Incorrect default permissions in some Intel Integrated Sensor Hub (ISH) driver for Windows 10 for Intel NUC P14E Laptop Element software installers before version 5.4.1.4479 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-28743 intel vulnerability CVSS: 0 19 Jan 2024, 20:15 UTC

Improper input validation for some Intel NUC BIOS firmware before version QN0073 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2023-28738 intel vulnerability CVSS: 0 19 Jan 2024, 20:15 UTC

Improper input validation for some Intel NUC BIOS firmware before version JY0070 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2023-28722 intel vulnerability CVSS: 0 19 Jan 2024, 20:15 UTC

Improper buffer restrictions for some Intel NUC BIOS firmware before version IN0048 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2023-40540 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Non-Transparent Sharing of Microarchitectural Resources in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access.

CVE-2023-40220 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper buffer restrictions in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access.

CVE-2023-39412 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Cross-site request forgery in some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access.

CVE-2023-39411 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper input validationation for some Intel Unison software may allow a privileged user to potentially enable denial of service via local access.

CVE-2023-39230 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Insecure inherited permissions in some Intel Rapid Storage Technology software before version 16.8.5.1014.9 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-39228 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper access control for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access.

CVE-2023-39221 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper access control for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access.

CVE-2023-38570 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Access of memory location after end of buffer for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-38411 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper access control in the Intel Smart Campus android application before version 9.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-38131 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper input validationation for some Intel Unison software may allow an authenticated user to potentially enable denial of service via network access.

CVE-2023-36860 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper input validation for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access.

CVE-2023-34997 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Insecure inherited permissions in the installer for some Intel Server Configuration Utility software before version 16.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-34431 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper input validation in some Intel(R) Server Board BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access

CVE-2023-34430 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Uncontrolled search path in some Intel Battery Life Diagnostic Tool software before version 2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-34350 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Uncontrolled search path element in some Intel(R) XTU software before version 7.12.0.15 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-34314 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Insecure inherited permissions in some Intel(R) Simics Simulator software before version 1.7.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-33874 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Uncontrolled search path in some Intel(R) NUC 12 Pro Kits & Mini PCs - NUC12WS Intel(R) HID Event Filter Driver installation software before version 2.2.2.1 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-33872 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper access control in the Intel Support android application all verions may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2023-32662 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper authorization in some Intel Battery Life Diagnostic Tool installation software before version 2.2.1 may allow a privilaged user to potentially enable escalation of privilege via local access.

CVE-2023-32660 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Uncontrolled search path in some Intel(R) NUC Kit NUC6i7KYK Thunderbolt(TM) 3 Firmware Update Tool installation software before version 46 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-32641 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper input validation in firmware for Intel(R) QAT before version QAT20.L.1.0.40-00004 may allow escalation of privilege and denial of service via adjacent access.

CVE-2023-32638 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Incorrect default permissions in some Intel Arc RGB Controller software before version 1.06 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-32283 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Insertion of sensitive information into log file in some Intel(R) On Demand software before versions 1.16.2, 2.1.1, 3.1.0 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2023-32279 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper access control in user mode driver for some Intel(R) Connectivity Performance Suite before version 2.1123.214.2 may allow unauthenticated user to potentially enable information disclosure via network access.

CVE-2023-32204 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper access control in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-31273 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Protection mechanism failure in some Intel DCM software before version 5.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVE-2023-31203 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper input validation in some OpenVINO Model Server software before version 2022.3 for Intel Distribution of OpenVINO toolkit may allow an unauthenticated user to potentially enable denial of service via network access.

CVE-2023-29504 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Uncontrolled search path element in some Intel(R) RealSense(TM) Dynamic Calibration software before version 2.13.1.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-29161 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Uncontrolled search path in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-29157 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper access control in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-28741 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Buffer overflow in some Intel(R) QAT drivers for Windows - HW Version 1.0 before version 1.10 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-28740 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Uncontrolled search path element in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-28737 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper initialization in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-28723 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Exposure of sensitive information to an unauthorized actor in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2023-28397 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated to potentially enable escalation of privileges via local access.

CVE-2023-28388 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Uncontrolled search path element in some Intel(R) Chipset Device Software before version 10.1.19444.8378 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-28378 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper authorization in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-28376 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Out-of-bounds read in the firmware for some Intel(R) E810 Ethernet Controllers and Adapters before version 1.7.1 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2023-27879 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper access control in firmware for some Intel(R) Optane(TM) SSD products may allow an unauthenticated user to potentially enable information disclosure via physical access.

CVE-2023-27519 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper input validation in firmware for some Intel(R) Optane(TM) SSD products may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2023-27383 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Protection mechanism failure in some Intel(R) oneAPI HPC Toolkit 2023.1 and Intel(R)MPI Library software before version 2021.9 may allow a privileged user to potentially enable escalation of privilege via adjacent access.

CVE-2023-27306 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper Initialization in firmware for some Intel(R) Optane(TM) SSD products may allow an authenticated user to potentially enable denial of service via local access.

CVE-2023-26589 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Use after free in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allowed an authenticated user to potentially enable denial of service via local access.

CVE-2023-25949 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Uncontrolled resource consumption in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access.

CVE-2023-25756 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Out-of-bounds read in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2023-25080 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Protection mechanism failure in some Intel(R) Distribution of OpenVINO toolkit software before version 2023.0.0 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2023-25075 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Unquoted search path in the installer for some Intel Server Configuration Utility software before version 16.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-24592 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Path traversal in the some Intel(R) oneAPI Toolkits and Component software before version 2023.1 may allow authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-24588 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Exposure of sensitive information to an unauthorized actor in firmware for some Intel(R) Optane(TM) SSD products may allow an unauthenticated user to potentially enable information disclosure via physical access.

CVE-2023-24587 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Insufficient control flow management in firmware for some Intel(R) Optane(TM) SSD products may allow a privileged user to potentially enable denial of service via local access.

CVE-2023-23583 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege and/or information disclosure and/or denial of service via local access.

CVE-2023-22663 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper authentication for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via network access.

CVE-2023-22448 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper access control for some Intel Unison software may allow a privileged user to potentially enable escalation of privilege via network access.

CVE-2023-22337 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper input validation for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access.

CVE-2023-22329 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper input validation in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via adjacent access.

CVE-2023-22327 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Out-of-bounds write in firmware for some Intel(R) FPGA products before version 2.8.1 may allow a privileged user to potentially enable information disclosure via local access.

CVE-2023-22313 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper buffer restrictions in some Intel(R) QAT Library software before version 22.07.1 may allow a privileged user to potentially enable information disclosure via local access.

CVE-2023-22310 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Race condition in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access.

CVE-2023-22305 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Integer overflow in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable denial of service via local access.

CVE-2023-22292 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Uncaught exception for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-22290 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Uncaught exception for some Intel Unison software may allow an authenticated user to potentially enable denial of service via network access.

CVE-2023-22285 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper access control for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via network access.

CVE-2022-46647 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Insertion of sensitive information into log file for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-46646 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Exposure of sensitive information to an unauthorized actor for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-46301 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper Initialization for some Intel Unison software may allow a privileged user to potentially enable denial of service via local access.

CVE-2022-46299 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Insufficient control flow management for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-46298 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Incomplete cleanup for some Intel Unison software may allow a privileged user to potentially enable denial of service via local access.

CVE-2022-45469 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper input validation for some Intel Unison software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-45109 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper initialization for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-43666 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Exposure of sensitive system information due to uncleared debug information for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-43477 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Incomplete cleanup for some Intel Unison software may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-42879 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

NULL pointer dereference in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2022-41700 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Insecure inherited permissions in some Intel(R) NUC Pro Software Suite installation software before version 2.0.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-41689 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper access control in some Intel In-Band Manageability software before version 3.0.14 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-41659 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper access control for some Intel Unison software may allow a privileged user to potentially enable denial of service via local access.

CVE-2022-38786 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper access control in some Intel Battery Life Diagnostic Tool software before version 2.2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-36396 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmiEdit-Linux-5.27.06.0017 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-36374 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmi Windows 5.27.03.0003 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-33945 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper input validation in some Intel(R) Server board and Intel(R) Server System BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-29510 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper buffer restrictions in some Intel(R) Server Board M10JNP2SB BIOS firmware before version 7.219 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-29262 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper buffer restrictions in some Intel(R) Server Board BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-24379 intel vulnerability CVSS: 0 14 Nov 2023, 19:15 UTC

Improper input validation in some Intel(R) Server System M70KLP Family BIOS firmware before version 01.04.0029 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2023-44216 intel vulnerability CVSS: 0 27 Sep 2023, 15:19 UTC

PVRIC (PowerVR Image Compression) on Imagination 2018 and later GPU devices offers software-transparent compression that enables cross-origin pixel-stealing attacks against feTurbulence and feBlend in the SVG Filter specification, aka a GPU.zip issue. For example, attackers can sometimes accurately determine text contained on a web page from one origin if they control a resource from a different origin.

CVE-2023-24478 intel vulnerability CVSS: 0 15 Aug 2023, 13:15 UTC

Use of insufficiently random values for some Intel Agilex(R) software included as part of Intel(R) Quartus(R) Prime Pro Edition for linux before version 22.4 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2023-34438 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2023-34427 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Protection mechanism failure in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.25.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-34355 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Uncontrolled search path element for some Intel(R) Server Board M10JNP2SB integrated BMC video drivers before version 3.0 for Microsoft Windows and before version 1.13.4 for linux may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-34349 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Race condition in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2023-34086 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper input validation in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2023-33877 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Out-of-bounds write in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.25.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-33867 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper buffer restrictions in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.25.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-32656 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper buffer restrictions in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.25.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-32617 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper input validation in some Intel(R) NUC Rugged Kit, Intel(R) NUC Kit and Intel(R) Compute Element BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2023-32609 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper access control in the Intel Unite(R) android application before version 4.2.3504 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2023-32285 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper access control in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable denial of service via local access.

CVE-2023-31246 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Incorrect default permissions in some Intel(R) SDP Tool software before version 1.4 build 5 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-30760 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Out-of-bounds read in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.25.0 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2023-29500 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Exposure of sensitive information to an unauthorized actor in BIOS firmware for some Intel(R) NUCs may allow a privilege user to potentially enable information disclosure via local access.

CVE-2023-29494 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper input validation in BIOS firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2023-29243 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Unchecked return value in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.25.0 may allow a priviledged user to potentially enable denial of service via local access.

CVE-2023-28823 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-28714 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper access control in firmware for some Intel(R) PROSet/Wireless WiFi software for Windows before version 22.220 HF (Hot Fix) may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2023-28658 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Insecure inherited permissions in some Intel(R) oneMKL software before version 2022.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-28405 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Uncontrolled search path in the Intel(R) Distribution of OpenVINO(TM) Toolkit before version 2022.3.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-27887 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper initialization in BIOS firmware for some Intel(R) NUCs may allow a privileged user to potentially enable information disclosure via local access.

CVE-2023-27515 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Cross-site scripting (XSS) for the Intel(R) DSA software before version 23.1.9 may allow unauthenticated user to potentially enable escalation of privilege via network access.

CVE-2023-27392 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Incorrect default permissions in the Intel(R) Support android application before version v23.02.07 may allow a privileged user to potentially enable information disclosure via local access.

CVE-2023-27391 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2023-26587 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper input validation for the Intel(R) Easy Streaming Wizard software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-25773 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper access control in the Intel(R) Unite(R) Hub software installer for Windows before version 4.2.34962 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-25182 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Uncontrolled search path element in the Intel(R) Unite(R) Client software for Mac before version 4.2.11 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-24016 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Uncontrolled search path element in some Intel(R) Quartus(R) Prime Pro and Standard edition software for linux may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-23908 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to potentially enable information disclosure via local access.

CVE-2023-23577 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Uncontrolled search path element for some ITE Tech consumer infrared drivers before version 5.5.2.1 for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-22840 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper neutralization in software for the Intel(R) oneVPL GPU software before version 22.6.5 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2023-22449 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper input validation in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2023-22444 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper initialization in some Intel(R) NUC 13 Extreme Compute Element, Intel(R) NUC 13 Extreme Kit, Intel(R) NUC 11 Performance Kit, Intel(R) NUC 11 Performance Mini PC, Intel(R) NUC Compute Element, Intel(R) NUC Laptop Kit, Intel(R) NUC Pro Kit, Intel(R) NUC Pro Board and Intel(R) NUC Pro Mini PC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access.

CVE-2023-22356 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper initialization in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access.

CVE-2023-22338 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Out-of-bounds read in some Intel(R) oneVPL GPU software before version 22.6.5 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2023-22330 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Use of uninitialized resource in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access.

CVE-2023-22276 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Race condition in firmware for some Intel(R) Ethernet Controllers and Adapters E810 Series before version 1.7.2.4 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2022-46329 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Protection mechanism failure for some Intel(R) PROSet/Wireless WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-45112 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper access control in some Intel(R) VROC software before version 8.0.0.4035 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-44611 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via adjacent access.

CVE-2022-43505 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Insufficient control flow management in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable denial of service via local access.

CVE-2022-43456 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Uncontrolled search path in some Intel(R) RST software before versions 16.8.5.1014.5, 17.11.3.1010.2, 18.7.6.1011.2 and 19.5.2.1049.5 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-41984 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Protection mechanism failure for some Intel(R) Arc(TM) graphics cards A770 and A750 Limited Edition sold between October of 2022 and December of 2022 may allow a privileged user to potentially enable denial of service via local access.

CVE-2022-41804 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Unauthorized error injection in Intel(R) SGX or Intel(R) TDX for some Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-40982 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-40964 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-38973 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper access control for some Intel(R) Arc(TM) graphics cards A770 and A750 Limited Edition sold between October of 2022 and December of 2022 may allow an authenticated user to potentially enable denial of service or infomation disclosure via local access.

CVE-2022-38102 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper Input validation in firmware for some Intel(R) Converged Security and Management Engine before versions 15.0.45, and 16.1.27 may allow a privileged user to potentially enable denial of service via local access.

CVE-2022-38083 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper initialization in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.

CVE-2022-38076 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-37343 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper access control in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-37336 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper input validation in BIOS firmware for some Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-36392 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper input validation in some firmware for Intel(R) AMT and Intel(R) Standard Manageability before versions 11.8.94, 11.12.94, 11.22.94, 12.0.93, 14.1.70, 15.0.45, and 16.1.27 in Intel (R) CSME may allow an unauthenticated user to potentially enable denial of service via network access.

CVE-2022-36372 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper buffer restrictions in some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-36351 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2022-29887 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Cross-site Scripting (XSS) in some Intel(R) Manageability Commander software before version 2.3 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVE-2022-29871 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper access control in the Intel(R) CSME software installer before version 2239.3.7.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-27879 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper buffer restrictions in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.

CVE-2022-27635 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-25864 intel vulnerability CVSS: 0 11 Aug 2023, 03:15 UTC

Uncontrolled search path in some Intel(R) oneMKL software before version 2022.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-31199 intel vulnerability CVSS: 0 12 May 2023, 15:15 UTC

Improper access control in the Intel(R) Solid State Drive Toolbox(TM) before version 3.4.5 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2023-31197 intel vulnerability CVSS: 0 12 May 2023, 15:15 UTC

Uncontrolled search path in the Intel(R) Trace Analyzer and Collector before version 2020 update 3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-30768 intel vulnerability CVSS: 0 12 May 2023, 15:15 UTC

Improper access control in the Intel(R) Server Board S2600WTT belonging to the Intel(R) Server Board S2600WT Family with the BIOS version 0016 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2023-30763 intel vulnerability CVSS: 0 12 May 2023, 15:15 UTC

Heap-based overflow in Intel(R) SoC Watch based software before version 2021.1 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2023-29242 intel vulnerability CVSS: 0 12 May 2023, 15:15 UTC

Improper access control for Intel(R) oneAPI Toolkits before version 2021.1 Beta 10 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-28411 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Double free in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable information disclosure via local access.

CVE-2023-28410 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper restriction of operations within the bounds of a memory buffer in some Intel(R) i915 Graphics drivers for linux before kernel version 6.2.10 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-27386 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Uncontrolled search path in some Intel(R) Pathfinder for RISC-V software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-27382 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Incorrect default permissions in the Audio Service for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.0.0.156 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-25776 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper input validation in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable information disclosure via local access.

CVE-2023-25772 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper input validation in the Intel(R) Retail Edge Mobile Android application before version 3.0.301126-RELEASE may allow an authenticated user to potentially enable denial of service via local access.

CVE-2023-25771 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable denial of service via local access.

CVE-2023-25545 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper buffer restrictions in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable escalation of privilege via local access.

CVE-2023-25179 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Uncontrolled resource consumption in the Intel(R) Unite(R) android application before Release 17 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2023-25175 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper input validation in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable information disclosure via local access.

CVE-2023-24475 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Out of bounds read in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable information disclosure via local access.

CVE-2023-23910 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Out-of-bounds write for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an authenticated user to potentially escalation of privilege via local access.

CVE-2023-23909 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Out-of-bounds read for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2023-23580 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Stack-based buffer overflow for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an authenticated user to potentially escalation of privilege via local access.

CVE-2023-23573 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper access control in the Intel(R) Unite(R) android application before Release 17 may allow a privileged user to potentially enable information disclosure via local access.

CVE-2023-23569 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Stack-based buffer overflow for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-22661 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Buffer overflow in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable escalation of privilege via local access.

CVE-2023-22447 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Insertion of sensitive information into log file in the Open CAS software for Linux maintained by Intel before version 22.6.2 may allow a privileged user to potentially enable information disclosure via local access.

CVE-2023-22443 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Integer overflow in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable denial of service via local access.

CVE-2023-22442 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Out of bounds write in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable escalation of privilege via local access.

CVE-2023-22440 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Incorrect default permissions in the Intel(R) SCS Add-on software installer for Microsoft SCCM all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-22379 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper input validation in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable information disclosure via local access.

CVE-2023-22355 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-22312 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2023-22297 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Access of memory location after end of buffer in some Intel(R) Server Board BMC firmware before version 2.90 may allow a privileged user to enable escalation of privilege via local access.

CVE-2022-46656 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Insecure inherited permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-46645 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Uncontrolled resource consumption in the Intel(R) Smart Campus Android application before version 9.9 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2022-46279 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper access control in the Intel(R) Retail Edge android application before version 3.0.301126-RELEASE may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-45128 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper authorization in the Intel(R) EMA software before version 1.9.0.0 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2022-44619 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Insecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-44610 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper authentication in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via network access.

CVE-2022-43507 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper buffer restrictions in the Intel(R) QAT Engine for OpenSSL before version 0.6.16 may allow a privileged user to potentially enable escalation of privilege via network access.

CVE-2022-43475 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Insecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-43474 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Uncontrolled search path for the DSP Builder software installer before version 22.4 for Intel(R) FPGAs Pro Edition may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-43465 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper authorization in the Intel(R) SCS software all versions may allow an authenticated user to potentially enable denial of service via local access.

CVE-2022-42878 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Null pointer dereference for some Intel(R) Trace Analyzer and Collector software before version 2021.8.0 published Dec 2022 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-42465 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper access control in kernel mode driver for the Intel(R) OFU software before version 14.1.30 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-41998 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Uncontrolled search path in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-41982 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Uncontrolled search path element in the Intel(R) VTune(TM) Profiler software before version 2023.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-41979 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Protection mechanism failure in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via network access.

CVE-2022-41808 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper buffer restriction in software for the Intel QAT Driver for Linux before version 1.7.l.4.12 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2022-41801 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Uncontrolled resource consumption in the Intel(R) Connect M Android application before version 1.82 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2022-41784 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper access control in kernel mode driver for the Intel(R) OFU software before version 14.1.30 may allow an authenticated user to potentially enable escalation of privilege via local access

CVE-2022-41771 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Incorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-41769 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper access control in the Intel(R) Connect M Android application before version 1.82 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-41699 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Incorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-41693 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Uncontrolled search path in the Intel(R) Quartus(R) Prime Pro edition software before version 22.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-41690 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper access control in the Intel(R) Retail Edge Mobile iOS application before version 3.4.7 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-41687 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Insecure inherited permissions in the HotKey Services for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.1.44 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-41658 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Insecure inherited permissions in the Intel(R) VTune(TM) Profiler software before version 2023.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-41646 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Insufficient control flow management in the Intel(R) IPP Cryptography software before version 2021.6 may allow an unauthenticated user to potentially enable information disclosure via local access.

CVE-2022-41628 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Uncontrolled search path element in the HotKey Services for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.1.44 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-41621 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-41610 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper authorization in Intel(R) EMA Configuration Tool before version 1.0.4 and Intel(R) MC before version 2.4 software may allow an authenticated user to potentially enable denial of service via local access.

CVE-2022-40974 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Incomplete cleanup in the Intel(R) IPP Cryptography software before version 2021.6 may allow a privileged user to potentially enable information disclosure via local access.

CVE-2022-40972 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-40971 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Incorrect default permissions for the Intel(R) HDMI Firmware Update Tool for NUC before version 1.79.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-40685 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Insufficiently protected credentials in the Intel(R) DCM software before version 5.0.1 may allow an authenticated user to potentially enable information disclosure via network access.

CVE-2022-40210 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Exposure of data element to wrong session in the Intel DCM software before version 5.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-40207 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper access control in the Intel(R) SUR software before version 2.4.8989 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-38787 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper input validation in firmware for some Intel(R) FPGA products before version 2.7.0 Hotfix may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-38103 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Insecure inherited permissions in the Intel(R) NUC Software Studio Service installer before version 1.17.38.0 may allow an authenticated user to potentially enable escalation of privilege via local access

CVE-2022-38101 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Uncontrolled search path in some Intel(R) NUC Chaco Canyon BIOS update software before version iFlashV Windows 5.13.00.2105 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-38087 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Exposure of resource to wrong sphere in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.

CVE-2022-37409 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Insufficient control flow management for the Intel(R) IPP Cryptography software before version 2021.6 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-37327 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper input validation in BIOS firmware for Intel(R) NUC, Intel(R) NUC Performance Kit, Intel(R) NUC Performance Mini PC, Intel(R) NUC 8 Compute Element, Intel(R) NUC Pro Kit, Intel(R) NUC Pro Board, Intel(R) NUC 11 Compute Element, Intel(R) NUC 12 Compute Element, Intel(R) NUC Extreme, Intel(R) NUC 12 Extreme Compute Element, Intel(R) NUC Laptop Kit, Intel(R) NUC Enthusiast, Intel(R) NUC Essential, Intel(R) NUC Laptop Kit, Intel(R) NUC Extreme Compute Element, Intel(R) NUC Boards, Intel(R) NUC Pro Compute Element, Intel(R) NUC Rugged may allow a privileged user to enable information disclosure via local access.

CVE-2022-36391 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Incorrect default permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-36339 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper input validation in firmware for Intel(R) NUC 8 Compute Element, Intel(R) NUC 11 Compute Element, Intel(R) NUC 12 Compute Element may allow a privileged user to enable escalation of privilege via local access.

CVE-2022-34855 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Path traversal for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-34848 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Uncontrolled search path for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-34147 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper input validation in BIOS firmware for some Intel(R) NUC 9 Extreme Laptop Kits, Intel(R) NUC Performance Kits, Intel(R) NUC Performance Mini PC, Intel(R) NUC 8 Compute Element, Intel(R) NUC Pro Kit, Intel(R) NUC Pro Board, and Intel(R) NUC Compute Element may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-33963 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Incorrect default permissions in the software installer for Intel(R) Unite(R) Client software for Windows before version 4.2.34870 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-33894 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-32766 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper input validation for some Intel(R) BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-32582 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper access control in firmware for some Intel(R) NUC Boards, Intel(R) NUC 11 Performance Kit, Intel(R) NUC 11 Performance Mini PC, Intel(R) NUC Pro Compute Element may allow a privileged user to potentially enable denial of service via local access.

CVE-2022-32578 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper access control for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-32577 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper input validation in BIOS Firmware for some Intel(R) NUC Kits before version PY0081 may allow a privileged user to potentially enable information disclosure or denial of service via local access

CVE-2022-32576 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Uncontrolled search path in the Intel(R) Unite(R) Plugin SDK before version 4.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-31477 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper initialization for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable information disclosure via local access.

CVE-2022-30338 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Incorrect default permissions in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-29919 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Use after free in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-29508 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Null pointer dereference in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-28699 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper input validation for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-25976 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Improper input validation in the Intel(R) VROC software before version 7.7.6.1003 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2022-21804 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Out-of-bounds write in software for the Intel QAT Driver for Windows before version 1.9.0-0008 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-21239 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Out-of-bounds read in software for the Intel QAT Driver for Windows before version 1.9.0-0008 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-21162 intel vulnerability CVSS: 0 10 May 2023, 14:15 UTC

Uncontrolled search path for the Intel(R) HDMI Firmware Update tool for NUC before version 1.79.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-28488 intel vulnerability CVSS: 0 12 Apr 2023, 16:15 UTC

client.c in gdhcp in ConnMan through 1.41 could be used by network-adjacent attackers (operating a crafted DHCP server) to cause a stack-based buffer overflow and denial of service, terminating the connman process.

CVE-2022-41614 intel vulnerability CVSS: 0 16 Feb 2023, 21:15 UTC

Insufficiently protected credentials in the Intel(R) ON Event Series Android application before version 2.0 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-41314 intel vulnerability CVSS: 0 16 Feb 2023, 21:15 UTC

Uncontrolled search path in some Intel(R) Network Adapter installer software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-38090 intel vulnerability CVSS: 0 16 Feb 2023, 21:15 UTC

Improper isolation of shared resources in some Intel(R) Processors when using Intel(R) Software Guard Extensions may allow a privileged user to potentially enable information disclosure via local access.

CVE-2022-38056 intel vulnerability CVSS: 0 16 Feb 2023, 21:15 UTC

Improper neutralization in the Intel(R) EMA software before version 1.8.1.0 may allow a privileged user to potentially enable escalation of privilege via network access.

CVE-2022-37340 intel vulnerability CVSS: 0 16 Feb 2023, 21:15 UTC

Uncontrolled search path in some Intel(R) QAT drivers for Windows before version 1.6 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-36397 intel vulnerability CVSS: 0 16 Feb 2023, 21:15 UTC

Incorrect default permissions in the software installer for some Intel(R) QAT drivers for Linux before version 4.17 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-36382 intel vulnerability CVSS: 0 16 Feb 2023, 21:15 UTC

Out-of-bounds write in firmware for some Intel(R) Ethernet Network Controllers and Adapters E810 Series before version 1.7.0.8 and some Intel(R) Ethernet 700 Series Controllers and Adapters before version 9.101 may allow a privileged user to potentially enable denial of service via local access.

CVE-2022-36369 intel vulnerability CVSS: 0 16 Feb 2023, 21:15 UTC

Improper access control in some QATzip software maintained by Intel(R) before version 1.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-36287 intel vulnerability CVSS: 0 16 Feb 2023, 21:15 UTC

Uncaught exception in the FCS Server software maintained by Intel before version 1.1.79.3 may allow a privileged user to potentially enable denial of service via physical access.

CVE-2022-34864 intel vulnerability CVSS: 0 16 Feb 2023, 21:15 UTC

Out-of-bounds read in the Intel(R) Trace Analyzer and Collector software before version 2021.5 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-34854 intel vulnerability CVSS: 0 16 Feb 2023, 21:15 UTC

Improper access control in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-34843 intel vulnerability CVSS: 0 16 Feb 2023, 21:15 UTC

Integer overflow in the Intel(R) Trace Analyzer and Collector software before version 2021.5 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-33972 intel vulnerability CVSS: 0 16 Feb 2023, 21:15 UTC

Incorrect calculation in microcode keying mechanism for some 3rd Generation Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable information disclosure via local access.

CVE-2022-33964 intel vulnerability CVSS: 0 16 Feb 2023, 21:15 UTC

Improper input validation in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVE-2022-33946 intel vulnerability CVSS: 0 16 Feb 2023, 21:15 UTC

Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-33196 intel vulnerability CVSS: 0 16 Feb 2023, 21:15 UTC

Incorrect default permissions in some memory controller configurations for some Intel(R) Xeon(R) Processors when using Intel(R) Software Guard Extensions which may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-33190 intel vulnerability CVSS: 0 16 Feb 2023, 21:15 UTC

Improper input validation in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-32971 intel vulnerability CVSS: 0 16 Feb 2023, 21:15 UTC

Improper authentication in the Intel(R) SUR software before version 2.4.8902 may allow a privileged user to potentially enable escalation of privilege via network access.

CVE-2022-32575 intel vulnerability CVSS: 0 16 Feb 2023, 21:15 UTC

Out-of-bounds write in the Intel(R) Trace Analyzer and Collector software before version 2021.5 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-31476 intel vulnerability CVSS: 0 16 Feb 2023, 21:15 UTC

Improper access control in the Intel(R) SUR software before version 2.4.8902 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2022-30692 intel vulnerability CVSS: 0 16 Feb 2023, 21:15 UTC

Improper conditions check in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potentially enable denial of service via network access.

CVE-2022-29514 intel vulnerability CVSS: 0 16 Feb 2023, 21:15 UTC

Improper access control in the Intel(R) SUR software before version 2.4.8902 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVE-2022-29494 intel vulnerability CVSS: 0 16 Feb 2023, 21:15 UTC

Improper input validation in firmware for OpenBMC in some Intel(R) platforms before versions egs-0.91-179 and bhs-04-45 may allow an authenticated user to potentially enable denial of service via network access.

CVE-2022-29493 intel vulnerability CVSS: 0 16 Feb 2023, 21:15 UTC

Uncaught exception in webserver for the Integrated BMC in some Intel(R) platforms before versions 2.86, 2.09 and 2.78 may allow a privileged user to potentially enable denial of service via network access.

CVE-2022-27808 intel vulnerability CVSS: 0 16 Feb 2023, 21:15 UTC

Insufficient control flow management in some Intel(R) Ethernet Controller Administrative Tools drivers for Windows before version 1.5.0.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-27234 intel vulnerability CVSS: 0 16 Feb 2023, 21:15 UTC

Server-side request forgery in the CVAT software maintained by Intel(R) before version 2.0.1 may allow an authenticated user to potentially enable information disclosure via network access.

CVE-2022-21163 intel vulnerability CVSS: 0 16 Feb 2023, 21:15 UTC

Improper access control in the Crypto API Toolkit for Intel(R) SGX before version 2.0 commit ID 91ee496 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-33104 intel vulnerability CVSS: 0 16 Feb 2023, 21:15 UTC

Improper access control in the Intel(R) OFU software before version 14.1.28 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2022-37329 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Uncontrolled search path in some Intel(R) Quartus(R) Prime Pro and Standard Edition software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-36794 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Improper condition check in some Intel(R) SPS firmware before version SPS_E3_06.00.03.300.0 may allow a privileged user to potentially enable denial of service via local access.

CVE-2022-36398 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Uncontrolled search path in the Intel(R) Battery Life Diagnostic Tool software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-36348 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Active debug code in some Intel (R) SPS firmware before version SPS_E5_04.04.04.300.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-36278 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Insufficient control flow management in the Intel(R) Battery Life Diagnostic Tool software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-34849 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Uncaught exception in the Intel(R) Iris(R) Xe MAX drivers for Windows before version 100.0.5.1436(v2) may allow a privileged user to potentially enable denial of service via local access.

CVE-2022-34157 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Improper access control in the Intel(R) FPGA SDK for OpenCL(TM) with Intel(R) Quartus(R) Prime Pro Edition software before version 22.1 may allow authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-34153 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Improper initialization in the Intel(R) Battery Life Diagnostic Tool software before version 2.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-33902 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Insufficient control flow management in the Intel(R) Quartus Prime Pro and Standard edition software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-33892 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Path traversal in the Intel(R) Quartus Prime Pro and Standard edition software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-32764 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Description: Race condition in the Intel(R) DSA software before version 22.4.26 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-32570 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Improper authentication in the Intel(R) Quartus Prime Pro and Standard edition software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-32231 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Improper initialization in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-30704 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Improper initialization in the Intel(R) TXT SINIT ACM for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-30539 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Use after free in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-30531 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Out-of-bounds read in the Intel(R) Iris(R) Xe MAX drivers for Windows before version 100.0.5.1474 may allow a privileged user to potentially enable information disclosure via local access.

CVE-2022-30530 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Protection mechanism failure in the Intel(R) DSA software before version 22.4.26 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-30339 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Out-of-bounds read in firmware for the Intel(R) Integrated Sensor Solution before versions 5.4.2.4579v3, 5.4.1.4479 and 5.0.0.4143 may allow a privileged user to potentially enable denial of service via local access.

CVE-2022-26888 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Cross-site scripting in the Intel(R) Quartus Prime Pro and Standard edition software may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-26843 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Insufficient visual distinction of homoglyphs presented to user in the Intel(R) oneAPI DPC++/C++ Compiler before version 2022.1 for Intel(R) oneAPI Toolkits before version 2022.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVE-2022-26841 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Insufficient control flow management for the Intel(R) SGX SDK software for Linux before version 2.16.100.1 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-26840 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Improper neutralization in the Intel(R) Quartus Prime Pro and Standard edition software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-26837 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-26512 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Uncontrolled search path element in the Intel(R) FPGA Add-on for Intel(R) oneAPI Base Toolkit before version 2022.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-26509 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Improper conditions check in the Intel(R) SGX SDK software may allow a privileged user to potentially enable information disclosure via local access.

CVE-2022-26425 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Uncontrolled search path element in the Intel(R) oneAPI Collective Communications Library (oneCCL) before version 2021.6 for Intel(R) oneAPI Base Toolkit may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-26421 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Uncontrolled search path element in the Intel(R) oneAPI DPC++/C++ Compiler Runtime before version 2022.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-26345 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Uncontrolled search path element in the Intel(R) oneAPI Toolkit OpenMP before version 2022.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-26343 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Improper access control in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-26076 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Uncontrolled search path element in the Intel(R) oneAPI Deep Neural Network (oneDNN) before version 2022.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-26062 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Uncontrolled search path element in the Intel(R) Trace Analyzer and Collector before version 2021.6 for Intel(R) oneAPI HPC Toolkit may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-26052 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Uncontrolled search path element in the Intel(R) MPI Library before version 2021.6 for Intel(R) oneAPI HPC Toolkit may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-26032 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Uncontrolled search path element in the Intel(R) Distribution for Python programming language before version 2022.1 for Intel(R) oneAPI Toolkits may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-25992 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Insecure inherited permissions in the Intel(R) oneAPI Toolkits oneapi-cli before version 0.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-25987 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Improper handling of Unicode encoding in source code to be compiled by the Intel(R) C++ Compiler Classic before version 2021.6 for Intel(R) oneAPI Toolkits before version 2022.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVE-2022-25905 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Uncontrolled search path element in the Intel(R) oneAPI Data Analytics Library (oneDAL) before version 2021.5 for Intel(R) oneAPI Base Toolkit may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-21216 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Insufficient granularity of access control in out-of-band management in some Intel(R) Atom and Intel Xeon Scalable Processors may allow a privileged user to potentially enable escalation of privilege via adjacent network access.

CVE-2021-0187 intel vulnerability CVSS: 0 16 Feb 2023, 20:15 UTC

Improper access control in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.

CVE-2022-41342 intel vulnerability CVSS: 0 06 Feb 2023, 19:15 UTC

Improper buffer restrictions in the Intel(R) C++ Compiler Classic before version 2021.7.1 for some Intel(R) oneAPI Toolkits before version 2022.3.1 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-40196 intel vulnerability CVSS: 0 06 Feb 2023, 19:15 UTC

Improper access control in the Intel(R) oneAPI DPC++/C++ Compiler before version 2022.2.1 and Intel C++ Compiler Classic before version 2021.7.1 for some Intel(R) oneAPI Toolkits before version 2022.3.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-38136 intel vulnerability CVSS: 0 06 Feb 2023, 19:15 UTC

Uncontrolled search path in the Intel(R) oneAPI DPC++/C++ Compiler for Windows and Intel Fortran Compiler for Windows before version 2022.2.1 for some Intel(R) oneAPI Toolkits before version 2022.3.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-38099 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Improper input validation in BIOS firmware for some Intel(R) NUC 11 Compute Elements before version EBTGL357.0065 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-37345 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Improper authentication in BIOS firmware[A1] for some Intel(R) NUC Kits before version RY0386 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-37334 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Improper initialization in BIOS firmware for some Intel(R) NUC 11 Pro Kits and Intel(R) NUC 11 Pro Boards before version TNTGL357.0064 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-36789 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Improper access control in BIOS firmware for some Intel(R) NUC 10 Performance Kits and Intel(R) NUC 10 Performance Mini PCs before version FNCML357.0053 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-36370 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Improper authentication in BIOS firmware for some Intel(R) NUC Boards and Intel(R) NUC Kits before version MYi30060 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-36367 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Incorrect default permissions in the Intel(R) Support Android application before version v22.02.28 may allow a privileged user to potentially enable information disclosure via local access.

CVE-2022-36349 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Insecure default variable initialization in BIOS firmware for some Intel(R) NUC Boards and Intel(R) NUC Kits before version MYi30060 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2022-35276 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Improper access control in BIOS firmware for some Intel(R) NUC 8 Compute Elements before version CBWHL357.0096 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-34152 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Improper input validation in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC Kits before version TY0070 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-33942 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Protection mechanism failure in the Intel(R) DCM software before version 5.0 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2022-33176 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Improper input validation in BIOS firmware for some Intel(R) NUC 11 Performance kits and Intel(R) NUC 11 Performance Mini PCs before version PATGL357.0042 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-32569 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Improper buffer restrictions in BIOS firmware for some Intel(R) NUC M15 Laptop Kits before version BCTGL357.0074 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-30691 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Uncontrolled resource consumption in the Intel(R) Support Android application before version 22.02.28 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2022-30548 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Uncontrolled search path element in the Intel(R) Glorp software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-30297 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Cross-site scripting in the Intel(R) EMA software before version 1.8.0 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-29893 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Improper authentication in firmware for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an authenticated user to potentially enable escalation of privilege via network access.

CVE-2022-29515 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Missing release of memory after effective lifetime in firmware for Intel(R) SPS before versions SPS_E3_06.00.03.035.0 may allow a privileged user to potentially enable denial of service via local access.

CVE-2022-29466 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Improper input validation in firmware for Intel(R) SPS before version SPS_E3_04.01.04.700.0 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2022-28667 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi software before version 22.140 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2022-27499 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Premature release of resource during expected lifetime in the Intel(R) SGX SDK software may allow a privileged user to potentially enable information disclosure via local access.

CVE-2022-27497 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Null pointer dereference in firmware for Intel(R) AMT before version 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an unauthenticated user to potentially enable denial of service via network access.

CVE-2022-27233 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

XML injection in the Quartus(R) Prime Programmer included in the Intel(R) Quartus Prime Pro and Standard edition software may allow an unauthenticated user to potentially enable information disclosure via network access.

CVE-2022-27187 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Uncontrolled search path element in the Intel(R) Quartus Prime Standard edition software before version 21.1 Patch 0.02std may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-26845 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Improper authentication in firmware for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVE-2022-26508 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Improper authentication in the Intel(R) SDP Tool before version 3.0.0 may allow an unauthenticated user to potentially enable information disclosure via network access.

CVE-2022-26341 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Insufficiently protected credentials in software in Intel(R) AMT SDK before version 16.0.4.1, Intel(R) EMA before version 1.7.1 and Intel(R) MC before version 2.3.2 may allow an authenticated user to potentially enable escalation of privilege via network access.

CVE-2022-26124 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Improper buffer restrictions in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC 8 Boards, Intel(R) NUC 8 Rugged Boards and Intel(R) NUC 8 Rugged Kits before version CHAPLCEL.0059 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-26086 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Uncontrolled search path element in the PresentMon software maintained by Intel(R) before version 1.7.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-26047 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Improper input validation for some Intel(R) PROSet/Wireless WiFi, Intel vPro(R) CSME WiFi and Killer(TM) WiFi products may allow unauthenticated user to potentially enable denial of service via local access.

CVE-2022-26028 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Uncontrolled search path in the Intel(R) VTune(TM) Profiler software before version 2022.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-26024 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Improper access control in the Intel(R) NUC HDMI Firmware Update Tool for NUC7i3DN, NUC7i5DN and NUC7i7DN before version 1.78.2.0.7 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-26006 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-21794 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Improper authentication in BIOS firmware for some Intel(R) NUC Boards, Intel(R) NUC Business, Intel(R) NUC Enthusiast, Intel(R) NUC Kits before version HN0067 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-21198 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Time-of-check time-of-use race condition in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2021-33164 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Improper access control in BIOS firmware for some Intel(R) NUCs before version INWHL357.0046 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2021-33159 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Improper authentication in subsystem for Intel(R) AMT before versions 11.8.93, 11.22.93, 11.12.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2021-33064 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Uncontrolled search path in the software installer for Intel(R) System Studio for all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-26251 intel vulnerability CVSS: 0 11 Nov 2022, 16:15 UTC

Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Toolkit may allow an authenticated user to potentially enable denial of service via network access.

CVE-2021-0185 intel vulnerability CVSS: 0 10 Nov 2022, 23:15 UTC

Improper input validation in the firmware for some Intel(R) Server Board M10JNP Family before version 7.216 may allow a privileged user to potentially enable an escalation of privilege via local access.

CVE-2022-40262 intel vulnerability CVSS: 0 20 Sep 2022, 18:15 UTC

A potential attacker can execute an arbitrary code at the time of the PEI phase and influence the subsequent boot stages. This can lead to the mitigations bypassing, physical memory contents disclosure, discovery of any secrets from any Virtual Machines (VMs) and bypassing memory isolation and confidential computing boundaries. Additionally, an attacker can build a payload which can be injected into the SMRAM memory. This issue affects: Module name: S3Resume2Pei SHA256: 7bb29f05534a8a1e010443213451425098faebd45948a4642db969b19d0253fc Module GUID: 89E549B0-7CFE-449D-9BA3-10D8B2312D71

CVE-2022-40261 intel vulnerability CVSS: 0 20 Sep 2022, 18:15 UTC

An attacker can exploit this vulnerability to elevate privileges from ring 0 to ring -2, execute arbitrary code in System Management Mode - an environment more privileged than operating system (OS) and completely isolated from it. Running arbitrary code in SMM additionally bypasses SMM-based SPI flash protections against modifications, which can help an attacker to install a firmware backdoor/implant into BIOS. Such a malicious firmware code in BIOS could persist across operating system re-installs. Additionally, this vulnerability potentially could be used by malicious actors to bypass security mechanisms provided by UEFI firmware (for example, Secure Boot and some types of memory isolation for hypervisors). This issue affects: Module name: OverClockSmiHandler SHA256: a204699576e1a48ce915d9d9423380c8e4c197003baf9d17e6504f0265f3039c Module GUID: 4698C2BD-A903-410E-AD1F-5EEF3A1AE422

CVE-2022-40250 intel vulnerability CVSS: 0 20 Sep 2022, 18:15 UTC

An attacker can exploit this vulnerability to elevate privileges from ring 0 to ring -2, execute arbitrary code in System Management Mode - an environment more privileged than operating system (OS) and completely isolated from it. Running arbitrary code in SMM additionally bypasses SMM-based SPI flash protections against modifications, which can help an attacker to install a firmware backdoor/implant into BIOS. Such a malicious firmware code in BIOS could persist across operating system re-installs. Additionally, this vulnerability potentially could be used by malicious actors to bypass security mechanisms provided by UEFI firmware (for example, Secure Boot and some types of memory isolation for hypervisors). This issue affects: Module name: SmmSmbiosElog SHA256: 3a8acb4f9bddccb19ec3b22b22ad97963711550f76b27b606461cd5073a93b59 Module GUID: 8e61fd6b-7a8b-404f-b83f-aa90a47cabdf This issue affects: AMI Aptio 5.x. This issue affects: AMI Aptio 5.x.

CVE-2022-40246 intel vulnerability CVSS: 0 20 Sep 2022, 18:15 UTC

A potential attacker can write one byte by arbitrary address at the time of the PEI phase (only during S3 resume boot mode) and influence the subsequent boot stages. This can lead to the mitigations bypassing, physical memory contents disclosure, discovery of any secrets from any Virtual Machines (VMs) and bypassing memory isolation and confidential computing boundaries. Additionally, an attacker can build a payload which can be injected into the SMRAM memory. This issue affects: Module name: SbPei SHA256: d827182e5f9b7a9ff0b9d3e232f7cfac43b5237e2681e11f005be627a49283a9 Module GUID: c1fbd624-27ea-40d1-aa48-94c3dc5c7e0d

CVE-2022-26873 intel vulnerability CVSS: 0 20 Sep 2022, 18:15 UTC

A potential attacker can execute an arbitrary code at the time of the PEI phase and influence the subsequent boot stages. This can lead to the mitigations bypassing, physical memory contents disclosure, discovery of any secrets from any Virtual Machines (VMs) and bypassing memory isolation and confidential computing boundaries. Additionally, an attacker can build a payload which can be injected into the SMRAM memory. This issue affects: Module name: PlatformInitAdvancedPreMem SHA256: 644044fdb8daea30a7820e0f5f88dbf5cd460af72fbf70418e9d2e47efed8d9b Module GUID: EEEE611D-F78F-4FB9-B868-55907F169280 This issue affects: AMI Aptio 5.x.

CVE-2021-33081 intel vulnerability CVSS: 0 20 Sep 2022, 15:15 UTC

Protection mechanism failure in firmware for some Intel(R) SSD DC Products may allow a privileged user to potentially enable information disclosure via local access.

CVE-2021-33079 intel vulnerability CVSS: 0 20 Sep 2022, 15:15 UTC

Protection mechanism failure in firmware for some Intel(R) SSD DC Products may allow a privileged user to potentially enable information disclosure via local access.

CVE-2021-33076 intel vulnerability CVSS: 0 20 Sep 2022, 15:15 UTC

Improper authentication in firmware for some Intel(R) SSD DC Products may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVE-2022-34488 intel vulnerability CVSS: 0 18 Aug 2022, 21:15 UTC

Improper buffer restrictions in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-34345 intel vulnerability CVSS: 0 18 Aug 2022, 21:15 UTC

Improper input validation in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentially enable escalation of privilege via physical access.

CVE-2022-33209 intel vulnerability CVSS: 0 18 Aug 2022, 21:15 UTC

Improper input validation in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-32579 intel vulnerability CVSS: 0 18 Aug 2022, 21:15 UTC

Improper initialization in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentially enable escalation of privilege via physical access.

CVE-2022-30944 intel vulnerability CVSS: 0 18 Aug 2022, 21:15 UTC

Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable information disclosure via local access.

CVE-2022-30601 intel vulnerability CVSS: 0 18 Aug 2022, 21:15 UTC

Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially enable information disclosure and escalation of privilege via network access.

CVE-2022-28858 intel vulnerability CVSS: 0 18 Aug 2022, 21:15 UTC

Improper buffer restriction in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-28697 intel vulnerability CVSS: 0 18 Aug 2022, 21:15 UTC

Improper access control in firmware for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVE-2022-27493 intel vulnerability CVSS: 0 18 Aug 2022, 21:15 UTC

Improper initialization in the firmware for some Intel(R) NUC Laptop Kits before version BC0076 may allow a privileged user to potentially enable an escalation of privilege via local access.

CVE-2022-30296 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Insufficiently protected credentials in the Intel(R) Datacenter Group Event iOS application, all versions, may allow an unauthenticated user to potentially enable information disclosure via network access.

CVE-2022-29507 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Insufficiently protected credentials in the Intel(R) Team Blue mobile application in all versions may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-28709 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Improper access control in the firmware for some Intel(R) E810 Ethernet Controllers before version 1.6.1.9 may allow a privileged user to potentially enable denial of service via local access.

CVE-2022-28696 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Uncontrolled search path in the Intel(R) Distribution for Python before version 2022.0.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-27500 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Incorrect default permissions for the Intel(R) Support Android application before 21.07.40 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-26844 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Insufficiently protected credentials in the installation binaries for Intel(R) SEAPI in all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-26374 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Uncontrolled search path in the installation binaries for Intel(R) SEAPI all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-26373 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

CVE-2022-26344 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Incorrect default permissions in the installation binaries for Intel(R) SEAPI all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-26074 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Incomplete cleanup in a firmware subsystem for Intel(R) SPS before versions SPS_E3_04.08.04.330.0 and SPS_E3_04.01.04.530.0 may allow a privileged user to potentially enable denial of service via local access.

CVE-2022-26017 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Improper access control in the Intel(R) DSA software for before version 22.2.14 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2022-25999 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Uncontrolled search path element in the Intel(R) Enpirion(R) Digital Power Configurator GUI software, all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-25966 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Improper access control in the Intel(R) Edge Insights for Industrial software before version 2.6.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-25899 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Authentication bypass for the Open AMT Cloud Toolkit software maintained by Intel(R) before versions 2.0.2 and 2.2.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVE-2022-25841 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Uncontrolled search path elements in the Intel(R) Datacenter Group Event Android application, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-24378 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Improper initialization in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2022-23403 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Improper input validation in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2022-23182 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Improper access control in the Intel(R) Data Center Manager software before version 4.1 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2022-22730 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Improper authentication in the Intel(R) Edge Insights for Industrial software before version 2.6.1 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVE-2022-21812 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Improper access control in the Intel(R) HAXM software before version 7.7.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-21807 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Uncontrolled search path elements in the Intel(R) VTune(TM) Profiler software before version 2022.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-21240 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Out of bounds read for some Intel(R) PROSet/Wireless WiFi products may allow a privileged user to potentially enable information disclosure via local access.

CVE-2022-21233 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Improper isolation of shared resources in some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.

CVE-2022-21229 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Improper buffer restrictions for some Intel(R) NUC 9 Extreme Laptop Kit drivers before version 2.2.0.22 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-21225 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Improper neutralization in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2022-21212 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Improper input validation for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2022-21197 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Improper input validation for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable denial of service via network access.

CVE-2022-21181 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Improper input validation for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-21172 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Out of bounds write for some Intel(R) PROSet/Wireless WiFi products may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-21160 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Improper buffer restrictions for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable denial of service via network access.

CVE-2022-21152 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Improper access control in the Intel(R) Edge Insights for Industrial software before version 2.6.1 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-21148 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Improper access control in the Intel(R) Edge Insights for Industrial software before version 2.6.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-21140 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable information disclosure via local access.

CVE-2022-21139 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Inadequate encryption strength for some Intel(R) PROSet/Wireless WiFi products may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2021-44545 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Improper input validation for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2021-44470 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Incorrect default permissions for the Intel(R) Connect M Android application before version 1.7.4 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2021-37409 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2021-33847 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Improper buffer restrictions in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-33128 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Improper access control in the firmware for some Intel(R) E810 Ethernet Controllers before version 1.6.0.6 may allow a privileged user to potentially enable denial of service via local access.

CVE-2021-33126 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Improper access control in the firmware for some Intel(R) 700 and 722 Series Ethernet Controllers and Adapters before versions 8.5 and 1.5.5 may allow a privileged user to potentially enable denial of service via local access.

CVE-2021-33060 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Out-of-bounds write in the BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-26950 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Out of bounds read in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2021-26257 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Improper buffer restrictions in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2021-26254 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Out of bounds read for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable denial of service via local access.

CVE-2021-23223 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Improper initialization for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2021-23188 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2021-23179 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Out of bounds read in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.120 may allow a privileged user to potentially enable information disclosure via local access.

CVE-2021-23168 intel vulnerability CVSS: 0 18 Aug 2022, 20:15 UTC

Out of bounds read for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2022-32293 intel vulnerability CVSS: 0 03 Aug 2022, 14:15 UTC

In ConnMan through 1.41, a man-in-the-middle attack against a WISPR HTTP query could be used to trigger a use-after-free in WISPR handling, leading to crashes or code execution.

CVE-2022-32292 intel vulnerability CVSS: 0 03 Aug 2022, 14:15 UTC

In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-based buffer overflow in received_data to execute code.

CVE-2022-29901 intel vulnerability CVSS: 1.9 12 Jul 2022, 19:15 UTC

Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions.

CVE-2022-24436 intel vulnerability CVSS: 4.0 15 Jun 2022, 21:15 UTC

Observable behavioral in power management throttling for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via network access.

CVE-2022-21180 intel vulnerability CVSS: 4.9 15 Jun 2022, 21:15 UTC

Improper input validation for some Intel(R) Processors may allow an authenticated user to potentially cause a denial of service via local access.

CVE-2022-21166 intel vulnerability CVSS: 2.1 15 Jun 2022, 21:15 UTC

Incomplete cleanup in specific special register write operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-21127 intel vulnerability CVSS: 2.1 15 Jun 2022, 20:15 UTC

Incomplete cleanup in specific special register read operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-21125 intel vulnerability CVSS: 2.1 15 Jun 2022, 20:15 UTC

Incomplete cleanup of microarchitectural fill buffers on some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-21123 intel vulnerability CVSS: 2.1 15 Jun 2022, 20:15 UTC

Incomplete cleanup of multi-core shared buffers for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-24382 intel vulnerability CVSS: 4.6 12 May 2022, 17:15 UTC

Improper input validation in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-24297 intel vulnerability CVSS: 4.6 12 May 2022, 17:15 UTC

Improper buffer restrictions in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-22139 intel vulnerability CVSS: 4.4 12 May 2022, 17:15 UTC

Uncontrolled search path in the Intel(R) XTU software before version 7.3.0.33 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-21237 intel vulnerability CVSS: 6.1 12 May 2022, 17:15 UTC

Improper buffer access in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2022-21151 intel vulnerability CVSS: 2.1 12 May 2022, 17:15 UTC

Processor optimization removal or modification of security-critical code for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-21136 intel vulnerability CVSS: 4.9 12 May 2022, 17:15 UTC

Improper input validation for some Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable denial of service via local access.

CVE-2022-21131 intel vulnerability CVSS: 2.1 12 May 2022, 17:15 UTC

Improper access control for some Intel(R) Xeon(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-21128 intel vulnerability CVSS: 4.6 12 May 2022, 17:15 UTC

Insufficient control flow management in the Intel(R) Advisor software before version 7.6.0.37 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-0005 intel vulnerability CVSS: 2.1 12 May 2022, 17:15 UTC

Sensitive information accessible by physical probing of JTAG interface for some Intel(R) Processors with SGX may allow an unprivileged user to potentially enable information disclosure via physical access.

CVE-2022-0004 intel vulnerability CVSS: 7.2 12 May 2022, 17:15 UTC

Hardware debug modes and processor INIT setting that allow override of locks for some Intel(R) Processors in Intel(R) Boot Guard and Intel(R) TXT may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVE-2021-33149 intel vulnerability CVSS: 2.1 12 May 2022, 17:15 UTC

Observable behavioral discrepancy in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

CVE-2021-33135 intel vulnerability CVSS: 2.1 12 May 2022, 17:15 UTC

Uncontrolled resource consumption in the Linux kernel drivers for Intel(R) SGX may allow an authenticated user to potentially enable denial of service via local access.

CVE-2021-33130 intel vulnerability CVSS: 2.1 12 May 2022, 17:15 UTC

Insecure default variable initialization of Intel(R) RealSense(TM) ID Solution F450 before version 2.6.0.74 may allow an unauthenticated user to potentially enable information disclosure via physical access.

CVE-2021-33124 intel vulnerability CVSS: 7.2 12 May 2022, 17:15 UTC

Out-of-bounds write in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

CVE-2021-33123 intel vulnerability CVSS: 7.2 12 May 2022, 17:15 UTC

Improper access control in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

CVE-2021-33122 intel vulnerability CVSS: 7.2 12 May 2022, 17:15 UTC

Insufficient control flow management in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

CVE-2021-33117 intel vulnerability CVSS: 2.1 12 May 2022, 17:15 UTC

Improper access control for some 3rd Generation Intel(R) Xeon(R) Scalable Processors before BIOS version MR7, may allow a local attacker to potentially enable information disclosure via local access.

CVE-2021-33108 intel vulnerability CVSS: 4.6 12 May 2022, 17:15 UTC

Improper input validation in the Intel(R) In-Band Manageability software before version 2.13.0 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2021-33103 intel vulnerability CVSS: 7.2 12 May 2022, 17:15 UTC

Unintended intermediary in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

CVE-2021-33083 intel vulnerability CVSS: 2.1 12 May 2022, 17:15 UTC

Improper authentication in firmware for some Intel(R) SSD, Intel(R) Optane(TM) SSD, Intel(R) Optane(TM) SSD DC and Intel(R) SSD DC Products may allow an privileged user to potentially enable information disclosure via local access.

CVE-2021-33082 intel vulnerability CVSS: 2.1 12 May 2022, 17:15 UTC

Sensitive information in resource not removed before reuse in firmware for some Intel(R) SSD and Intel(R) Optane(TM) SSD Products may allow an unauthenticated user to potentially enable information disclosure via physical access.

CVE-2021-33080 intel vulnerability CVSS: 4.6 12 May 2022, 17:15 UTC

Exposure of sensitive system information due to uncleared debug information in firmware for some Intel(R) SSD DC, Intel(R) Optane(TM) SSD and Intel(R) Optane(TM) SSD DC Products may allow an unauthenticated user to potentially enable information disclosure or escalation of privilege via physical access.

CVE-2021-33078 intel vulnerability CVSS: 4.7 12 May 2022, 17:15 UTC

Race condition within a thread in firmware for some Intel(R) Optane(TM) SSD and Intel(R) SSD DC Products may allow a privileged user to potentially enable denial of service via local access.

CVE-2021-33077 intel vulnerability CVSS: 4.6 12 May 2022, 17:15 UTC

Insufficient control flow management in firmware for some Intel(R) SSD, Intel(R) Optane(TM) SSD and Intel(R) SSD DC Products may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVE-2021-33075 intel vulnerability CVSS: 4.7 12 May 2022, 17:15 UTC

Race condition in firmware for some Intel(R) Optane(TM) SSD, Intel(R) Optane(TM) SSD DC and Intel(R) SSD DC Products may allow a privileged user to potentially enable denial of service via local access.

CVE-2021-33074 intel vulnerability CVSS: 2.1 12 May 2022, 17:15 UTC

Protection mechanism failure in firmware for some Intel(R) SSD, Intel(R) SSD DC and Intel(R) Optane(TM) SSD Products may allow an unauthenticated user to potentially enable information disclosure via physical access.

CVE-2021-33069 intel vulnerability CVSS: 4.9 12 May 2022, 17:15 UTC

Improper resource shutdown or release in firmware for some Intel(R) SSD, Intel(R) SSD DC, Intel(R) Optane(TM) SSD and Intel(R) Optane(TM) SSD DC may allow a privileged user to potentially enable denial of service via local access.

CVE-2021-26258 intel vulnerability CVSS: 4.6 12 May 2022, 17:15 UTC

Improper access control for the Intel(R) Killer(TM) Control Center software before version 2.4.3337.0 may allow an authorized user to potentially enable escalation of privilege via local access.

CVE-2021-0194 intel vulnerability CVSS: 6.5 12 May 2022, 17:15 UTC

Improper access control in the Intel(R) In-Band Manageability software before version 2.13.0 may allow a privileged user to potentially enable escalation of privilege via network access.

CVE-2021-0190 intel vulnerability CVSS: 7.2 12 May 2022, 17:15 UTC

Uncaught exception in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

CVE-2021-0189 intel vulnerability CVSS: 7.2 12 May 2022, 17:15 UTC

Use of out-of-range pointer offset in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

CVE-2021-0188 intel vulnerability CVSS: 7.2 12 May 2022, 17:15 UTC

Return of pointer value outside of expected range in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

CVE-2021-0159 intel vulnerability CVSS: 7.2 12 May 2022, 17:15 UTC

Improper input validation in the BIOS authenticated code module for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

CVE-2021-0155 intel vulnerability CVSS: 2.1 12 May 2022, 17:15 UTC

Unchecked return value in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.

CVE-2021-0154 intel vulnerability CVSS: 7.2 12 May 2022, 17:15 UTC

Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

CVE-2021-0153 intel vulnerability CVSS: 7.2 12 May 2022, 17:15 UTC

Out-of-bounds write in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable aescalation of privilege via local access.

CVE-2021-0126 intel vulnerability CVSS: 5.2 12 May 2022, 17:15 UTC

Improper input validation for the Intel(R) Manageability Commander before version 2.2 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2022-0002 intel vulnerability CVSS: 2.1 11 Mar 2022, 18:15 UTC

Non-transparent sharing of branch predictor within a context in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

CVE-2022-0001 intel vulnerability CVSS: 2.1 11 Mar 2022, 18:15 UTC

Non-transparent sharing of branch predictor selectors between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

CVE-2021-33150 intel vulnerability CVSS: 4.6 11 Mar 2022, 18:15 UTC

Hardware allows activation of test or debug logic at runtime for some Intel(R) Trace Hub instances which may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVE-2022-21226 intel vulnerability CVSS: 2.1 09 Feb 2022, 23:15 UTC

Out-of-bounds read in the Intel(R) Trace Analyzer and Collector before version 2021.5 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-21220 intel vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

Improper restriction of XML external entity for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-21218 intel vulnerability CVSS: 2.1 09 Feb 2022, 23:15 UTC

Uncaught exception in the Intel(R) Trace Analyzer and Collector before version 2021.5 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-21205 intel vulnerability CVSS: 5.0 09 Feb 2022, 23:15 UTC

Improper restriction of XML external entity reference in DSP Builder Pro for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an unauthenticated user to potentially enable information disclosure via network access.

CVE-2022-21204 intel vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

Improper permissions for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-21203 intel vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

Improper permissions in the SafeNet Sentinel driver for Intel(R) Quartus(R) Prime Standard Edition before version 21.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-21174 intel vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

Improper access control in a third-party component of Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2022-21157 intel vulnerability CVSS: 2.1 09 Feb 2022, 23:15 UTC

Improper access control in the Intel(R) Smart Campus Android application before version 6.1 may allow authenticated user to potentially enable information disclosure via local access.

CVE-2022-21156 intel vulnerability CVSS: 2.1 09 Feb 2022, 23:15 UTC

Access of uninitialized pointer in the Intel(R) Trace Analyzer and Collector before version 2021.5 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2022-21153 intel vulnerability CVSS: 2.1 09 Feb 2022, 23:15 UTC

Improper access control in the Intel(R) Capital Global Summit Android application may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2022-21133 intel vulnerability CVSS: 2.1 09 Feb 2022, 23:15 UTC

Out-of-bounds read in the Intel(R) Trace Analyzer and Collector before version 2021.5 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2021-44454 intel vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

Improper input validation in a third-party component for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-33166 intel vulnerability CVSS: 2.1 09 Feb 2022, 23:15 UTC

Incorrect default permissions for the Intel(R) RXT for Chromebook application, all versions, may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2021-33155 intel vulnerability CVSS: 2.7 09 Feb 2022, 23:15 UTC

Improper input validation in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.100 may allow an authenticated user to potentially enable denial of service via adjacent access.

CVE-2021-33147 intel vulnerability CVSS: 2.1 09 Feb 2022, 23:15 UTC

Improper conditions check in the Intel(R) IPP Crypto library before version 2021.2 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2021-33139 intel vulnerability CVSS: 2.7 09 Feb 2022, 23:15 UTC

Improper conditions check in firmware for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products before version 22.100 may allow an authenticated user to potentially enable denial of service via adjacent access.

CVE-2021-33137 intel vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

Out-of-bounds write in the Intel(R) Kernelflinger project may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-33129 intel vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

Incorrect default permissions in the software installer for the Intel(R) Advisor before version 2021.4.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-33120 intel vulnerability CVSS: 5.5 09 Feb 2022, 23:15 UTC

Out of bounds read under complex microarchitectural condition in memory subsystem for some Intel Atom(R) Processors may allow authenticated user to potentially enable information disclosure or cause denial of service via network access.

CVE-2021-33119 intel vulnerability CVSS: 2.1 09 Feb 2022, 23:15 UTC

Improper access control in the Intel(R) RealSense(TM) DCM before version 20210625 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2021-33115 intel vulnerability CVSS: 5.8 09 Feb 2022, 23:15 UTC

Improper input validation for some Intel(R) PROSet/Wireless WiFi in UEFI may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2021-33114 intel vulnerability CVSS: 2.7 09 Feb 2022, 23:15 UTC

Improper input validation for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and Killer(TM) WiFi in Windows 10 and 11 may allow an authenticated user to potentially enable denial of service via adjacent access.

CVE-2021-33113 intel vulnerability CVSS: 4.8 09 Feb 2022, 23:15 UTC

Improper input validation for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and Killer(TM) WiFi in Windows 10 and 11 may allow an unauthenticated user to potentially enable denial of service or information disclosure via adjacent access.

CVE-2021-33110 intel vulnerability CVSS: 3.3 09 Feb 2022, 23:15 UTC

Improper input validation for some Intel(R) Wireless Bluetooth(R) products and Killer(TM) Bluetooth(R) products in Windows 10 and 11 before version 22.80 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2021-33107 intel vulnerability CVSS: 2.1 09 Feb 2022, 23:15 UTC

Insufficiently protected credentials in USB provisioning for Intel(R) AMT SDK before version 16.0.3, Intel(R) SCS before version 12.2 and Intel(R) MEBx before versions 11.0.0.0012, 12.0.0.0011, 14.0.0.0004 and 15.0.0.0004 may allow an unauthenticated user to potentially enable information disclosure via physical access.

CVE-2021-33105 intel vulnerability CVSS: 2.1 09 Feb 2022, 23:15 UTC

Out-of-bounds read in some Intel(R) Core(TM) processors with Radeon(TM) RX Vega M GL integrated graphics before version 21.10 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2021-33101 intel vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

Uncontrolled search path in the Intel(R) GPA software before version 21.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-33096 intel vulnerability CVSS: 2.1 09 Feb 2022, 23:15 UTC

Improper isolation of shared resources in network on chip for the Intel(R) 82599 Ethernet Controllers and Adapters may allow an authenticated user to potentially enable denial of service via local access.

CVE-2021-33068 intel vulnerability CVSS: 4.0 09 Feb 2022, 23:15 UTC

Null pointer dereference in subsystem for Intel(R) AMT before versions 15.0.35 may allow an authenticated user to potentially enable denial of service via network access.

CVE-2021-33061 intel vulnerability CVSS: 2.1 09 Feb 2022, 23:15 UTC

Insufficient control flow management for the Intel(R) 82599 Ethernet Controllers and Adapters may allow an authenticated user to potentially enable denial of service via local access.

CVE-2021-23152 intel vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

Improper access control in the Intel(R) Advisor software before version 2021.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-0183 intel vulnerability CVSS: 3.3 09 Feb 2022, 23:15 UTC

Improper Validation of Specified Index, Position, or Offset in Input in software for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2021-0179 intel vulnerability CVSS: 3.3 09 Feb 2022, 23:15 UTC

Improper Use of Validation Framework in software for Intel(R) PROSet/Wireless Wi-Fi and Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2021-0178 intel vulnerability CVSS: 3.3 09 Feb 2022, 23:15 UTC

Improper input validation in software for Intel(R) PROSet/Wireless Wi-Fi and Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2021-0177 intel vulnerability CVSS: 3.3 09 Feb 2022, 23:15 UTC

Improper Validation of Consistency within input in software for Intel(R) PROSet/Wireless Wi-Fi and Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2021-0176 intel vulnerability CVSS: 2.1 09 Feb 2022, 23:15 UTC

Improper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable denial of service via local access.

CVE-2021-0175 intel vulnerability CVSS: 3.3 09 Feb 2022, 23:15 UTC

Improper Validation of Specified Index, Position, or Offset in Input in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2021-0174 intel vulnerability CVSS: 3.3 09 Feb 2022, 23:15 UTC

Improper Use of Validation Framework in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2021-0173 intel vulnerability CVSS: 3.3 09 Feb 2022, 23:15 UTC

Improper Validation of Consistency within input in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2021-0172 intel vulnerability CVSS: 3.3 09 Feb 2022, 23:15 UTC

Improper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2021-0171 intel vulnerability CVSS: 2.1 09 Feb 2022, 23:15 UTC

Improper access control in software for Intel(R) PROSet/Wireless Wi-Fi and Killer(TM) Wi-Fi in Windows 10 and 11 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2021-0170 intel vulnerability CVSS: 2.1 09 Feb 2022, 23:15 UTC

Exposure of Sensitive Information to an Unauthorized Actor in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2021-0169 intel vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

Uncontrolled Search Path Element in software for Intel(R) PROSet/Wireless Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2021-0168 intel vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

Improper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2021-0167 intel vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

Improper access control in software for Intel(R) PROSet/Wireless Wi-Fi and Killer(TM) Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2021-0166 intel vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

Exposure of Sensitive Information to an Unauthorized Actor in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2021-0165 intel vulnerability CVSS: 3.3 09 Feb 2022, 23:15 UTC

Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2021-0164 intel vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

Improper access control in firmware for Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable escalation of privilege via local access.

CVE-2021-0163 intel vulnerability CVSS: 5.8 09 Feb 2022, 23:15 UTC

Improper Validation of Consistency within input in software for Intel(R) PROSet/Wireless Wi-Fi and Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2021-0162 intel vulnerability CVSS: 5.8 09 Feb 2022, 23:15 UTC

Improper input validation in software for Intel(R) PROSet/Wireless Wi-Fi and Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2021-0161 intel vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and Killer(TM) Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2021-0156 intel vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an escalation of privilege via local access.

CVE-2021-0147 intel vulnerability CVSS: 2.1 09 Feb 2022, 23:15 UTC

Improper locking in the Power Management Controller (PMC) for some Intel Chipset firmware before versions pmc_fw_lbg_c1-21ww02a and pmc_fw_lbg_b0-21ww02a may allow a privileged user to potentially enable denial of service via local access.

CVE-2021-0145 intel vulnerability CVSS: 2.1 09 Feb 2022, 23:15 UTC

Improper initialization of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2021-0127 intel vulnerability CVSS: 2.1 09 Feb 2022, 23:15 UTC

Insufficient control flow management in some Intel(R) Processors may allow an authenticated user to potentially enable a denial of service via local access.

CVE-2021-0125 intel vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.

CVE-2021-0124 intel vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

Improper access control in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.

CVE-2021-0119 intel vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.

CVE-2021-0118 intel vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

Out-of-bounds read in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.

CVE-2021-0117 intel vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

Pointer issues in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.

CVE-2021-0116 intel vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

Out-of-bounds write in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.

CVE-2021-0115 intel vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

Buffer overflow in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2021-0111 intel vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

NULL pointer dereference in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.

CVE-2021-0107 intel vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

Unchecked return value in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2021-0103 intel vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

Insufficient control flow management in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.

CVE-2021-0099 intel vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

Insufficient control flow management in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an escalation of privilege via local access.

CVE-2021-0093 intel vulnerability CVSS: 2.1 09 Feb 2022, 23:15 UTC

Incorrect default permissions in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access.

CVE-2021-0092 intel vulnerability CVSS: 2.1 09 Feb 2022, 23:15 UTC

Improper access control in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access.

CVE-2021-0091 intel vulnerability CVSS: 7.2 09 Feb 2022, 23:15 UTC

Improper access control in the firmware for some Intel(R) Processors may allow an unauthenticated user to potentially enable an escalation of privilege via local access.

CVE-2021-0076 intel vulnerability CVSS: 2.1 09 Feb 2022, 23:15 UTC

Improper Validation of Specified Index, Position, or Offset in Input in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable denial of service via local access.

CVE-2021-0072 intel vulnerability CVSS: 2.1 09 Feb 2022, 23:15 UTC

Improper input validation in firmware for some Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and some Killer(TM) Wi-Fi in Windows 10 and 11 may allow a privileged user to potentially enable information disclosure via local access.

CVE-2021-0066 intel vulnerability CVSS: 4.6 09 Feb 2022, 23:15 UTC

Improper input validation in firmware for Intel(R) PROSet/Wireless Wi-Fi in multiple operating systems and Killer(TM) Wi-Fi in Windows 10 and 11 may allow an unauthenticated user to potentially enable escalation of privilege via local access.

CVE-2022-23098 intel vulnerability CVSS: 5.0 28 Jan 2022, 16:15 UTC

An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation has an infinite loop if no data is received.

CVE-2022-23097 intel vulnerability CVSS: 6.4 28 Jan 2022, 16:15 UTC

An issue was discovered in the DNS proxy in Connman through 1.40. forward_dns_reply mishandles a strnlen call, leading to an out-of-bounds read.

CVE-2022-23096 intel vulnerability CVSS: 6.4 28 Jan 2022, 16:15 UTC

An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation lacks a check for the presence of sufficient Header Data, leading to an out-of-bounds read.

CVE-2021-45046 intel vulnerability CVSS: 5.1 14 Dec 2021, 19:15 UTC

It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout with either a Context Lookup (for example, $${ctx:loginId}) or a Thread Context Map pattern (%X, %mdc, or %MDC) to craft malicious input data using a JNDI Lookup pattern resulting in an information leak and remote code execution in some environments and local code execution in all environments. Log4j 2.16.0 (Java 8) and 2.12.2 (Java 7) fix this issue by removing support for message lookup patterns and disabling JNDI functionality by default.

CVE-2021-44228 intel vulnerability CVSS: 9.3 10 Dec 2021, 10:15 UTC

Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled. From log4j 2.15.0, this behavior has been disabled by default. From version 2.16.0 (along with 2.12.2, 2.12.3, and 2.3.1), this functionality has been completely removed. Note that this vulnerability is specific to log4j-core and does not affect log4net, log4cxx, or other Apache Logging Services projects.

CVE-2021-33118 intel vulnerability CVSS: 4.6 17 Nov 2021, 20:15 UTC

Improper access control in the software installer for the Intel(R) Serial IO driver for Intel(R) NUC 11 Gen before version 30.100.2104.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-33098 intel vulnerability CVSS: 4.9 17 Nov 2021, 20:15 UTC

Improper input validation in the Intel(R) Ethernet ixgbe driver for Linux before version 3.17.3 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2021-33097 intel vulnerability CVSS: 6.0 17 Nov 2021, 20:15 UTC

Time-of-check time-of-use vulnerability in the Crypto API Toolkit for Intel(R) SGX may allow a privileged user to potentially enable escalation of privilege via network access.

CVE-2021-33073 intel vulnerability CVSS: 2.1 17 Nov 2021, 20:15 UTC

Uncontrolled resource consumption in the Intel(R) Distribution of OpenVINOâ„¢ Toolkit before version 2021.4 may allow an unauthenticated user to potentially enable denial of service via local access.

CVE-2021-33071 intel vulnerability CVSS: 4.6 17 Nov 2021, 20:15 UTC

Incorrect default permissions in the installer for the Intel(R) oneAPI Rendering Toolkit before version 2021.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-33063 intel vulnerability CVSS: 4.4 17 Nov 2021, 20:15 UTC

Uncontrolled search path in the Intel(R) RealSense(TM) D400 Series UWP driver for Windows 10 before version 6.1.160.22 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-33062 intel vulnerability CVSS: 4.6 17 Nov 2021, 20:15 UTC

Incorrect default permissions in the software installer for the Intel(R) VTune(TM) Profiler before version 2021.3.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-33059 intel vulnerability CVSS: 4.6 17 Nov 2021, 20:15 UTC

Improper input validation in the Intel(R) Administrative Tools for Intel(R) Network Adapters driver for Windows before version 1.4.0.15, may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2021-33058 intel vulnerability CVSS: 4.6 17 Nov 2021, 20:15 UTC

Improper access control in the installer Intel(R)Administrative Tools for Intel(R) Network Adaptersfor Windowsbefore version 1.4.0.21 may allow an unauthenticated user to potentially enable escalation of privilege via local access.

CVE-2021-0200 intel vulnerability CVSS: 4.6 17 Nov 2021, 20:15 UTC

Out-of-bounds write in the firmware for Intel(R) Ethernet 700 Series Controllers before version 8.2 may allow a privileged user to potentially enable an escalation of privilege via local access.

CVE-2021-0199 intel vulnerability CVSS: 2.1 17 Nov 2021, 20:15 UTC

Improper input validation in the firmware for the Intel(R) Ethernet Network Controller E810 before version 1.6.0.6 may allow a privileged user to potentially enable a denial of service via local access.

CVE-2021-0198 intel vulnerability CVSS: 2.1 17 Nov 2021, 20:15 UTC

Improper access control in the firmware for the Intel(R) Ethernet Network Controller E810 before version 1.5.5.6 may allow a privileged user to potentially enable a denial of service via local access.

CVE-2021-0197 intel vulnerability CVSS: 2.1 17 Nov 2021, 20:15 UTC

Protection mechanism failure in the firmware for the Intel(R) Ethernet Network Controller E810 before version 1.5.5.6 may allow a privileged user to enable a denial of service via local access.

CVE-2021-0186 intel vulnerability CVSS: 4.6 17 Nov 2021, 20:15 UTC

Improper input validation in the Intel(R) SGX SDK applications compiled for SGX2 enabled processors may allow a privileged user to potentially escalation of privilege via local access.

CVE-2021-0182 intel vulnerability CVSS: 2.1 17 Nov 2021, 20:15 UTC

Uncontrolled resource consumption in the Intel(R) HAXM software before version 7.6.6 may allow an unauthenticated user to potentially enable information disclosure via local access.

CVE-2021-0180 intel vulnerability CVSS: 4.6 17 Nov 2021, 20:15 UTC

Uncontrolled resource consumption in the Intel(R) HAXM software before version 7.6.6 may allow an unauthenticated user to potentially enable privilege escalation via local access.

CVE-2021-0158 intel vulnerability CVSS: 4.6 17 Nov 2021, 20:15 UTC

Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2021-0157 intel vulnerability CVSS: 4.6 17 Nov 2021, 20:15 UTC

Insufficient control flow management in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2021-0152 intel vulnerability CVSS: 2.1 17 Nov 2021, 20:15 UTC

Improper verification of cryptographic signature in the installer for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products in Windows 10 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2021-0151 intel vulnerability CVSS: 4.6 17 Nov 2021, 20:15 UTC

Improper access control in the installer for some Intel(R) Wireless Bluetooth(R) and Killer(TM) Bluetooth(R) products in Windows 10 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-0148 intel vulnerability CVSS: 2.1 17 Nov 2021, 20:15 UTC

Insertion of information into log file in firmware for some Intel(R) SSD DC may allow a privileged user to potentially enable information disclosure via local access.

CVE-2021-0146 intel vulnerability CVSS: 4.6 17 Nov 2021, 20:15 UTC

Hardware allows activation of test or debug logic at runtime for some Intel(R) processors which may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVE-2021-0135 intel vulnerability CVSS: 4.6 17 Nov 2021, 20:15 UTC

Improper input validation in the Intel(R) Ethernet Diagnostic Driver for Windows before version 1.4.0.10 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2021-0120 intel vulnerability CVSS: 2.1 17 Nov 2021, 20:15 UTC

Improper initialization in the installer for some Intel(R) Graphics DCH Drivers for Windows 10 before version 27.20.100.9316 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2021-0110 intel vulnerability CVSS: 2.1 17 Nov 2021, 20:15 UTC

Improper access control in some Intel(R) Thunderbolt(TM) Windows DCH Drivers before version 1.41.1054.0 may allow unauthenticated user to potentially enable denial of service via local access.

CVE-2021-0082 intel vulnerability CVSS: 4.4 17 Nov 2021, 20:15 UTC

Uncontrolled search path in software installer for Intel(R) PROSet/Wireless WiFi in Windows 10 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-0079 intel vulnerability CVSS: 6.1 17 Nov 2021, 20:15 UTC

Improper input validation in software for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi in Windows 10 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2021-0078 intel vulnerability CVSS: 6.8 17 Nov 2021, 20:15 UTC

Improper input validation in software for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi in Windows 10 may allow an unauthenticated user to potentially enable denial of service or information disclosure via adjacent access.

CVE-2021-0075 intel vulnerability CVSS: 2.1 17 Nov 2021, 20:15 UTC

Out-of-bounds write in firmware for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and some Killer(TM) WiFi in Windows 10 may allow a privileged user to potentially enable denial of service via local access.

CVE-2021-0071 intel vulnerability CVSS: 5.8 17 Nov 2021, 20:15 UTC

Improper input validation in firmware for some Intel(R) PROSet/Wireless WiFi in UEFI may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2021-0069 intel vulnerability CVSS: 3.3 17 Nov 2021, 20:15 UTC

Improper input validation in firmware for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and some Killer(TM) WiFi in Windows 10 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2021-0065 intel vulnerability CVSS: 4.6 17 Nov 2021, 20:15 UTC

Incorrect default permissions in the Intel(R) PROSet/Wireless WiFi software installer for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-0064 intel vulnerability CVSS: 4.6 17 Nov 2021, 20:15 UTC

Insecure inherited permissions in the Intel(R) PROSet/Wireless WiFi software installer for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-0063 intel vulnerability CVSS: 6.1 17 Nov 2021, 20:15 UTC

Improper input validation in firmware for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi in Windows 10 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2021-0053 intel vulnerability CVSS: 2.7 17 Nov 2021, 20:15 UTC

Improper initialization in firmware for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi in Windows 10 may allow an authenticated user to potentially enable information disclosure via adjacent access.

CVE-2021-0013 intel vulnerability CVSS: 5.0 17 Nov 2021, 20:15 UTC

Improper input validation for Intel(R) EMA before version 1.5.0 may allow an unauthenticated user to potentially enable denial of service via network access.

CVE-2020-8741 intel vulnerability CVSS: 4.6 17 Nov 2021, 20:15 UTC

Improper permissions in the installer for the Intel(R) Thunderbolt(TM) non-DCH driver, all versions, for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-33090 intel vulnerability CVSS: 7.2 17 Nov 2021, 19:15 UTC

Incorrect default permissionsin the software installer for the Intel(R) NUC HDMI Firmware Update Tool for NUC10i3FN, NUC10i5FN, NUC10i7FN before version 1.78.2.0.7 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-33089 intel vulnerability CVSS: 4.6 17 Nov 2021, 19:15 UTC

Improper access control in the software installer for the Intel(R) NUC HDMI Firmware Update Tool for NUC8i3BE, NUC8i5BE, NUC8i7BE before version 1.78.4.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-33086 intel vulnerability CVSS: 4.9 17 Nov 2021, 19:15 UTC

Out-of-bounds write in firmware for some Intel(R) NUCs may allow an authenticated user to potentially enable denial of service via local access.

CVE-2021-0121 intel vulnerability CVSS: 4.6 17 Nov 2021, 19:15 UTC

Improper access control in the installer for some Intel(R) Iris(R) Xe MAX Dedicated Graphics Drivers for Windows 10 before version 27.20.100.9466 may allow authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-0114 intel vulnerability CVSS: 7.2 16 Aug 2021, 19:15 UTC

Unchecked return value in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.

CVE-2021-0196 intel vulnerability CVSS: 4.6 11 Aug 2021, 13:15 UTC

Improper access control in kernel mode driver for some Intel(R) NUC 9 Extreme Laptop Kits before version 2.2.0.20 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-0160 intel vulnerability CVSS: 4.6 11 Aug 2021, 13:15 UTC

Uncontrolled search path in some Intel(R) NUC Pro Chassis Element AverMedia Capture Card drivers before version 3.0.64.143 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-0084 intel vulnerability CVSS: 4.6 11 Aug 2021, 13:15 UTC

Improper input validation in the Intel(R) Ethernet Controllers X722 and 800 series Linux RMDA driver before version 1.3.19 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-0083 intel vulnerability CVSS: 2.1 11 Aug 2021, 13:15 UTC

Improper input validation in some Intel(R) Optane(TM) PMem versions before versions 1.2.0.5446 or 2.2.0.1547 may allow a privileged user to potentially enable denial of service via local access.

CVE-2021-0062 intel vulnerability CVSS: 4.6 11 Aug 2021, 13:15 UTC

Improper input validation in some Intel(R) Graphics Drivers before version 27.20.100.8935 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-0061 intel vulnerability CVSS: 4.6 11 Aug 2021, 13:15 UTC

Improper initialization in some Intel(R) Graphics Driver before version 27.20.100.9030 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-0012 intel vulnerability CVSS: 2.1 11 Aug 2021, 13:15 UTC

Use after free in some Intel(R) Graphics Driver before version 27.20.100.8336, 15.45.33.5164, and 15.40.47.5166 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2021-0009 intel vulnerability CVSS: 3.3 11 Aug 2021, 13:15 UTC

Out-of-bounds read in the firmware for Intel(R) Ethernet Adapters 800 Series Controllers and associated adapters before version 1.5.3.0 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2021-0008 intel vulnerability CVSS: 2.1 11 Aug 2021, 13:15 UTC

Uncontrolled resource consumption in firmware for Intel(R) Ethernet Adapters 800 Series Controllers and associated adapters before version 1.5.3.0 may allow privileged user to potentially enable denial of service via local access.

CVE-2021-0007 intel vulnerability CVSS: 2.1 11 Aug 2021, 13:15 UTC

Uncaught exception in firmware for Intel(R) Ethernet Adapters 800 Series Controllers and associated adapters before version 1.5.1.0 may allow a privileged attacker to potentially enable denial of service via local access.

CVE-2021-0006 intel vulnerability CVSS: 2.1 11 Aug 2021, 13:15 UTC

Improper conditions check in firmware for Intel(R) Ethernet Adapters 800 Series Controllers and associated adapters before version 1.5.4.0 may allow a privileged user to potentially enable denial of service via local access.

CVE-2021-0005 intel vulnerability CVSS: 2.1 11 Aug 2021, 13:15 UTC

Uncaught exception in firmware for Intel(R) Ethernet Adapters 800 Series Controllers and associated adapters before version 1.5.3.0 may allow a privileged user to potentially enable denial of service via local access.

CVE-2021-0004 intel vulnerability CVSS: 2.1 11 Aug 2021, 13:15 UTC

Improper buffer restrictions in the firmware of Intel(R) Ethernet Adapters 800 Series Controllers and associated adapters before version 1.5.3.0 may allow a privileged user to potentially enable denial of service via local access.

CVE-2021-0003 intel vulnerability CVSS: 2.1 11 Aug 2021, 13:15 UTC

Improper conditions check in some Intel(R) Ethernet Controllers 800 series Linux drivers before version 1.4.11 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2021-0002 intel vulnerability CVSS: 3.6 11 Aug 2021, 13:15 UTC

Improper conditions check in some Intel(R) Ethernet Controllers 800 series Linux drivers before version 1.4.11 may allow an authenticated user to potentially enable information disclosure or denial of service via local access.

CVE-2021-0144 intel vulnerability CVSS: 7.2 14 Jul 2021, 14:15 UTC

Insecure default variable initialization for the Intel BSSA DFT feature may allow a privileged user to potentially enable an escalation of privilege via local access.

CVE-2021-0143 intel vulnerability CVSS: 4.6 17 Jun 2021, 12:15 UTC

Improper permissions in the installer for the Intel(R) Brand Verification Tool before version 11.0.0.1225 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-0112 intel vulnerability CVSS: 4.4 09 Jun 2021, 20:15 UTC

Unquoted service path in the Intel Unite(R) Client for Windows before version 4.2.25031 may allow an authenticated user to potentially enable an escalation of privilege via local access.

CVE-2021-0108 intel vulnerability CVSS: 4.4 09 Jun 2021, 20:15 UTC

Uncontrolled search path in the Intel Unite(R) Client for Windows before version 4.2.25031 may allow an authenticated user to potentially enable an escalation of privilege via local access.

CVE-2021-0106 intel vulnerability CVSS: 4.6 09 Jun 2021, 20:15 UTC

Incorrect default permissions in the Intel(R) Optane(TM) DC Persistent Memory for Windows software versions before 2.00.00.3842 or 1.00.00.3515 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-0104 intel vulnerability CVSS: 4.4 09 Jun 2021, 20:15 UTC

Uncontrolled search path element in the installer for the Intel(R) Rapid Storage Technology software, before versions 17.9.0.34, 18.0.0.640 and 18.1.0.24, may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-0102 intel vulnerability CVSS: 4.6 09 Jun 2021, 20:15 UTC

Insecure inherited permissions in the Intel Unite(R) Client for Windows before version 4.2.25031 may allow an authenticated user to potentially enable an escalation of privilege via local access.

CVE-2021-0100 intel vulnerability CVSS: 4.6 09 Jun 2021, 20:15 UTC

Incorrect default permissions in the installer for the Intel(R) SSD Data Center Tool, versions downloaded before 12/31/2020, may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-0098 intel vulnerability CVSS: 4.6 09 Jun 2021, 20:15 UTC

Improper access control in the Intel Unite(R) Client for Windows before version 4.2.25031 may allow an authenticated user to potentially enable an escalation of privilege via local access.

CVE-2021-0094 intel vulnerability CVSS: 4.6 09 Jun 2021, 20:15 UTC

Improper link resolution before file access in Intel(R) DSA before version 20.11.50.9 may allow an authenticated user to potentially enable an escalation of privilege via local access.

CVE-2021-0090 intel vulnerability CVSS: 4.4 09 Jun 2021, 20:15 UTC

Uncontrolled search path element in Intel(R) DSA before version 20.11.50.9 may allow an authenticated user to potentially enable an escalation of privilege via local access.

CVE-2021-0089 intel vulnerability CVSS: 2.1 09 Jun 2021, 20:15 UTC

Observable response discrepancy in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

CVE-2021-0086 intel vulnerability CVSS: 2.1 09 Jun 2021, 20:15 UTC

Observable response discrepancy in floating-point operations for some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

CVE-2021-0077 intel vulnerability CVSS: 4.6 09 Jun 2021, 20:15 UTC

Insecure inherited permissions in the installer for the Intel(R) VTune(TM) Profiler before version 2021.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-0074 intel vulnerability CVSS: 4.6 09 Jun 2021, 20:15 UTC

Improper permissions in the installer for the Intel(R) Computing Improvement Program software before version 2.4.5982 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-0073 intel vulnerability CVSS: 4.6 09 Jun 2021, 20:15 UTC

Insufficient control flow management in Intel(R) DSA before version 20.11.50.9 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-0067 intel vulnerability CVSS: 4.6 09 Jun 2021, 20:15 UTC

 Improper access control in system firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2021-0058 intel vulnerability CVSS: 4.6 09 Jun 2021, 20:15 UTC

Incorrect default permissions in the Intel(R) NUC M15 Laptop Kit Driver Pack software before updated version 1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-0057 intel vulnerability CVSS: 4.4 09 Jun 2021, 20:15 UTC

Uncontrolled search path in the Intel(R) NUC M15 Laptop Kit Driver Pack software before updated version 1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-0056 intel vulnerability CVSS: 4.6 09 Jun 2021, 20:15 UTC

Insecure inherited permissions for the Intel(R) NUC M15 Laptop Kit Driver Pack software before updated version 1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-0055 intel vulnerability CVSS: 4.6 09 Jun 2021, 20:15 UTC

Insecure inherited permissions for some Intel(R) NUC 9 Extreme Laptop Kit LAN Drivers before version 10.42 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-0054 intel vulnerability CVSS: 4.6 09 Jun 2021, 20:15 UTC

Improper buffer restrictions in system firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2021-0052 intel vulnerability CVSS: 4.6 09 Jun 2021, 20:15 UTC

Incorrect default privileges in the Intel(R) Computing Improvement Program before version 2.4.6522 may allow an authenticated user to potentially enable an escalation of privilege via local access.

CVE-2021-0051 intel vulnerability CVSS: 2.1 09 Jun 2021, 20:15 UTC

Improper input validation in the Intel(R) SPS versions before SPS_E5_04.04.04.023.0, SPS_E5_04.04.03.228.0 or SPS_SoC-A_05.00.03.098.0 may allow a privileged user to potentially enable denial of service via local access.

CVE-2021-0001 intel vulnerability CVSS: 2.1 09 Jun 2021, 20:15 UTC

Observable timing discrepancy in Intel(R) IPP before version 2020 update 1 may allow authorized user to potentially enable information disclosure via local access.

CVE-2020-24489 intel vulnerability CVSS: 4.6 09 Jun 2021, 20:15 UTC

Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-24475 intel vulnerability CVSS: 2.1 09 Jun 2021, 20:15 UTC

Improper initialization in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.48.ce3e3bd2 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2020-24474 intel vulnerability CVSS: 5.2 09 Jun 2021, 20:15 UTC

Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.48.ce3e3bd2 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2020-24473 intel vulnerability CVSS: 4.6 09 Jun 2021, 20:15 UTC

Out of bounds write in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.48.ce3e3bd2 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-0105 intel vulnerability CVSS: 4.1 09 Jun 2021, 19:15 UTC

Insecure inherited permissions in some Intel(R) ProSet/Wireless WiFi drivers may allow an authenticated user to potentially enable information disclosure and denial of service via adjacent access.

CVE-2021-0095 intel vulnerability CVSS: 2.1 09 Jun 2021, 19:15 UTC

Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access.

CVE-2020-8704 intel vulnerability CVSS: 4.4 09 Jun 2021, 19:15 UTC

Race condition in a subsystem in the Intel(R) LMS versions before 2039.1.0.0 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-8703 intel vulnerability CVSS: 4.6 09 Jun 2021, 19:15 UTC

Improper buffer restrictions in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32 and 15.0.22 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-8702 intel vulnerability CVSS: 4.4 09 Jun 2021, 19:15 UTC

Uncontrolled search path element in the Intel(R) Processor Diagnostic Tool before version 4.1.5.37 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-8700 intel vulnerability CVSS: 4.6 09 Jun 2021, 19:15 UTC

Improper input validation in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-8670 intel vulnerability CVSS: 4.4 09 Jun 2021, 19:15 UTC

Race condition in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-24516 intel vulnerability CVSS: 4.6 09 Jun 2021, 19:15 UTC

Modification of assumed-immutable data in subsystem in Intel(R) CSME versions before 13.0.47, 13.30.17, 14.1.53, 14.5.32, 15.0.22 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVE-2020-24515 intel vulnerability CVSS: 4.6 09 Jun 2021, 19:15 UTC

Protection mechanism failure in some Intel(R) RealSense(TM) IDs may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVE-2020-24514 intel vulnerability CVSS: 4.6 09 Jun 2021, 19:15 UTC

Improper authentication in some Intel(R) RealSense(TM) IDs may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVE-2020-24513 intel vulnerability CVSS: 2.1 09 Jun 2021, 19:15 UTC

Domain-bypass transient execution vulnerability in some Intel Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2020-24512 intel vulnerability CVSS: 2.1 09 Jun 2021, 19:15 UTC

Observable timing discrepancy in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2020-24511 intel vulnerability CVSS: 2.1 09 Jun 2021, 19:15 UTC

Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2020-24509 intel vulnerability CVSS: 4.6 09 Jun 2021, 19:15 UTC

Insufficient control flow management in subsystem in Intel(R) SPS versions before SPS_E3_05.01.04.300.0, SPS_SoC-A_05.00.03.091.0, SPS_E5_04.04.04.023.0, or SPS_E5_04.04.03.263.0 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-24507 intel vulnerability CVSS: 2.1 09 Jun 2021, 19:15 UTC

Improper initialization in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32, 13.50.11 and 15.0.22 may allow a privileged user to potentially enable information disclosure via local access.

CVE-2020-24506 intel vulnerability CVSS: 2.1 09 Jun 2021, 19:15 UTC

Out of bound read in a subsystem in the Intel(R) CSME versions before 12.0.81, 13.0.47, 13.30.17, 14.1.53 and 14.5.32 may allow a privileged user to potentially enable information disclosure via local access.

CVE-2020-24486 intel vulnerability CVSS: 2.1 09 Jun 2021, 19:15 UTC

Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.

CVE-2020-12360 intel vulnerability CVSS: 4.6 09 Jun 2021, 19:15 UTC

Out of bounds read in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-12359 intel vulnerability CVSS: 4.6 09 Jun 2021, 19:15 UTC

Insufficient control flow management in the firmware for some Intel(R) Processors may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVE-2020-12358 intel vulnerability CVSS: 2.1 09 Jun 2021, 19:15 UTC

Out of bounds write in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable denial of service via local access.

CVE-2020-12357 intel vulnerability CVSS: 4.6 09 Jun 2021, 19:15 UTC

Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-12296 intel vulnerability CVSS: 2.1 09 Jun 2021, 19:15 UTC

Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.

CVE-2020-12295 intel vulnerability CVSS: 2.1 09 Jun 2021, 19:15 UTC

Improper input validation in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.

CVE-2020-12294 intel vulnerability CVSS: 2.1 09 Jun 2021, 19:15 UTC

Insufficient control flow management in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.

CVE-2020-12293 intel vulnerability CVSS: 2.1 09 Jun 2021, 19:15 UTC

Improper control of a resource through its lifetime in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.

CVE-2020-12292 intel vulnerability CVSS: 2.1 09 Jun 2021, 19:15 UTC

Improper conditions check in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.

CVE-2020-12291 intel vulnerability CVSS: 2.1 09 Jun 2021, 19:15 UTC

Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.

CVE-2020-12290 intel vulnerability CVSS: 2.1 09 Jun 2021, 19:15 UTC

Improper access control in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.

CVE-2020-12289 intel vulnerability CVSS: 2.1 09 Jun 2021, 19:15 UTC

Out-of-bounds write in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.

CVE-2020-12288 intel vulnerability CVSS: 2.1 09 Jun 2021, 19:15 UTC

Protection mechanism failure in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access.

CVE-2021-33833 intel vulnerability CVSS: 7.5 09 Jun 2021, 18:15 UTC

ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAME, RDATA, or RDLENGTH (for A or AAAA).

CVE-2021-26314 intel vulnerability CVSS: 2.1 09 Jun 2021, 12:15 UTC

Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause the use of incorrect data from FPVI and may result in data leakage.

CVE-2021-26313 intel vulnerability CVSS: 2.1 09 Jun 2021, 12:15 UTC

Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution of overwritten instructions, may cause an incorrect speculation and could result in data leakage.

CVE-2020-26558 intel vulnerability CVSS: 4.3 24 May 2021, 18:15 UTC

Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the authentication evidence of the initiating device, potentially permitting this attacker to complete authenticated pairing with the responding device using the correct Passkey for the pairing session. The attack methodology determines the Passkey value one bit at a time.

CVE-2020-26555 intel vulnerability CVSS: 4.8 24 May 2021, 18:15 UTC

Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing without knowledge of the PIN.

CVE-2020-26140 intel vulnerability CVSS: 3.3 11 May 2021, 20:15 UTC

An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network configuration.

CVE-2020-26139 intel vulnerability CVSS: 2.9 11 May 2021, 20:15 UTC

An issue was discovered in the kernel in NetBSD 7.1. An Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. This might be abused in projected Wi-Fi networks to launch denial-of-service attacks against connected clients and makes it easier to exploit other vulnerabilities in connected clients.

CVE-2020-24588 intel vulnerability CVSS: 2.9 11 May 2021, 20:15 UTC

The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that the A-MSDU flag in the plaintext QoS header field is authenticated. Against devices that support receiving non-SSP A-MSDU frames (which is mandatory as part of 802.11n), an adversary can abuse this to inject arbitrary network packets.

CVE-2020-24587 intel vulnerability CVSS: 1.8 11 May 2021, 20:15 UTC

The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that all fragments of a frame are encrypted under the same key. An adversary can abuse this to decrypt selected fragments when another device sends fragmented frames and the WEP, CCMP, or GCMP encryption key is periodically renewed.

CVE-2020-24586 intel vulnerability CVSS: 2.9 11 May 2021, 20:15 UTC

The 802.11 standard that underpins Wi-Fi Protected Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't require that received fragments be cleared from memory after (re)connecting to a network. Under the right circumstances, when another device sends fragmented frames encrypted using WEP, CCMP, or GCMP, this can be abused to inject arbitrary network packets and/or exfiltrate user data.

CVE-2020-12374 intel vulnerability CVSS: 4.6 19 Feb 2021, 16:15 UTC

Buffer overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.47 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-12365 intel vulnerability CVSS: 2.1 17 Feb 2021, 15:15 UTC

Untrusted pointer dereference in some Intel(R) Graphics Drivers before versions 15.33.51.5146, 15.45.32.5145, 15.36.39.5144 and 15.40.46.5143 may allow an authenticated user to potentially denial of service via local access.

CVE-2020-8765 intel vulnerability CVSS: 4.6 17 Feb 2021, 14:15 UTC

Incorrect default permissions in the installer for the Intel(R) RealSense(TM) DCM may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-8701 intel vulnerability CVSS: 4.6 17 Feb 2021, 14:15 UTC

Incorrect default permissions in installer for the Intel(R) SSD Toolbox versions before 2/9/2021 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-8678 intel vulnerability CVSS: 4.6 17 Feb 2021, 14:15 UTC

Improper access control for Intel(R) Graphics Drivers before version 15.45.33.5164 and 27.20.100.8280 may allow an authenticated user to potentially enable an escalation of privilege via local access.

CVE-2020-24505 intel vulnerability CVSS: 2.1 17 Feb 2021, 14:15 UTC

Insufficient input validation in the firmware for the Intel(R) 700-series of Ethernet Controllers before version 7.3 may allow a privileged user to potentially enable denial of service via local access.

CVE-2020-24504 intel vulnerability CVSS: 2.1 17 Feb 2021, 14:15 UTC

Uncontrolled resource consumption in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2020-24503 intel vulnerability CVSS: 2.1 17 Feb 2021, 14:15 UTC

Insufficient access control in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2020-24502 intel vulnerability CVSS: 2.1 17 Feb 2021, 14:15 UTC

Improper input validation in some Intel(R) Ethernet E810 Adapter drivers for Linux before version 1.0.4 and before version 1.4.29.0 for Windows*, may allow an authenticated user to potentially enable a denial of service via local access.

CVE-2020-24501 intel vulnerability CVSS: 3.3 17 Feb 2021, 14:15 UTC

Buffer overflow in the firmware for Intel(R) E810 Ethernet Controllers before version 1.4.1.13 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2020-24500 intel vulnerability CVSS: 2.1 17 Feb 2021, 14:15 UTC

Buffer overflow in the firmware for Intel(R) E810 Ethernet Controllers before version 1.4.1.13 may allow a privileged user to potentially enable a denial of service via local access.

CVE-2020-24498 intel vulnerability CVSS: 2.1 17 Feb 2021, 14:15 UTC

Buffer overflow in the firmware for Intel(R) E810 Ethernet Controllers before version 1.4.1.13 may allow a privileged user to potentially enable denial of service via local access.

CVE-2020-24497 intel vulnerability CVSS: 2.1 17 Feb 2021, 14:15 UTC

Insufficient Access Control in the firmware for Intel(R) E810 Ethernet Controllers before version 1.4.1.13 may allow a privileged user to potentially enable denial of service via local access.

CVE-2020-24496 intel vulnerability CVSS: 2.1 17 Feb 2021, 14:15 UTC

Insufficient input validation in the firmware for Intel(R) 722 Ethernet Controllers before version 1.4.3 may allow a privileged user to potentially enable denial of service via local access.

CVE-2020-24495 intel vulnerability CVSS: 2.1 17 Feb 2021, 14:15 UTC

Insufficient access control in the firmware for the Intel(R) 700-series of Ethernet Controllers before version 7.3 may allow a privileged user to potentially enable denial of service via local access.

CVE-2020-24494 intel vulnerability CVSS: 2.1 17 Feb 2021, 14:15 UTC

Insufficient access control in the firmware for the Intel(R) 722 Ethernet Controllers before version 1.4.3 may allow a privileged user to potentially enable denial of service via local access.

CVE-2020-24493 intel vulnerability CVSS: 2.1 17 Feb 2021, 14:15 UTC

Insufficient access control in the firmware for the Intel(R) 700-series of Ethernet Controllers before version 8.0 may allow a privileged user to potentially enable denial of service via local access.

CVE-2020-24492 intel vulnerability CVSS: 2.1 17 Feb 2021, 14:15 UTC

Insufficient access control in the firmware for the Intel(R) 722 Ethernet Controllers before version 1.5 may allow a privileged user to potentially enable a denial of service via local access.

CVE-2020-24491 intel vulnerability CVSS: 1.9 17 Feb 2021, 14:15 UTC

Debug message containing addresses of memory transactions in some Intel(R) 10th Generation Core Processors supporting SGX may allow a privileged user to potentially enable information disclosure via local access.

CVE-2020-24485 intel vulnerability CVSS: 4.4 17 Feb 2021, 14:15 UTC

Improper conditions check in the Intel(R) FPGA OPAE Driver for Linux before kernel version 4.17 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-24480 intel vulnerability CVSS: 2.1 17 Feb 2021, 14:15 UTC

Out-of-bounds write in the Intel(R) XTU before version 6.5.3.25 may allow a privileged user to potentially enable denial of service via local access.

CVE-2020-24462 intel vulnerability CVSS: 4.6 17 Feb 2021, 14:15 UTC

Out of bounds write in the Intel(R) Graphics Driver before version 15.33.53.5161, 15.36.40.5162, 15.40.47.5166, 15.45.33.5164 and 27.20.100.8336 may allow an authenticated user to potentially enable an escalation of privilege via local access.

CVE-2020-24458 intel vulnerability CVSS: 4.1 17 Feb 2021, 14:15 UTC

Incomplete cleanup in some Intel(R) PROSet/Wireless WiFi and Killer (TM) drivers before version 22.0 may allow a privileged user to potentially enable information disclosure and denial of service<b>&nbsp;</b>via adjacent access.

CVE-2020-24453 intel vulnerability CVSS: 4.6 17 Feb 2021, 14:15 UTC

Improper input validation in the Intel(R) EPID SDK before version 8, may allow an authenticated user to potentially enable an escalation of privilege via local access.

CVE-2020-24451 intel vulnerability CVSS: 4.4 17 Feb 2021, 14:15 UTC

Uncontrolled search path in the Intel(R) Optane(TM) DC Persistent Memory installer for Windows* before version 1.00.00.3506 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-24450 intel vulnerability CVSS: 4.6 17 Feb 2021, 14:15 UTC

Improper conditions check in some Intel(R) Graphics Drivers before versions 26.20.100.8141, 15.45.32.5145 and 15.40.46.5144 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-24448 intel vulnerability CVSS: 2.1 17 Feb 2021, 14:15 UTC

Uncaught exception in some Intel(R) Graphics Drivers before version 15.33.51.5146 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2020-12386 intel vulnerability CVSS: 2.1 17 Feb 2021, 14:15 UTC

Out-of-bounds write in some Intel(R) Graphics Drivers before version 15.36.39.5143 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2020-12385 intel vulnerability CVSS: 4.6 17 Feb 2021, 14:15 UTC

Improper input validation in some Intel(R) Graphics Drivers before version 26.20.100.8141 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-12384 intel vulnerability CVSS: 4.6 17 Feb 2021, 14:15 UTC

Improper access control in some Intel(R) Graphics Drivers before version 26.20.100.8476 may allow an authenticated user to potentially enable an escalation of privilege via local access.

CVE-2020-12380 intel vulnerability CVSS: 4.6 17 Feb 2021, 14:15 UTC

Out of bounds read in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.47 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-12377 intel vulnerability CVSS: 4.6 17 Feb 2021, 14:15 UTC

Insufficient input validation in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.47 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-12376 intel vulnerability CVSS: 2.1 17 Feb 2021, 14:15 UTC

Use of hard-coded key in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.47 may allow authenticated user to potentially enable information disclosure via local access.

CVE-2020-12375 intel vulnerability CVSS: 4.6 17 Feb 2021, 14:15 UTC

Heap overflow in the BMC firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.47 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-12373 intel vulnerability CVSS: 4.6 17 Feb 2021, 14:15 UTC

Expired pointer dereference in some Intel(R) Graphics Drivers before version 26.20.100.8141 may allow a privileged user to potentially enable a denial of service via local access.

CVE-2020-12372 intel vulnerability CVSS: 2.1 17 Feb 2021, 14:15 UTC

Unchecked return value in some Intel(R) Graphics Drivers before version 26.20.100.8141 may allow a privileged user to potentially enable a denial of service via local access.

CVE-2020-12371 intel vulnerability CVSS: 2.1 17 Feb 2021, 14:15 UTC

Divide by zero in some Intel(R) Graphics Drivers before version 26.20.100.8141 may allow a privileged user to potentially enable a denial of service via local access.

CVE-2020-12370 intel vulnerability CVSS: 2.1 17 Feb 2021, 14:15 UTC

Untrusted pointer dereference in some Intel(R) Graphics Drivers before version 26.20.100.8141 may allow a privileged user to potentially enable a denial of service via local access.

CVE-2020-12369 intel vulnerability CVSS: 4.6 17 Feb 2021, 14:15 UTC

Out of bound write in some Intel(R) Graphics Drivers before version 26.20.100.8336 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-12368 intel vulnerability CVSS: 4.6 17 Feb 2021, 14:15 UTC

Integer overflow in some Intel(R) Graphics Drivers before version 26.20.100.8141 may allow a privileged user to potentially enable an escalation of privilege via local access.

CVE-2020-12367 intel vulnerability CVSS: 4.6 17 Feb 2021, 14:15 UTC

Integer overflow in some Intel(R) Graphics Drivers before version 26.20.100.8476 may allow a privileged user to potentially enable an escalation of privilege via local access.

CVE-2020-12366 intel vulnerability CVSS: 4.6 17 Feb 2021, 14:15 UTC

Insufficient input validation in some Intel(R) Graphics Drivers before version 27.20.100.8587 may allow a privileged user to potentially enable an escalation of privilege via local access.

CVE-2020-12364 intel vulnerability CVSS: 2.1 17 Feb 2021, 14:15 UTC

Null pointer reference in some Intel(R) Graphics Drivers for Windows* before version 26.20.100.7212 and before version Linux kernel version 5.5 may allow a privileged user to potentially enable a denial of service via local access.

CVE-2020-12363 intel vulnerability CVSS: 2.1 17 Feb 2021, 14:15 UTC

Improper input validation in some Intel(R) Graphics Drivers for Windows* before version 26.20.100.7212 and before Linux kernel version 5.5 may allow a privileged user to potentially enable a denial of service via local access.

CVE-2020-12362 intel vulnerability CVSS: 4.6 17 Feb 2021, 14:15 UTC

Integer overflow in the firmware for some Intel(R) Graphics Drivers for Windows * before version 26.20.100.7212 and before Linux kernel version 5.5 may allow a privileged user to potentially enable an escalation of privilege via local access.

CVE-2020-12361 intel vulnerability CVSS: 2.1 17 Feb 2021, 14:15 UTC

Use after free in some Intel(R) Graphics Drivers before version 15.33.51.5146 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2020-12339 intel vulnerability CVSS: 6.5 17 Feb 2021, 14:15 UTC

Insufficient control flow management in the API for the Intel(R) Collaboration Suite for WebRTC before version 4.3.1 may allow an authenticated user to potentially enable escalation of privilege via network access.

CVE-2020-0544 intel vulnerability CVSS: 4.6 17 Feb 2021, 14:15 UTC

Insufficient control flow management in the kernel mode driver for some Intel(R) Graphics Drivers before version 15.36.39.5145 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-0525 intel vulnerability CVSS: 2.1 17 Feb 2021, 14:15 UTC

Improper access control in firmware for the Intel(R) Ethernet I210 Controller series of network adapters before version 3.30 may allow a privileged user to potentially enable denial of service via local access.

CVE-2020-0524 intel vulnerability CVSS: 2.1 17 Feb 2021, 14:15 UTC

Improper default permissions in the firmware for the Intel(R) Ethernet I210 Controller series of network adapters before version 3.30 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2020-0523 intel vulnerability CVSS: 2.1 17 Feb 2021, 14:15 UTC

Improper access control in the firmware for the Intel(R) Ethernet I210 Controller series of network adapters before version 3.30 may potentially allow a privileged user to enable a denial of service via local access.

CVE-2020-0522 intel vulnerability CVSS: 2.1 17 Feb 2021, 14:15 UTC

Improper initialization in the firmware for the Intel(R) Ethernet I210 Controller series of network adapters before version 3.30 may allow a privileged user to potentially enable denial of service via local access.

CVE-2020-0521 intel vulnerability CVSS: 4.6 17 Feb 2021, 14:15 UTC

Insufficient control flow management in some Intel(R) Graphics Drivers before version 15.45.32.5145 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-0518 intel vulnerability CVSS: 2.1 17 Feb 2021, 14:15 UTC

Improper access control in the Intel(R) HD Graphics Control Panel before version 15.40.46.5144 and 15.36.39.5143 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2021-26676 intel vulnerability CVSS: 3.3 09 Feb 2021, 16:15 UTC

gdhcp in ConnMan before 1.39 could be used by network-adjacent attackers to leak sensitive stack information, allowing further exploitation of bugs in gdhcp.

CVE-2021-26675 intel vulnerability CVSS: 5.8 09 Feb 2021, 16:15 UTC

A stack-based buffer overflow in dnsproxy in ConnMan before 1.39 could be used by network adjacent attackers to execute code.

CVE-2020-8672 intel vulnerability CVSS: 4.6 02 Feb 2021, 22:15 UTC

Out of bound read in BIOS firmware for 8th, 9th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 Series Processors may allow an unauthenticated user to potentially enable elevation of privilege or denial of service via local access.

CVE-2020-8734 intel vulnerability CVSS: 4.6 02 Feb 2021, 21:15 UTC

Improper input validation in the firmware for Intel(R) Server Board M10JNP2SB before version 7.210 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-0569 intel vulnerability CVSS: 2.7 23 Nov 2020, 17:15 UTC

Out of bounds write in Intel(R) PROSet/Wireless WiFi products on Windows 10 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2020-12338 intel vulnerability CVSS: 7.5 13 Nov 2020, 20:15 UTC

Insufficient control flow management in the Open WebRTC Toolkit before version 4.3.1 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVE-2020-12313 intel vulnerability CVSS: 5.8 13 Nov 2020, 20:15 UTC

Insufficient control flow management in some Intel(R) PROSet/Wireless WiFi products before version 21.110 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2020-0599 intel vulnerability CVSS: 4.6 13 Nov 2020, 20:15 UTC

Improper access control in the PMC for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-8669 intel vulnerability CVSS: 4.0 12 Nov 2020, 19:15 UTC

Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable information disclosure via network access.

CVE-2020-24525 intel vulnerability CVSS: 4.6 12 Nov 2020, 19:15 UTC

Insecure inherited permissions in firmware update tool for some Intel(R) NUCs may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-24460 intel vulnerability CVSS: 2.1 12 Nov 2020, 19:15 UTC

Incorrect default permissions in the Intel(R) DSA before version 20.8.30.6 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2020-24456 intel vulnerability CVSS: 4.6 12 Nov 2020, 19:15 UTC

Incorrect default permissions in the Intel(R) Board ID Tool version v.1.01 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-24454 intel vulnerability CVSS: 5.0 12 Nov 2020, 19:15 UTC

Improper Restriction of XML External Entity Reference in subsystem forIntel(R) Quartus(R) Prime Pro Edition before version 20.3 and Intel(R) Quartus(R) Prime Standard Edition before version 20.2 may allow unauthenticated user to potentially enable information disclosure via network access.

CVE-2020-12353 intel vulnerability CVSS: 4.0 12 Nov 2020, 19:15 UTC

Improper permissions in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable denial of service via network access.

CVE-2020-12350 intel vulnerability CVSS: 4.6 12 Nov 2020, 19:15 UTC

Improper access control in the Intel(R) XTU before version 6.5.1.360 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-12349 intel vulnerability CVSS: 4.0 12 Nov 2020, 19:15 UTC

Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable information disclosure via network access.

CVE-2020-12347 intel vulnerability CVSS: 6.5 12 Nov 2020, 19:15 UTC

Improper input validation in the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable escalation of privilege via network access.

CVE-2020-12346 intel vulnerability CVSS: 4.6 12 Nov 2020, 19:15 UTC

Improper permissions in the installer for the Intel(R) Battery Life Diagnostic Tool before version 1.0.7 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-12345 intel vulnerability CVSS: 4.6 12 Nov 2020, 19:15 UTC

Improper permissions in the installer for the Intel(R) Data Center Manager Console before version 3.6.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-12337 intel vulnerability CVSS: 4.6 12 Nov 2020, 19:15 UTC

Improper buffer restrictions in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-12336 intel vulnerability CVSS: 4.6 12 Nov 2020, 19:15 UTC

Insecure default variable initialization in firmware for some Intel(R) NUCs may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-12335 intel vulnerability CVSS: 4.6 12 Nov 2020, 19:15 UTC

Improper permissions in the installer for the Intel(R) Processor Identification Utility before version 6.4.0603 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-12334 intel vulnerability CVSS: 4.6 12 Nov 2020, 19:15 UTC

Improper permissions in the installer for the Intel(R) Advisor tools before version 2020 Update 2 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-12333 intel vulnerability CVSS: 4.6 12 Nov 2020, 19:15 UTC

Insufficiently protected credentials in the Intel(R) QAT for Linux before version 1.7.l.4.10.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-12330 intel vulnerability CVSS: 4.6 12 Nov 2020, 19:15 UTC

Improper permissions in the installer for the Intel(R) Falcon 8+ UAS AscTec Thermal Viewer, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-12329 intel vulnerability CVSS: 4.6 12 Nov 2020, 19:15 UTC

Uncontrolled search path in the Intel(R) VTune(TM) Profiler before version 2020 Update 1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-12328 intel vulnerability CVSS: 2.1 12 Nov 2020, 19:15 UTC

Protection mechanism failure in some Intel(R) Thunderbolt(TM) DCH drivers for Windows* before version 72 may allow a privileged user to potentially enable information disclosure via local access.

CVE-2020-12327 intel vulnerability CVSS: 2.1 12 Nov 2020, 19:15 UTC

Insecure default variable initialization in some Intel(R) Thunderbolt(TM) DCH drivers for Windows* before version 72 may allow a privileged user to potentially enable information disclosure via local access.

CVE-2020-12326 intel vulnerability CVSS: 2.1 12 Nov 2020, 19:15 UTC

Improper initialization in some Intel(R) Thunderbolt(TM) DCH drivers for Windows* before version 72 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2020-12325 intel vulnerability CVSS: 4.6 12 Nov 2020, 19:15 UTC

Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH drivers for Windows* before version 72 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-12324 intel vulnerability CVSS: 4.6 12 Nov 2020, 19:15 UTC

Protection mechanism failure in some Intel(R) Thunderbolt(TM) DCH drivers for Windows* before version 72 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-12320 intel vulnerability CVSS: 4.6 12 Nov 2020, 19:15 UTC

Uncontrolled search path in Intel(R) SCS Add-on for Microsoft* SCCM before version 2.1.10 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-12316 intel vulnerability CVSS: 2.1 12 Nov 2020, 19:15 UTC

Insufficiently protected credentials in the Intel(R) EMA before version 1.3.3 may allow an authorized user to potentially enable information disclosure via local access.

CVE-2020-12315 intel vulnerability CVSS: 7.5 12 Nov 2020, 19:15 UTC

Path traversal in the Intel(R) EMA before version 1.3.3 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVE-2020-0573 intel vulnerability CVSS: 2.1 12 Nov 2020, 19:15 UTC

Out of bounds read in the Intel CSI2 Host Controller driver may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2020-0572 intel vulnerability CVSS: 4.6 12 Nov 2020, 19:15 UTC

Improper input validation in the firmware for Intel(R) Server Board S2600ST and S2600WF families may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-8767 intel vulnerability CVSS: 2.1 12 Nov 2020, 18:15 UTC

Uncaught exception in the Intel(R) 50GbE IP Core for Intel(R) Quartus Prime before version 20.2 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2020-8766 intel vulnerability CVSS: 3.3 12 Nov 2020, 18:15 UTC

Improper conditions check in the Intel(R) SGX DCAP software before version 1.6 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2020-8764 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Improper access control in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-8761 intel vulnerability CVSS: 2.1 12 Nov 2020, 18:15 UTC

Inadequate encryption strength in subsystem for Intel(R) CSME versions before 13.0.40 and 13.30.10 may allow an unauthenticated user to potentially enable information disclosure via physical access.

CVE-2020-8760 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Integer overflow in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 14.0.45 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-8757 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Out-of-bounds read in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-8756 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Improper input validation in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-8755 intel vulnerability CVSS: 4.4 12 Nov 2020, 18:15 UTC

Race condition in subsystem for Intel(R) CSME versions before 12.0.70 and 14.0.45, Intel(R) SPS versions before E5_04.01.04.400 and E3_05.01.04.200 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVE-2020-8754 intel vulnerability CVSS: 5.0 12 Nov 2020, 18:15 UTC

Out-of-bounds read in subsystem for Intel(R) AMT, Intel(R) ISM versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable information disclosure via network access.

CVE-2020-8753 intel vulnerability CVSS: 5.0 12 Nov 2020, 18:15 UTC

Out-of-bounds read in DHCP subsystem for Intel(R) AMT, Intel(R) ISM versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable information disclosure via network access.

CVE-2020-8752 intel vulnerability CVSS: 7.5 12 Nov 2020, 18:15 UTC

Out-of-bounds write in IPv6 subsystem for Intel(R) AMT, Intel(R) ISM versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 14.0.45 may allow an unauthenticated user to potentially enable escalation of privileges via network access.

CVE-2020-8751 intel vulnerability CVSS: 2.1 12 Nov 2020, 18:15 UTC

Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, Intel(R) TXE versions before 3.1.80 may allow an unauthenticated user to potentially enable information disclosure via physical access.

CVE-2020-8750 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Use after free in Kernel Mode Driver for Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-8749 intel vulnerability CVSS: 5.8 12 Nov 2020, 18:15 UTC

Out-of-bounds read in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2020-8747 intel vulnerability CVSS: 6.4 12 Nov 2020, 18:15 UTC

Out-of-bounds read in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable information disclosure and/or denial of service via network access.

CVE-2020-8746 intel vulnerability CVSS: 3.3 12 Nov 2020, 18:15 UTC

Integer overflow in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2020-8745 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Insufficient control flow management in subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25 , Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVE-2020-8744 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Improper initialization in subsystem for Intel(R) CSME versions before12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 4.0.30 Intel(R) SPS versions before E3_05.01.04.200 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-8740 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Out of bounds write in Intel BIOS platform sample code for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-8739 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Use of potentially dangerous function in Intel BIOS platform sample code for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-8738 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Improper conditions check in Intel BIOS platform sample code for some Intel(R) Processors before may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-8737 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Improper buffer restrictions in the Intel(R) Stratix(R) 10 FPGA firmware provided with the Intel(R) Quartus(R) Prime Pro software before version 20.1 may allow an unauthenticated user to potentially enable escalation of privilege and/or information disclosure via physical access.

CVE-2020-8705 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Insecure default initialization of resource in Intel(R) Boot Guard in Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 3.1.80 and 4.0.30, Intel(R) SPS versions before E5_04.01.04.400, E3_04.01.04.200, SoC-X_04.00.04.200 and SoC-A_04.00.04.300 may allow an unauthenticated user to potentially enable escalation of privileges via physical access.

CVE-2020-8698 intel vulnerability CVSS: 2.1 12 Nov 2020, 18:15 UTC

Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2020-8696 intel vulnerability CVSS: 2.1 12 Nov 2020, 18:15 UTC

Improper removal of sensitive information before storage or transfer in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2020-8695 intel vulnerability CVSS: 2.1 12 Nov 2020, 18:15 UTC

Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.

CVE-2020-8694 intel vulnerability CVSS: 2.1 12 Nov 2020, 18:15 UTC

Insufficient access control in the Linux kernel driver for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2020-8677 intel vulnerability CVSS: 2.1 12 Nov 2020, 18:15 UTC

Improper access control in the Intel(R) Visual Compute Accelerator 2, all versions, may allow a privileged user to potentially enable denial of service via local access.

CVE-2020-8676 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Improper access control in the Intel(R) Visual Compute Accelerator 2, all versions, may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-12356 intel vulnerability CVSS: 2.1 12 Nov 2020, 18:15 UTC

Out-of-bounds read in subsystem in Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow a privileged user to potentially enable information disclosure via local access.

CVE-2020-12355 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Authentication bypass by capture-replay in RPMB protocol message authentication subsystem in Intel(R) TXE versions before 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVE-2020-12354 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Incorrect default permissions in Windows(R) installer in Intel(R) AMT SDK versions before 14.0.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-12322 intel vulnerability CVSS: 3.3 12 Nov 2020, 18:15 UTC

Improper input validation in some Intel(R) Wireless Bluetooth(R) products before version 21.110 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2020-12321 intel vulnerability CVSS: 5.8 12 Nov 2020, 18:15 UTC

Improper buffer restriction in some Intel(R) Wireless Bluetooth(R) products before version 21.110 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2020-12319 intel vulnerability CVSS: 3.3 12 Nov 2020, 18:15 UTC

Insufficient control flow management in some Intel(R) PROSet/Wireless WiFi products before version 21.110 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2020-12318 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Protection mechanism failure in some Intel(R) PROSet/Wireless WiFi products before version 21.110 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-12317 intel vulnerability CVSS: 3.3 12 Nov 2020, 18:15 UTC

Improper buffer restriction in some Intel(R) PROSet/Wireless WiFi products before version 21.110 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2020-12314 intel vulnerability CVSS: 3.3 12 Nov 2020, 18:15 UTC

Improper input validation in some Intel(R) PROSet/Wireless WiFi products before version 21.110 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2020-12312 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Improper buffer restrictions in the Intel(R) Stratix(R) 10 FPGA firmware provided with the Intel(R) Quartus(R) Prime Pro software before version 20.2 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVE-2020-12311 intel vulnerability CVSS: 2.1 12 Nov 2020, 18:15 UTC

Insufficient control flow managementin firmware in some Intel(R) Client SSDs and some Intel(R) Data Center SSDs may allow an unauthenticated user to potentially enable information disclosure via physical access.

CVE-2020-12310 intel vulnerability CVSS: 2.1 12 Nov 2020, 18:15 UTC

Insufficient control flow managementin firmware in some Intel(R) Client SSDs and some Intel(R) Data Center SSDs may allow an unauthenticated user to potentially enable information disclosure via physical access.

CVE-2020-12309 intel vulnerability CVSS: 2.1 12 Nov 2020, 18:15 UTC

Insufficiently protected credentialsin subsystem in some Intel(R) Client SSDs and some Intel(R) Data Center SSDs may allow an unauthenticated user to potentially enable information disclosure via physical access.

CVE-2020-12308 intel vulnerability CVSS: 4.0 12 Nov 2020, 18:15 UTC

Improper access control for the Intel(R) Computing Improvement Program before version 2.4.5982 may allow an unprivileged user to potentially enable information disclosure via network access.

CVE-2020-12307 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Improper permissions in some Intel(R) High Definition Audio drivers before version 9.21.00.4561 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-12306 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Incorrect default permissions in the Intel(R) RealSense(TM) D400 Series Dynamic Calibration Tool before version 2.11, may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-12304 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Improper access control in Installer for Intel(R) DAL SDK before version 2.1 for Windows may allow an authenticated user to potentially enable escalation of privileges via local access.

CVE-2020-12303 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Use after free in DAL subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE 3.1.80, 4.0.30 may allow an authenticated user to potentially enable escalation of privileges via local access.

CVE-2020-12297 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Improper access control in Installer for Intel(R) CSME Driver for Windows versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel TXE 3.1.80, 4.0.30 may allow an authenticated user to potentially enable escalation of privileges via local access.

CVE-2020-0593 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Improper buffer restrictions in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-0592 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Out of bounds write in BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege and/or denial of service via local access.

CVE-2020-0591 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Improper buffer restrictions in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-0590 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Improper input validation in BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-0588 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Improper conditions check in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-0587 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Improper conditions check in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-0584 intel vulnerability CVSS: 2.1 12 Nov 2020, 18:15 UTC

Buffer overflow in firmware for Intel(R) SSD DC P4800X and P4801X Series, Intel(R) Optane(TM) SSD 900P and 905P Series may allow an unauthenticated user to potentially enable a denial of service via local access.

CVE-2020-0575 intel vulnerability CVSS: 2.1 12 Nov 2020, 18:15 UTC

Improper buffer restrictions in the Intel(R) Unite Client for Windows* before version 4.2.13064 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2019-11121 intel vulnerability CVSS: 4.6 12 Nov 2020, 18:15 UTC

Improper file permissions in the installer for the Intel(R) Media SDK for Windows before version 2019 R1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-11616 intel vulnerability CVSS: 5.0 29 Oct 2020, 04:15 UTC

NVIDIA DGX servers, all BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which the Pseudo-Random Number Generator (PRNG) algorithm used in the JSOL package that implements the IPMI protocol is not cryptographically strong, which may lead to information disclosure.

CVE-2020-11615 intel vulnerability CVSS: 5.0 29 Oct 2020, 04:15 UTC

NVIDIA DGX servers, all BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which it uses a hard-coded RC4 cipher key, which may lead to information disclosure.

CVE-2020-11489 intel vulnerability CVSS: 5.0 29 Oct 2020, 04:15 UTC

NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contain a vulnerability in the AMI BMC firmware in which default SNMP community strings are used, which may lead to information disclosure.

CVE-2020-11488 intel vulnerability CVSS: 4.6 29 Oct 2020, 04:15 UTC

NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contains a vulnerability in the AMI BMC firmware in which software does not validate the RSA 1024 public key used to verify the firmware signature, which may lead to information disclosure or code execution.

CVE-2020-11487 intel vulnerability CVSS: 5.0 29 Oct 2020, 04:15 UTC

NVIDIA DGX servers, DGX-1 with BMC firmware versions prior to 3.38.30. DGX-2 with BMC firmware versions prior to 1.06.06 and all DGX A100 Servers with all BMC firmware versions, contains a vulnerability in the AMI BMC firmware in which the use of a hard-coded RSA 1024 key with weak ciphers may lead to information disclosure.

CVE-2020-11486 intel vulnerability CVSS: 7.5 29 Oct 2020, 04:15 UTC

NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which software allows an attacker to upload or transfer files that can be automatically processed within the product's environment, which may lead to remote code execution.

CVE-2020-11485 intel vulnerability CVSS: 6.8 29 Oct 2020, 04:15 UTC

NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contains a Cross-Site Request Forgery (CSRF) vulnerability in the AMI BMC firmware in which the web application does not sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request, which can lead to information disclosure or code execution.

CVE-2020-11484 intel vulnerability CVSS: 4.0 29 Oct 2020, 04:15 UTC

NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contains a vulnerability in the AMI BMC firmware in which an attacker with administrative privileges can obtain the hash of the BMC/IPMI user password, which may lead to information disclosure.

CVE-2020-11483 intel vulnerability CVSS: 7.5 29 Oct 2020, 04:15 UTC

NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contains a vulnerability in the AMI BMC firmware in which the firmware includes hard-coded credentials, which may lead to elevation of privileges or information disclosure.

CVE-2020-8671 intel vulnerability CVSS: 2.1 05 Oct 2020, 14:15 UTC

Insufficient control flow management in BIOS firmware 8th, 9th Generation Intel(R) Core(TM) Processors and Intel(R) Celeron(R) Processor 4000 Series may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2020-12302 intel vulnerability CVSS: 4.6 05 Oct 2020, 14:15 UTC

Improper permissions in the Intel(R) Driver & Support Assistant before version 20.7.26.7 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-0571 intel vulnerability CVSS: 2.1 05 Oct 2020, 14:15 UTC

Improper conditions check in BIOS firmware for 8th Generation Intel(R) Core(TM) Processors and Intel(R) Pentium(R) Silver Processor Series may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2019-14558 intel vulnerability CVSS: 2.7 05 Oct 2020, 14:15 UTC

Insufficient control flow management in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Series Processors may allow an authenticated user to potentially enable denial of service via adjacent access.

CVE-2019-14557 intel vulnerability CVSS: 5.2 05 Oct 2020, 14:15 UTC

Buffer overflow in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Series Processors may allow an authenticated user to potentially enable elevation of privilege or denial of service via adjacent access.

CVE-2019-14556 intel vulnerability CVSS: 2.1 05 Oct 2020, 14:15 UTC

Improper initialization in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Series Processors may allow a privileged user to potentially enable denial of service via local access.

CVE-2020-24457 intel vulnerability CVSS: 4.6 14 Sep 2020, 19:15 UTC

Logic error in BIOS firmware for 8th, 9th and 10th Generation Intel(R) Core(TM) Processors may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.

CVE-2020-8758 intel vulnerability CVSS: 7.5 10 Sep 2020, 15:16 UTC

Improper buffer restrictions in network subsystem in provisioned Intel(R) AMT and Intel(R) ISM versions before 11.8.79, 11.12.79, 11.22.79, 12.0.68 and 14.0.39 may allow an unauthenticated user to potentially enable escalation of privilege via network access. On un-provisioned systems, an authenticated user may potentially enable escalation of privilege via local access.

CVE-2020-8720 intel vulnerability CVSS: 2.1 13 Aug 2020, 04:15 UTC

Buffer overflow in a subsystem for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow a privileged user to potentially enable denial of service via local access.

CVE-2020-8689 intel vulnerability CVSS: 3.3 13 Aug 2020, 04:15 UTC

Improper buffer restrictions in the Intel(R) Wireless for Open Source before version 1.5 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2020-8688 intel vulnerability CVSS: 5.0 13 Aug 2020, 04:15 UTC

Improper input validation in the Intel(R) RAID Web Console 3 for Windows* may allow an unauthenticated user to potentially enable denial of service via network access.

CVE-2020-8687 intel vulnerability CVSS: 4.6 13 Aug 2020, 04:15 UTC

Uncontrolled search path in the installer for Intel(R) RSTe Software RAID Driver for the Intel(R) Server Board M10JNP2SB before version 4.7.0.1119 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-8685 intel vulnerability CVSS: 2.1 13 Aug 2020, 04:15 UTC

Improper authentication in subsystem for Intel (R) LED Manager for NUC before version 1.2.3 may allow privileged user to potentially enable denial of service via local access.

CVE-2020-8684 intel vulnerability CVSS: 4.6 13 Aug 2020, 04:15 UTC

Improper access control in firmware for Intel(R) PAC with Arria(R) 10 GX FPGA before Intel Acceleration Stack version 1.2.1 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-8680 intel vulnerability CVSS: 4.4 13 Aug 2020, 04:15 UTC

Race condition in some Intel(R) Graphics Drivers before version 15.40.45.5126 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-8679 intel vulnerability CVSS: 2.1 13 Aug 2020, 04:15 UTC

Out-of-bounds write in Kernel Mode Driver for some Intel(R) Graphics Drivers before version 26.20.100.7755 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2020-12301 intel vulnerability CVSS: 4.6 13 Aug 2020, 04:15 UTC

Improper initialization in BIOS firmware for Intel(R) Server Board Families S2600ST, S2600BP and S2600WF may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-12300 intel vulnerability CVSS: 4.6 13 Aug 2020, 04:15 UTC

Uninitialized pointer in BIOS firmware for Intel(R) Server Board Families S2600CW, S2600KP, S2600TP, and S2600WT may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-12299 intel vulnerability CVSS: 4.6 13 Aug 2020, 04:15 UTC

Improper input validation in BIOS firmware for Intel(R) Server Board Families S2600ST, S2600BP and S2600WF may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-0559 intel vulnerability CVSS: 4.6 13 Aug 2020, 04:15 UTC

Insecure inherited permissions in some Intel(R) PROSet/Wireless WiFi products on Windows* 7 and 8.1 before version 21.40.5.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-0555 intel vulnerability CVSS: 4.6 13 Aug 2020, 04:15 UTC

Improper input validation for some Intel(R) Wireless Bluetooth(R) products may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-0554 intel vulnerability CVSS: 3.7 13 Aug 2020, 04:15 UTC

Race condition in software installer for some Intel(R) Wireless Bluetooth(R) products on Windows* 7, 8.1 and 10 may allow an unprivileged user to potentially enable escalation of privilege via local access.

CVE-2020-0553 intel vulnerability CVSS: 2.1 13 Aug 2020, 04:15 UTC

Out-of-bounds read in kernel mode driver for some Intel(R) Wireless Bluetooth(R) products on Windows* 10, may allow a privileged user to potentially enable information disclosure via local access.

CVE-2020-0510 intel vulnerability CVSS: 4.6 13 Aug 2020, 04:15 UTC

Out of bounds read in some Intel(R) Graphics Drivers before versions 15.45.31.5127 and 15.40.45.5126 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-14620 intel vulnerability CVSS: 3.3 13 Aug 2020, 04:15 UTC

Insufficient control flow management for some Intel(R) Wireless Bluetooth(R) products may allow an unprivileged user to potentially enable denial of service via adjacent access.

CVE-2020-8763 intel vulnerability CVSS: 4.6 13 Aug 2020, 03:15 UTC

Improper permissions in the installer for the Intel(R) RealSense(TM) D400 Series UWP driver for Windows* 10 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-8759 intel vulnerability CVSS: 4.6 13 Aug 2020, 03:15 UTC

Improper access control in the installer for Intel(R) SSD DCT versions before 3.0.23 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-8743 intel vulnerability CVSS: 4.6 13 Aug 2020, 03:15 UTC

Improper permissions in the installer for the Intel(R) Mailbox Interface driver, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-8742 intel vulnerability CVSS: 4.6 13 Aug 2020, 03:15 UTC

Improper input validation in the firmware for Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-8736 intel vulnerability CVSS: 4.6 13 Aug 2020, 03:15 UTC

Improper access control in subsystem for the Intel(R) Computing Improvement Program before version 2.4.5718 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-8733 intel vulnerability CVSS: 4.6 13 Aug 2020, 03:15 UTC

Improper buffer restrictions in the firmware for Intel(R) Server Board M10JNP2SB before version 7.210 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-8732 intel vulnerability CVSS: 5.8 13 Aug 2020, 03:15 UTC

Heap-based buffer overflow in the firmware for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2020-8731 intel vulnerability CVSS: 4.6 13 Aug 2020, 03:15 UTC

Incorrect execution-assigned permissions in the file system for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-8730 intel vulnerability CVSS: 4.6 13 Aug 2020, 03:15 UTC

Heap-based overflow for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-8729 intel vulnerability CVSS: 4.6 13 Aug 2020, 03:15 UTC

Buffer copy without checking size of input for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-8723 intel vulnerability CVSS: 5.4 13 Aug 2020, 03:15 UTC

Cross-site scripting for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2020-8722 intel vulnerability CVSS: 4.6 13 Aug 2020, 03:15 UTC

Buffer overflow in a subsystem for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-8721 intel vulnerability CVSS: 4.6 13 Aug 2020, 03:15 UTC

Improper input validation for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-8719 intel vulnerability CVSS: 4.6 13 Aug 2020, 03:15 UTC

Buffer overflow in subsystem for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-8718 intel vulnerability CVSS: 4.6 13 Aug 2020, 03:15 UTC

Buffer overflow in a subsystem for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-8717 intel vulnerability CVSS: 2.1 13 Aug 2020, 03:15 UTC

Improper input validation in a subsystem for some Intel Server Boards, Server Systems and Compute Modules before version 1.59 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2020-8716 intel vulnerability CVSS: 2.1 13 Aug 2020, 03:15 UTC

Improper access control for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2020-8715 intel vulnerability CVSS: 2.1 13 Aug 2020, 03:15 UTC

Invalid pointer for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to potentially enable denial of service via local access.

CVE-2020-8714 intel vulnerability CVSS: 4.6 13 Aug 2020, 03:15 UTC

Improper authentication for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-8713 intel vulnerability CVSS: 5.8 13 Aug 2020, 03:15 UTC

Improper authentication for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2020-8712 intel vulnerability CVSS: 4.6 13 Aug 2020, 03:15 UTC

Buffer overflow in a verification process for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.45 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-8711 intel vulnerability CVSS: 4.6 13 Aug 2020, 03:15 UTC

Improper access control in the bootloader for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.45 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-8710 intel vulnerability CVSS: 4.6 13 Aug 2020, 03:15 UTC

Buffer overflow in the bootloader for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.45 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-8709 intel vulnerability CVSS: 5.8 13 Aug 2020, 03:15 UTC

Improper authentication in socket services for some Intel(R) Server Boards, Server Systems and Compute Modules before version 2.45 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2020-8708 intel vulnerability CVSS: 5.8 13 Aug 2020, 03:15 UTC

Improper authentication for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2020-8707 intel vulnerability CVSS: 5.8 13 Aug 2020, 03:15 UTC

Buffer overflow in daemon for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2020-8706 intel vulnerability CVSS: 5.8 13 Aug 2020, 03:15 UTC

Buffer overflow in a daemon for some Intel(R) Server Boards, Server Systems and Compute Modules before version 1.59 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2020-12287 intel vulnerability CVSS: 4.6 13 Aug 2020, 03:15 UTC

Incorrect permissions in the Intel(R) Distribution of OpenVINO(TM) Toolkit before version 2020.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-14630 intel vulnerability CVSS: 2.1 13 Aug 2020, 03:15 UTC

Reliance on untrusted inputs in a security decision in some Intel(R) Thunderbolt(TM) controllers may allow unauthenticated user to potentially enable information disclosure via physical access.

CVE-2020-17497 intel vulnerability CVSS: 4.8 12 Aug 2020, 16:15 UTC

eapol.c in iNet wireless daemon (IWD) through 1.8 allows attackers to trigger a PTK reinstallation by retransmitting EAPOL Msg4/4.

CVE-2020-8674 intel vulnerability CVSS: 5.0 15 Jun 2020, 14:15 UTC

Out-of-bounds read in DHCPv6 subsystem in Intel(R) AMT and Intel(R)ISM versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64 and 14.0.33 may allow an unauthenticated user to potentially enable information disclosure via network access.

CVE-2020-0597 intel vulnerability CVSS: 5.0 15 Jun 2020, 14:15 UTC

Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 14.0.33 may allow an unauthenticated user to potentially enable denial of service via network access.

CVE-2020-0596 intel vulnerability CVSS: 5.0 15 Jun 2020, 14:15 UTC

Improper input validation in DHCPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable information disclosure via network access.

CVE-2020-0595 intel vulnerability CVSS: 7.5 15 Jun 2020, 14:15 UTC

Use after free in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVE-2020-0594 intel vulnerability CVSS: 7.5 15 Jun 2020, 14:15 UTC

Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVE-2020-0586 intel vulnerability CVSS: 4.6 15 Jun 2020, 14:15 UTC

Improper initialization in subsystem for Intel(R) SPS versions before SPS_E3_04.01.04.109.0 and SPS_E3_04.08.04.070.0 may allow an authenticated user to potentially enable escalation of privilege and/or denial of service via local access.

CVE-2020-0566 intel vulnerability CVSS: 4.6 15 Jun 2020, 14:15 UTC

Improper Access Control in subsystem for Intel(R) TXE versions before 3.175 and 4.0.25 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVE-2020-0545 intel vulnerability CVSS: 2.1 15 Jun 2020, 14:15 UTC

Integer overflow in subsystem for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77 and Intel(R) TXE versions before 3.1.75, 4.0.25 and Intel(R) Server Platform Services (SPS) versions before SPS_E5_04.01.04.380.0, SPS_SoC-X_04.00.04.128.0, SPS_SoC-A_04.00.04.211.0, SPS_E3_04.01.04.109.0, SPS_E3_04.08.04.070.0 may allow a privileged user to potentially enable denial of service via local access.

CVE-2020-0543 intel vulnerability CVSS: 2.1 15 Jun 2020, 14:15 UTC

Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2020-0542 intel vulnerability CVSS: 4.6 15 Jun 2020, 14:15 UTC

Improper buffer restrictions in subsystem for Intel(R) CSME versions before 12.0.64, 13.0.32, 14.0.33 and 14.5.12 may allow an authenticated user to potentially enable escalation of privilege, information disclosure or denial of service via local access.

CVE-2020-0541 intel vulnerability CVSS: 4.6 15 Jun 2020, 14:15 UTC

Out-of-bounds write in subsystem for Intel(R) CSME versions before 12.0.64, 13.0.32, 14.0.33 and 14.5.12 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2020-0540 intel vulnerability CVSS: 5.0 15 Jun 2020, 14:15 UTC

Insufficiently protected credentials in Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable information disclosure via network access.

CVE-2020-0539 intel vulnerability CVSS: 2.1 15 Jun 2020, 14:15 UTC

Path traversal in subsystem for Intel(R) DAL software for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64, 13.0.32, 14.0.33 and Intel(R) TXE versions before 3.1.75, 4.0.25 may allow an unprivileged user to potentially enable denial of service via local access.

CVE-2020-0538 intel vulnerability CVSS: 5.0 15 Jun 2020, 14:15 UTC

Improper input validation in subsystem for Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable denial of service via network access.

CVE-2020-0537 intel vulnerability CVSS: 4.0 15 Jun 2020, 14:15 UTC

Improper input validation in subsystem for Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow a privileged user to potentially enable denial of service via network access.

CVE-2020-0536 intel vulnerability CVSS: 5.0 15 Jun 2020, 14:15 UTC

Improper input validation in the DAL subsystem for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64, 13.0.32,14.0.33 and Intel(R) TXE versions before 3.1.75 and 4.0.25 may allow an unauthenticated user to potentially enable information disclosure via network access.

CVE-2020-0535 intel vulnerability CVSS: 5.0 15 Jun 2020, 14:15 UTC

Improper input validation in Intel(R) AMT versions before 11.8.76, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable information disclosure via network access.

CVE-2020-0534 intel vulnerability CVSS: 5.0 15 Jun 2020, 14:15 UTC

Improper input validation in the DAL subsystem for Intel(R) CSME versions before 12.0.64, 13.0.32, 14.0.33 and 14.5.12 may allow an unauthenticated user to potentially enable denial of service via network access.

CVE-2020-0533 intel vulnerability CVSS: 4.6 15 Jun 2020, 14:15 UTC

Reversible one-way hash in Intel(R) CSME versions before 11.8.76, 11.12.77 and 11.22.77 may allow a privileged user to potentially enable escalation of privilege, denial of service or information disclosure via local access.

CVE-2020-0532 intel vulnerability CVSS: 4.8 15 Jun 2020, 14:15 UTC

Improper input validation in subsystem for Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable denial of service or information disclosure via adjacent access.

CVE-2020-0531 intel vulnerability CVSS: 4.0 15 Jun 2020, 14:15 UTC

Improper input validation in Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an authenticated user to potentially enable information disclosure via network access.

CVE-2020-0529 intel vulnerability CVSS: 4.6 15 Jun 2020, 14:15 UTC

Improper initialization in BIOS firmware for 8th, 9th and 10th Generation Intel(R) Core(TM) Processor families may allow an unauthenticated user to potentially enable escalation of privilege via local access.

CVE-2020-0528 intel vulnerability CVSS: 4.6 15 Jun 2020, 14:15 UTC

Improper buffer restrictions in BIOS firmware for 7th, 8th, 9th and 10th Generation Intel(R) Core(TM) Processor families may allow an authenticated user to potentially enable escalation of privilege and/or denial of service via local access.

CVE-2020-0527 intel vulnerability CVSS: 2.1 15 Jun 2020, 14:15 UTC

Insufficient control flow management in firmware for some Intel(R) Data Center SSDs may allow a privileged user to potentially enable information disclosure via local access.

CVE-2020-0110 intel vulnerability CVSS: 4.6 14 May 2020, 21:15 UTC

In psi_write of psi.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-148159562References: Upstream kernel

CVE-2020-0600 intel vulnerability CVSS: 4.6 15 Apr 2020, 17:15 UTC

Improper buffer restrictions in firmware for some Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-0598 intel vulnerability CVSS: 4.4 15 Apr 2020, 17:15 UTC

Uncontrolled search path in the installer for the Intel(R) Binary Configuration Tool for Windows, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-0578 intel vulnerability CVSS: 5.8 15 Apr 2020, 17:15 UTC

Improper conditions check for Intel(R) Modular Server MFS2600KISPP Compute Module may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2020-0577 intel vulnerability CVSS: 5.8 15 Apr 2020, 17:15 UTC

Insufficient control flow for Intel(R) Modular Server MFS2600KISPP Compute Module may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2020-0576 intel vulnerability CVSS: 3.3 15 Apr 2020, 17:15 UTC

Buffer overflow in Intel(R) Modular Server MFS2600KISPP Compute Module may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2020-0568 intel vulnerability CVSS: 1.9 15 Apr 2020, 17:15 UTC

Race condition in the Intel(R) Driver and Support Assistant before version 20.1.5 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2020-0558 intel vulnerability CVSS: 3.3 15 Apr 2020, 17:15 UTC

Improper buffer restrictions in kernel mode driver for Intel(R) PROSet/Wireless WiFi products before version 21.70 on Windows 10 may allow an unprivileged user to potentially enable denial of service via adjacent access.

CVE-2020-0557 intel vulnerability CVSS: 4.6 15 Apr 2020, 17:15 UTC

Insecure inherited permissions in Intel(R) PROSet/Wireless WiFi products before version 21.70 on Windows 10 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-0547 intel vulnerability CVSS: 4.6 15 Apr 2020, 17:15 UTC

Incorrect default permissions in the installer for Intel(R) Data Migration Software versions 3.3 and earlier may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-0583 intel vulnerability CVSS: 4.6 12 Mar 2020, 22:15 UTC

Improper access control in the subsystem for Intel(R) Smart Sound Technology may allow an authenticated user to potentially enable escalation of privilege via local access. This affects Intel® Smart Sound Technology before versions: 10th Generation Intel® Core™ i7 Processors, version 3431 and 8th Generation Intel® Core™ Processors, version 3349.

CVE-2020-0551 intel vulnerability CVSS: 1.9 12 Mar 2020, 22:15 UTC

Load value injection in some Intel(R) Processors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. The list of affected products is provided in intel-sa-00334: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00334.html

CVE-2020-0550 intel vulnerability CVSS: 1.9 12 Mar 2020, 22:15 UTC

Improper data forwarding in some data cache for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. The list of affected products is provided in intel-sa-00330: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00330.html

CVE-2020-0574 intel vulnerability CVSS: 3.6 12 Mar 2020, 21:15 UTC

Improper configuration in block design for Intel(R) MAX(R) 10 FPGA all versions may allow an authenticated user to potentially enable escalation of privilege and information disclosure via physical access.

CVE-2020-0567 intel vulnerability CVSS: 2.1 12 Mar 2020, 21:15 UTC

Improper input validation in Intel(R) Graphics Drivers before version 26.20.100.7212 may allow an authenticated user to enable denial of service via local access.

CVE-2020-0565 intel vulnerability CVSS: 4.6 12 Mar 2020, 21:15 UTC

Uncontrolled search path in Intel(R) Graphics Drivers before version 26.20.100.7158 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-0546 intel vulnerability CVSS: 4.6 12 Mar 2020, 21:15 UTC

Unquoted service path in Intel(R) Optane(TM) DC Persistent Memory Module Management Software before version 1.0.0.3461 may allow an authenticated user to potentially enable escalation of privilege and denial of service via local access.

CVE-2020-0530 intel vulnerability CVSS: 4.6 12 Mar 2020, 21:15 UTC

Improper buffer restrictions in firmware for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access. The list of affected products is provided in intel-sa-00343: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00343.html

CVE-2020-0526 intel vulnerability CVSS: 4.6 12 Mar 2020, 21:15 UTC

Improper input validation in firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege via local access. The list of affected products is provided in intel-sa-00343: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00343.html

CVE-2020-0520 intel vulnerability CVSS: 4.6 12 Mar 2020, 20:15 UTC

Path traversal in igdkmd64.sys for Intel(R) Graphics Drivers before versions 15.45.30.5103, 15.40.44.5107, 15.36.38.5117 and 15.33.49.5100 may allow an authenticated user to potentially enable escalation of privilege or denial of service via local access.

CVE-2020-0519 intel vulnerability CVSS: 4.6 12 Mar 2020, 20:15 UTC

Improper access control for Intel(R) Graphics Drivers before versions 15.33.49.5100 and 15.36.38.5117 may allow an authenticated user to potentially enable escalation of privilege or denial of service via local access.

CVE-2020-0517 intel vulnerability CVSS: 4.6 12 Mar 2020, 20:15 UTC

Out-of-bounds write in Intel(R) Graphics Drivers before version 15.36.38.5117 may allow an authenticated user to potentially enable escalation of privilege or denial of service via local access.

CVE-2020-0516 intel vulnerability CVSS: 2.1 12 Mar 2020, 20:15 UTC

Improper access control in Intel(R) Graphics Drivers before version 26.20.100.7463 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2020-0515 intel vulnerability CVSS: 4.6 12 Mar 2020, 20:15 UTC

Uncontrolled search path element in the installer for Intel(R) Graphics Drivers before versions 26.20.100.7584, 15.45.30.5103, 15.40.44.5107, 15.36.38.5117, and 15.33.49.5100 may allow an authenticated user to potentially enable escalation of privilege via local access

CVE-2020-0514 intel vulnerability CVSS: 4.6 12 Mar 2020, 20:15 UTC

Improper default permissions in the installer for Intel(R) Graphics Drivers before versions 26.20.100.7463 and 15.45.30.5103 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-0511 intel vulnerability CVSS: 2.1 12 Mar 2020, 20:15 UTC

Uncaught exception in system driver for Intel(R) Graphics Drivers before version 15.40.44.5107 may allow an authenticated user to potentially enable a denial of service via local access.

CVE-2020-0508 intel vulnerability CVSS: 4.6 12 Mar 2020, 20:15 UTC

Incorrect default permissions in the installer for Intel(R) Graphics Drivers before versions 15.33.49.5100, 15.36.38.5117, 15.40.44.5107, 15.45.30.5103, and 26.20.100.7212 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-0507 intel vulnerability CVSS: 2.1 12 Mar 2020, 18:15 UTC

Unquoted service path in Intel(R) Graphics Drivers before versions 15.33.49.5100, 15.36.38.5117, 15.40.44.5107, 15.45.30.5103, and 26.20.100.7212 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2020-0506 intel vulnerability CVSS: 2.1 12 Mar 2020, 18:15 UTC

Improper initialization in Intel(R) Graphics Drivers before versions 15.40.44.5107, 15.45.29.5077, and 26.20.100.7000 may allow a privileged user to potentially enable a denial of service via local access.

CVE-2020-0505 intel vulnerability CVSS: 3.6 12 Mar 2020, 18:15 UTC

Improper conditions check in Intel(R) Graphics Drivers before versions 15.33.49.5100, 15.36.38.5117, 15.40.44.5107, 15.45.30.5103, and 26.20.100.7212 may allow an authenticated user to potentially enable information disclosure and denial of service via local

CVE-2020-0504 intel vulnerability CVSS: 4.6 12 Mar 2020, 18:15 UTC

Buffer overflow in Intel(R) Graphics Drivers before versions 15.40.44.5107, 15.45.30.5103, and 26.20.100.7158 may allow an authenticated user to potentially enable escalation of privilege and denial of service via local access.

CVE-2020-0503 intel vulnerability CVSS: 2.1 12 Mar 2020, 18:15 UTC

Improper access control in Intel(R) Graphics Drivers before version 26.20.100.7212 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2020-0502 intel vulnerability CVSS: 4.6 12 Mar 2020, 18:15 UTC

Improper access control in Intel(R) Graphics Drivers before version 26.20.100.6912 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-0501 intel vulnerability CVSS: 2.1 12 Mar 2020, 18:15 UTC

Buffer overflow in Intel(R) Graphics Drivers before version 26.20.100.6912 may allow an authenticated user to potentially enable a denial of service via local access.

CVE-2019-14626 intel vulnerability CVSS: 4.6 12 Mar 2020, 18:15 UTC

Improper access control in PCIe function for the Intel® FPGA Programmable Acceleration Card N3000, all versions, may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2019-14625 intel vulnerability CVSS: 2.1 12 Mar 2020, 18:15 UTC

Improper access control in on-card storage for the Intel® FPGA Programmable Acceleration Card N3000, all versions, may allow a privileged user to potentially enable denial of service via local access.

CVE-2013-1634 intel vulnerability CVSS: 7.8 13 Feb 2020, 22:15 UTC

A denial of service vulnerability exists in some motherboard implementations of Intel e1000e/82574L network controller devices through 2013-02-06 where the device can be brought into a non-processing state when parsing 32 hex, 33 hex, or 34 hex byte values at the 0x47f offset. NOTE: A followup statement from Intel suggests that the root cause of this issue was an incorrectly configured EEPROM image.

CVE-2020-0564 intel vulnerability CVSS: 4.6 13 Feb 2020, 19:15 UTC

Improper permissions in the installer for Intel(R) RWC3 for Windows before version 7.010.009.000 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-0562 intel vulnerability CVSS: 4.6 13 Feb 2020, 19:15 UTC

Improper permissions in the installer for Intel(R) RWC2, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-0561 intel vulnerability CVSS: 4.6 13 Feb 2020, 19:15 UTC

Improper initialization in the Intel(R) SGX SDK before v2.6.100.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-14598 intel vulnerability CVSS: 4.6 13 Feb 2020, 19:15 UTC

Improper Authentication in subsystem in Intel(R) CSME versions 12.0 through 12.0.48 (IOT only: 12.0.56), versions 13.0 through 13.0.20, versions 14.0 through 14.0.10 may allow a privileged user to potentially enable escalation of privilege, denial of service or information disclosure via local access.

CVE-2020-0560 intel vulnerability CVSS: 4.6 13 Feb 2020, 17:15 UTC

Improper permissions in the installer for the Intel(R) Renesas Electronics(R) USB 3.0 Driver, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2020-0549 intel vulnerability CVSS: 2.1 28 Jan 2020, 01:15 UTC

Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2020-0548 intel vulnerability CVSS: 2.1 28 Jan 2020, 01:15 UTC

Cleanup errors in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2019-14629 intel vulnerability CVSS: 2.1 17 Jan 2020, 18:15 UTC

Improper permissions in Intel(R) DAAL before version 2020 Gold may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2019-14615 intel vulnerability CVSS: 1.9 17 Jan 2020, 18:15 UTC

Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access.

CVE-2019-14613 intel vulnerability CVSS: 4.6 17 Jan 2020, 18:15 UTC

Improper access control in driver for Intel(R) VTune(TM) Amplifier for Windows* before update 8 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-14601 intel vulnerability CVSS: 4.6 17 Jan 2020, 18:15 UTC

Improper permissions in the installer for Intel(R) RWC 3 for Windows before version 7.010.009.000 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-14600 intel vulnerability CVSS: 4.6 17 Jan 2020, 18:15 UTC

Uncontrolled search path element in the installer for Intel(R) SNMP Subagent Stand-Alone for Windows* may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-14596 intel vulnerability CVSS: 2.1 17 Jan 2020, 18:15 UTC

Improper access control in the installer for Intel(R) Chipset Device Software INF Utility before version 10.1.18 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2019-11147 intel vulnerability CVSS: 4.6 18 Dec 2019, 22:15 UTC

Insufficient access control in hardware abstraction driver for MEInfo software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.0, 14.0.10; TXEInfo software for Intel(R) TXE before versions 3.1.70 and 4.0.20; INTEL-SA-00086 Detection Tool version 1.2.7.0 or before; INTEL-SA-00125 Detection Tool version 1.0.45.0 or before may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-11132 intel vulnerability CVSS: 6.8 18 Dec 2019, 22:15 UTC

Cross site scripting in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow a privileged user to potentially enable escalation of privilege via network access.

CVE-2019-11131 intel vulnerability CVSS: 7.5 18 Dec 2019, 22:15 UTC

Logic issue in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVE-2019-11110 intel vulnerability CVSS: 4.6 18 Dec 2019, 22:15 UTC

Authentication bypass in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2019-11109 intel vulnerability CVSS: 4.6 18 Dec 2019, 22:15 UTC

Logic issue in the subsystem for Intel(R) SPS before versions SPS_E5_04.01.04.275.0, SPS_SoC-X_04.00.04.100.0 and SPS_SoC-A_04.00.04.191.0 may allow a privileged user to potentially enable denial of service via local access.

CVE-2019-11108 intel vulnerability CVSS: 4.6 18 Dec 2019, 22:15 UTC

Insufficient input validation in subsystem for Intel(R) CSME before versions 12.0.45 and 13.0.10 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2019-11107 intel vulnerability CVSS: 7.5 18 Dec 2019, 22:15 UTC

Insufficient input validation in the subsystem for Intel(R) AMT before version 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVE-2019-11106 intel vulnerability CVSS: 4.6 18 Dec 2019, 22:15 UTC

Insufficient session validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2019-11105 intel vulnerability CVSS: 4.6 18 Dec 2019, 22:15 UTC

Logic issue in subsystem for Intel(R) CSME before versions 12.0.45, 13.0.10 and 14.0.10 may allow a privileged user to potentially enable escalation of privilege and information disclosure via local access.

CVE-2019-11104 intel vulnerability CVSS: 4.6 18 Dec 2019, 22:15 UTC

Insufficient input validation in MEInfo software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-11103 intel vulnerability CVSS: 4.6 18 Dec 2019, 22:15 UTC

Insufficient input validation in firmware update software for Intel(R) CSME before versions 12.0.45,13.0.10 and 14.0.10 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-11102 intel vulnerability CVSS: 2.1 18 Dec 2019, 22:15 UTC

Insufficient input validation in Intel(R) DAL software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.

CVE-2019-11101 intel vulnerability CVSS: 2.1 18 Dec 2019, 22:15 UTC

Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.

CVE-2019-11100 intel vulnerability CVSS: 2.1 18 Dec 2019, 22:15 UTC

Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via physical access.

CVE-2019-11097 intel vulnerability CVSS: 4.6 18 Dec 2019, 22:15 UTC

Improper directory permissions in the installer for Intel(R) Management Engine Consumer Driver for Windows before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45,13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-11090 intel vulnerability CVSS: 4.3 18 Dec 2019, 22:15 UTC

Cryptographic timing conditions in the subsystem for Intel(R) PTT before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.0 and 14.0.10; Intel(R) TXE 3.1.70 and 4.0.20; Intel(R) SPS before versions SPS_E5_04.01.04.305.0, SPS_SoC-X_04.00.04.108.0, SPS_SoC-A_04.00.04.191.0, SPS_E3_04.01.04.086.0, SPS_E3_04.08.04.047.0 may allow an unauthenticated user to potentially enable information disclosure via network access.

CVE-2019-11088 intel vulnerability CVSS: 5.8 18 Dec 2019, 22:15 UTC

Insufficient input validation in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.

CVE-2019-11087 intel vulnerability CVSS: 4.6 18 Dec 2019, 22:15 UTC

Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable escalation of privilege, information disclosure or denial of service via local access.

CVE-2019-11086 intel vulnerability CVSS: 4.6 18 Dec 2019, 22:15 UTC

Insufficient input validation in subsystem for Intel(R) AMT before version 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVE-2019-0169 intel vulnerability CVSS: 5.8 18 Dec 2019, 22:15 UTC

Heap overflow in subsystem in Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an unauthenticated user to potentially enable escalation of privileges, information disclosure or denial of service via adjacent access.

CVE-2019-0168 intel vulnerability CVSS: 2.1 18 Dec 2019, 22:15 UTC

Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45 and 13.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.

CVE-2019-0166 intel vulnerability CVSS: 5.0 18 Dec 2019, 22:15 UTC

Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via network access.

CVE-2019-0165 intel vulnerability CVSS: 2.1 18 Dec 2019, 22:15 UTC

Insufficient Input validation in the subsystem for Intel(R) CSME before versions 12.0.45,13.0.10 and 14.0.10 may allow a privileged user to potentially enable denial of service via local access.

CVE-2019-0131 intel vulnerability CVSS: 4.8 18 Dec 2019, 22:15 UTC

Insufficient input validation in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable denial of service or information disclosure via adjacent access.

CVE-2019-14612 intel vulnerability CVSS: 4.6 16 Dec 2019, 20:15 UTC

Out of bounds write in firmware for Intel(R) NUC(R) may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2019-14611 intel vulnerability CVSS: 4.6 16 Dec 2019, 20:15 UTC

Integer overflow in firmware for Intel(R) NUC(R) may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2019-14610 intel vulnerability CVSS: 4.6 16 Dec 2019, 20:15 UTC

Improper access control in firmware for Intel(R) NUC(R) may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-14609 intel vulnerability CVSS: 4.6 16 Dec 2019, 20:15 UTC

Improper input validation in firmware for Intel(R) NUC(R) may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2019-14608 intel vulnerability CVSS: 4.6 16 Dec 2019, 20:15 UTC

Improper buffer restrictions in firmware for Intel(R) NUC(R) may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-14607 intel vulnerability CVSS: 4.6 16 Dec 2019, 20:15 UTC

Improper conditions check in multiple Intel® Processors may allow an authenticated user to potentially enable partial escalation of privilege, denial of service and/or information disclosure via local access.

CVE-2019-14605 intel vulnerability CVSS: 4.6 16 Dec 2019, 20:15 UTC

Improper permissions in the installer for the Intel(R) SCS Platform Discovery Utility, all versions, may allow an authenticated user to potentially enable escalation of privilege via local attack.

CVE-2019-14604 intel vulnerability CVSS: 2.1 16 Dec 2019, 20:15 UTC

Null pointer dereference in the FPGA kernel driver for Intel(R) Quartus(R) Prime Pro Edition before version 19.3 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2019-14603 intel vulnerability CVSS: 4.6 16 Dec 2019, 20:15 UTC

Improper permissions in the installer for the License Server software for Intel® Quartus® Prime Pro Edition before version 19.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-14599 intel vulnerability CVSS: 4.6 16 Dec 2019, 20:15 UTC

Unquoted service path in Control Center-I version 2.1.0.0 and earlier may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-14568 intel vulnerability CVSS: 4.6 16 Dec 2019, 20:15 UTC

Improper permissions in the executable for Intel(R) RST before version 17.7.0.1006 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-11165 intel vulnerability CVSS: 2.1 16 Dec 2019, 20:15 UTC

Improper conditions check in the Linux kernel driver for the Intel(R) FPGA SDK for OpenCL(TM) Pro Edition before version 19.4 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2019-11157 intel vulnerability CVSS: 4.6 16 Dec 2019, 20:15 UTC

Improper conditions check in voltage settings for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege and/or information disclosure via local access.

CVE-2019-11096 intel vulnerability CVSS: 2.1 16 Dec 2019, 20:15 UTC

Insufficient memory protection for Intel(R) Ethernet I218 Adapter driver for Windows* 10 before version 24.1 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2019-0159 intel vulnerability CVSS: 4.6 16 Dec 2019, 20:15 UTC

Insufficient memory protection in the Linux Administrative Tools for Intel(R) Network Adapters before version 24.3 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-0134 intel vulnerability CVSS: 4.6 16 Dec 2019, 20:15 UTC

Improper permissions in the Intel(R) Dynamic Platform and Thermal Framework v8.3.10208.5643 and before may allow an authenticated user to potentially execute code at an elevated level of privilege.

CVE-2019-14591 intel vulnerability CVSS: 2.1 14 Nov 2019, 20:15 UTC

Improper input validation in the API for Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2019-14590 intel vulnerability CVSS: 2.1 14 Nov 2019, 20:15 UTC

Improper access control in the API for the Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2019-14574 intel vulnerability CVSS: 2.1 14 Nov 2019, 20:15 UTC

Out of bounds read in a subsystem for Intel(R) Graphics Driver versions before 26.20.100.7209 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2019-11113 intel vulnerability CVSS: 2.1 14 Nov 2019, 20:15 UTC

Buffer overflow in Kernel Mode module for Intel(R) Graphics Driver before version 25.20.100.6618 (DCH) or 21.20.x.5077 (aka15.45.5077) may allow a privileged user to potentially enable information disclosure via local access.

CVE-2019-11111 intel vulnerability CVSS: 4.6 14 Nov 2019, 20:15 UTC

Pointer corruption in the Unified Shader Compiler in Intel(R) Graphics Drivers before 10.18.14.5074 (aka 15.36.x.5074) may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-11089 intel vulnerability CVSS: 2.1 14 Nov 2019, 20:15 UTC

Insufficient input validation in Kernel Mode module for Intel(R) Graphics Driver before version 25.20.100.6519 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2019-0184 intel vulnerability CVSS: 2.1 14 Nov 2019, 20:15 UTC

Insufficient access control in protected memory subsystem for Intel(R) TXT for 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Xeon(R) Processor E3-1500 v5 and v6 Families; Intel(R) Xeon(R) E-2100 and E-2200 Processor Families with Intel(R) Processor Graphics and Intel(R) TXT may allow a privileged user to potentially enable information disclosure via local access.

CVE-2019-0152 intel vulnerability CVSS: 7.2 14 Nov 2019, 20:15 UTC

Insufficient memory protection in System Management Mode (SMM) and Intel(R) TXT for certain Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2019-0151 intel vulnerability CVSS: 7.2 14 Nov 2019, 20:15 UTC

Insufficient memory protection in Intel(R) TXT for certain Intel(R) Core Processors and Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2019-0124 intel vulnerability CVSS: 7.2 14 Nov 2019, 20:15 UTC

Insufficient memory protection in Intel(R) 6th Generation Core Processors and greater, supporting TXT, may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2019-0123 intel vulnerability CVSS: 7.2 14 Nov 2019, 20:15 UTC

Insufficient memory protection in Intel(R) 6th Generation Core Processors and greater, supporting SGX, may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2019-0117 intel vulnerability CVSS: 2.1 14 Nov 2019, 20:15 UTC

Insufficient access control in protected memory subsystem for Intel(R) SGX for 6th, 7th, 8th, 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Xeon(R) Processor E3-1500 v5, v6 Families; Intel(R) Xeon(R) E-2100 & E-2200 Processor Families with Intel(R) Processor Graphics may allow a privileged user to potentially enable information disclosure via local access.

CVE-2018-12207 intel vulnerability CVSS: 4.9 14 Nov 2019, 20:15 UTC

Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.

CVE-2019-11139 intel vulnerability CVSS: 2.1 14 Nov 2019, 19:15 UTC

Improper conditions check in the voltage modulation interface for some Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable denial of service via local access.

CVE-2019-11135 intel vulnerability CVSS: 2.1 14 Nov 2019, 19:15 UTC

TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.

CVE-2019-11112 intel vulnerability CVSS: 7.2 14 Nov 2019, 19:15 UTC

Memory corruption in Kernel Mode Driver in Intel(R) Graphics Driver before 26.20.100.6813 (DCH) or 26.20.100.6812 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-0185 intel vulnerability CVSS: 2.1 14 Nov 2019, 19:15 UTC

Insufficient access control in protected memory subsystem for SMM for 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor families; Intel(R) Xeon(R) Processor E3-1500 v5 and v6 families; Intel(R) Xeon(R) E-2100 and E-2200 Processor families with Intel(R) Processor Graphics may allow a privileged user to potentially enable information disclosure via local access.

CVE-2019-0155 intel vulnerability CVSS: 7.2 14 Nov 2019, 19:15 UTC

Insufficient access control in a subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R) Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900 Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6, E-2100 and E-2200 Processor Families; Intel(R) Graphics Driver for Windows before 26.20.100.6813 (DCH) or 26.20.100.6812 and before 21.20.x.5077 (aka15.45.5077), i915 Linux Driver for Intel(R) Processor Graphics before versions 5.4-rc7, 5.3.11, 4.19.84, 4.14.154, 4.9.201, 4.4.201 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-0154 intel vulnerability CVSS: 2.1 14 Nov 2019, 19:15 UTC

Insufficient access control in subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R) Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900 Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6 and E-2100 Processor Families may allow an authenticated user to potentially enable denial of service via local access.

CVE-2019-0150 intel vulnerability CVSS: 2.1 14 Nov 2019, 19:15 UTC

Insufficient access control in firmware Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow a privileged user to potentially enable a denial of service via local access.

CVE-2019-0149 intel vulnerability CVSS: 2.1 14 Nov 2019, 19:15 UTC

Insufficient input validation in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 2.8.43 may allow an authenticated user to potentially enable a denial of service via local access.

CVE-2019-0148 intel vulnerability CVSS: 2.1 14 Nov 2019, 19:15 UTC

Resource leak in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable a denial of service via local access.

CVE-2019-0147 intel vulnerability CVSS: 2.1 14 Nov 2019, 19:15 UTC

Insufficient input validation in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable a denial of service via local access.

CVE-2019-0146 intel vulnerability CVSS: 2.1 14 Nov 2019, 19:15 UTC

Resource leak in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 2.8.43 may allow an authenticated user to potentially enable a denial of service via local access.

CVE-2019-0145 intel vulnerability CVSS: 7.2 14 Nov 2019, 19:15 UTC

Buffer overflow in i40e driver for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable an escalation of privilege via local access.

CVE-2019-0144 intel vulnerability CVSS: 4.9 14 Nov 2019, 19:15 UTC

Unhandled exception in firmware for Intel(R) Ethernet 700 Series Controllers before version 7.0 may allow an authenticated user to potentially enable a denial of service via local access.

CVE-2019-0143 intel vulnerability CVSS: 4.9 14 Nov 2019, 19:15 UTC

Unhandled exception in Kernel-mode drivers for Intel(R) Ethernet 700 Series Controllers versions before 7.0 may allow an authenticated user to potentially enable a denial of service via local access.

CVE-2019-0142 intel vulnerability CVSS: 7.2 14 Nov 2019, 19:15 UTC

Insufficient access control in ilp60x64.sys driver for Intel(R) Ethernet 700 Series Controllers before version 1.33.0.0 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2019-0140 intel vulnerability CVSS: 5.8 14 Nov 2019, 19:15 UTC

Buffer overflow in firmware for Intel(R) Ethernet 700 Series Controllers before version 7.0 may allow an unauthenticated user to potentially enable an escalation of privilege via an adjacent access.

CVE-2019-0139 intel vulnerability CVSS: 4.6 14 Nov 2019, 19:15 UTC

Insufficient access control in firmware for Intel(R) Ethernet 700 Series Controllers before version 7.0 may allow a privileged user to potentially enable an escalation of privilege, denial of service, or information disclosure via local access.

CVE-2019-14602 intel vulnerability CVSS: 4.6 14 Nov 2019, 17:15 UTC

Improper permissions in the installer for the Nuvoton* CIR Driver versions 1.02.1002 and before may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-14566 intel vulnerability CVSS: 4.6 14 Nov 2019, 17:15 UTC

Insufficient input validation in Intel(R) SGX SDK multiple Linux and Windows versions may allow an authenticated user to enable information disclosure, escalation of privilege or denial of service via local access.

CVE-2019-14565 intel vulnerability CVSS: 4.6 14 Nov 2019, 17:15 UTC

Insufficient initialization in Intel(R) SGX SDK Windows versions 2.4.100.51291 and earlier, and Linux versions 2.6.100.51363 and earlier, may allow an authenticated user to enable information disclosure, escalation of privilege or denial of service via local access.

CVE-2019-11182 intel vulnerability CVSS: 7.8 14 Nov 2019, 17:15 UTC

Memory corruption in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of service via network access.

CVE-2019-11181 intel vulnerability CVSS: 7.2 14 Nov 2019, 17:15 UTC

Out of bound read in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVE-2019-11180 intel vulnerability CVSS: 7.8 14 Nov 2019, 17:15 UTC

Insufficient input validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of service via network access.

CVE-2019-11179 intel vulnerability CVSS: 4.0 14 Nov 2019, 17:15 UTC

Insufficient input validation in Intel(R) Baseboard Management Controller firmware may allow an authenticated user to potentially enable information disclosure via network access.

CVE-2019-11178 intel vulnerability CVSS: 5.5 14 Nov 2019, 17:15 UTC

Stack overflow in Intel(R) Baseboard Management Controller firmware may allow an authenticated user to potentially enable information disclosure and/or denial of service via network access.

CVE-2019-11177 intel vulnerability CVSS: 7.8 14 Nov 2019, 17:15 UTC

Unhandled exception in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of service via network access.

CVE-2019-11175 intel vulnerability CVSS: 5.0 14 Nov 2019, 17:15 UTC

Insufficient input validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable denial of service via network access.

CVE-2019-11174 intel vulnerability CVSS: 5.0 14 Nov 2019, 17:15 UTC

Insufficient access control in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure via network access.

CVE-2019-11173 intel vulnerability CVSS: 3.6 14 Nov 2019, 17:15 UTC

Insufficient session validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure and/or denial of service via local access.

CVE-2019-11172 intel vulnerability CVSS: 5.0 14 Nov 2019, 17:15 UTC

Out of bound read in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure via network access.

CVE-2019-11171 intel vulnerability CVSS: 7.5 14 Nov 2019, 17:15 UTC

Heap corruption in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure, escalation of privilege and/or denial of service via network access.

CVE-2019-11170 intel vulnerability CVSS: 7.2 14 Nov 2019, 17:15 UTC

Authentication bypass in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure, escalation of privilege and/or denial of service via local access.

CVE-2019-11168 intel vulnerability CVSS: 6.4 14 Nov 2019, 17:15 UTC

Insufficient session validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure and/or denial of service via network access.

CVE-2019-11156 intel vulnerability CVSS: 4.6 14 Nov 2019, 17:15 UTC

Logic errors in Intel(R) PROSet/Wireless WiFi Software before version 21.40 may allow an authenticated user to potentially enable escalation of privilege, denial of service, and information disclosure via local access.

CVE-2019-11155 intel vulnerability CVSS: 3.6 14 Nov 2019, 17:15 UTC

Improper directory permissions in Intel(R) PROSet/Wireless WiFi Software before version 21.40 may allow an authenticated user to potentially enable denial of service and information disclosure via local access.

CVE-2019-11154 intel vulnerability CVSS: 3.6 14 Nov 2019, 17:15 UTC

Improper directory permissions in Intel(R) PROSet/Wireless WiFi Software before version 21.40 may allow an authenticated user to potentially enable denial of service and information disclosure via local access.

CVE-2019-11153 intel vulnerability CVSS: 4.6 14 Nov 2019, 17:15 UTC

Memory corruption issues in Intel(R) PROSet/Wireless WiFi Software extension DLL before version 21.40 may allow an authenticated user to potentially enable escalation of privilege, information disclosure and a denial of service via local access.

CVE-2019-11152 intel vulnerability CVSS: 5.8 14 Nov 2019, 17:15 UTC

Memory corruption issues in Intel(R) WIFI Drivers before version 21.40 may allow a privileged user to potentially enable escalation of privilege, denial of service, and information disclosure via adjacent access.

CVE-2019-11151 intel vulnerability CVSS: 4.6 14 Nov 2019, 17:15 UTC

Memory corruption issues in Intel(R) WIFI Drivers before version 21.40 may allow a privileged user to potentially enable escalation of privilege, denial of service, and information disclosure via local access.

CVE-2019-11137 intel vulnerability CVSS: 4.6 14 Nov 2019, 17:15 UTC

Insufficient input validation in system firmware for Intel(R) Xeon(R) Scalable Processors, Intel(R) Xeon(R) Processors D Family, Intel(R) Xeon(R) Processors E5 v4 Family, Intel(R) Xeon(R) Processors E7 v4 Family and Intel(R) Atom(R) processor C Series may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.

CVE-2019-11136 intel vulnerability CVSS: 4.6 14 Nov 2019, 17:15 UTC

Insufficient access control in system firmware for Intel(R) Xeon(R) Scalable Processors, 2nd Generation Intel(R) Xeon(R) Scalable Processors and Intel(R) Xeon(R) Processors D Family may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.

CVE-2019-14570 intel vulnerability CVSS: 4.6 11 Oct 2019, 18:15 UTC

Memory corruption in system firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.

CVE-2019-14569 intel vulnerability CVSS: 4.6 11 Oct 2019, 18:15 UTC

Pointer corruption in system firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.

CVE-2019-11167 intel vulnerability CVSS: 4.6 11 Oct 2019, 18:15 UTC

Improper file permission in software installer for Intel(R) Smart Connect Technology for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-11120 intel vulnerability CVSS: 4.6 11 Oct 2019, 18:15 UTC

Insufficient path checking in the installer for Intel(R) Active System Console before version 8.0 Build 24 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-11184 intel vulnerability CVSS: 2.3 16 Sep 2019, 16:15 UTC

A race condition in specific microprocessors using Intel (R) DDIO cache allocation and RDMA may allow an authenticated user to potentially enable partial information disclosure via adjacent access.

CVE-2019-11166 intel vulnerability CVSS: 4.6 16 Sep 2019, 16:15 UTC

Improper file permissions in the installer for Intel(R) Easy Streaming Wizard before version 2.1.0731 may allow an authenticated user to potentially enable escalation of privilege via local attack.

CVE-2019-11163 intel vulnerability CVSS: 4.6 19 Aug 2019, 17:15 UTC

Insufficient access control in a hardware abstraction driver for Intel(R) Processor Identification Utility for Windows before version 6.1.0731 may allow an authenticated user to potentially enable escalation of privilege, denial of service or information disclosure via local access.

CVE-2019-11162 intel vulnerability CVSS: 4.6 19 Aug 2019, 17:15 UTC

Insufficient access control in hardware abstraction in SEMA driver for Intel(R) Computing Improvement Program before version 2.4.0.04733 may allow an authenticated user to potentially enable escalation of privilege, denial of service or information disclosure via local access.

CVE-2019-11148 intel vulnerability CVSS: 4.6 19 Aug 2019, 17:15 UTC

Improper permissions in the installer for Intel(R) Remote Displays SDK before version 2.0.1 R2 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-11146 intel vulnerability CVSS: 4.6 19 Aug 2019, 17:15 UTC

Improper file verification in Intel® Driver & Support Assistant before 19.7.30.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-11145 intel vulnerability CVSS: 4.6 19 Aug 2019, 17:15 UTC

Improper file verification in Intel® Driver & Support Assistant before 19.7.30.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-11143 intel vulnerability CVSS: 4.6 19 Aug 2019, 17:15 UTC

Improper permissions in the software installer for Intel(R) Authenticate before 3.8 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-11140 intel vulnerability CVSS: 4.6 19 Aug 2019, 17:15 UTC

Insufficient session validation in system firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.

CVE-2019-0173 intel vulnerability CVSS: 5.8 19 Aug 2019, 17:15 UTC

Authentication bypass in the web console for Intel(R) Raid Web Console 2 all versions may allow an unauthenticated attacker to potentially enable disclosure of information via network access.

CVE-2019-11133 intel vulnerability CVSS: 4.6 11 Jul 2019, 21:15 UTC

Improper access control in the Intel(R) Processor Diagnostic Tool before version 4.1.2.24 may allow an authenticated user to potentially enable escalation of privilege, information disclosure or denial of service via local access.

CVE-2019-11129 intel vulnerability CVSS: 4.6 13 Jun 2019, 16:29 UTC

Out of bound read/write in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.

CVE-2019-11128 intel vulnerability CVSS: 4.6 13 Jun 2019, 16:29 UTC

Insufficient input validation in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.

CVE-2019-11127 intel vulnerability CVSS: 4.6 13 Jun 2019, 16:29 UTC

Buffer overflow in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.

CVE-2019-11126 intel vulnerability CVSS: 4.6 13 Jun 2019, 16:29 UTC

Pointer corruption in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.

CVE-2019-11125 intel vulnerability CVSS: 4.6 13 Jun 2019, 16:29 UTC

Insufficient input validation in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.

CVE-2019-11124 intel vulnerability CVSS: 4.6 13 Jun 2019, 16:29 UTC

Out of bound read/write in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.

CVE-2019-11123 intel vulnerability CVSS: 4.6 13 Jun 2019, 16:29 UTC

Insufficient session validation in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.

CVE-2019-11119 intel vulnerability CVSS: 7.5 13 Jun 2019, 16:29 UTC

Insufficient session validation in the service API for Intel(R) RWC3 version 4.186 and before may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVE-2019-11117 intel vulnerability CVSS: 4.6 13 Jun 2019, 16:29 UTC

Improper permissions in the installer for Intel(R) Omni-Path Fabric Manager GUI before version 10.9.2.1.1 may allow an authenticated user to potentially enable escalation of privilege via local attack.

CVE-2019-11092 intel vulnerability CVSS: 3.6 13 Jun 2019, 16:29 UTC

Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2019-0183 intel vulnerability CVSS: 2.1 13 Jun 2019, 16:29 UTC

Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2019-0182 intel vulnerability CVSS: 2.1 13 Jun 2019, 16:29 UTC

Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2019-0181 intel vulnerability CVSS: 4.6 13 Jun 2019, 16:29 UTC

Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2019-0180 intel vulnerability CVSS: 3.6 13 Jun 2019, 16:29 UTC

Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2019-0179 intel vulnerability CVSS: 3.6 13 Jun 2019, 16:29 UTC

Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2019-0178 intel vulnerability CVSS: 3.3 13 Jun 2019, 16:29 UTC

Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2019-0177 intel vulnerability CVSS: 3.6 13 Jun 2019, 16:29 UTC

Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2019-0175 intel vulnerability CVSS: 3.6 13 Jun 2019, 16:29 UTC

Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2019-0174 intel vulnerability CVSS: 2.1 13 Jun 2019, 16:29 UTC

Logic condition in specific microprocessors may allow an authenticated user to potentially enable partial physical address information disclosure via local access.

CVE-2019-0164 intel vulnerability CVSS: 4.4 13 Jun 2019, 16:29 UTC

Improper permissions in the installer for Intel(R) Turbo Boost Max Technology 3.0 driver version 1.0.0.1035 and before may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-0157 intel vulnerability CVSS: 2.1 13 Jun 2019, 16:29 UTC

Insufficient input validation in the Intel(R) SGX driver for Linux may allow an authenticated user to potentially enable a denial of service via local access.

CVE-2019-0136 intel vulnerability CVSS: 3.3 13 Jun 2019, 16:29 UTC

Insufficient access control in the Intel(R) PROSet/Wireless WiFi Software driver before version 21.10 may allow an unauthenticated user to potentially enable denial of service via adjacent access.

CVE-2019-0130 intel vulnerability CVSS: 4.3 13 Jun 2019, 16:29 UTC

Reflected XSS in web interface for Intel(R) Accelerated Storage Manager in Intel(R) RSTe before version 5.5.0.2015 may allow an unauthenticated user to potentially enable denial of service via network access.

CVE-2019-0128 intel vulnerability CVSS: 4.6 13 Jun 2019, 16:29 UTC

Improper permissions in the installer for Intel(R) Chipset Device Software (INF Update Utility) before version 10.1.1.45 may allow an authenticated user to escalate privilege via local access.

CVE-2018-3702 intel vulnerability CVSS: 4.6 13 Jun 2019, 16:29 UTC

Improper permissions in the installer for the ITE Tech* Consumer Infrared Driver for Windows 10 versions before 5.4.3.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2018-12147 intel vulnerability CVSS: 7.2 13 Jun 2019, 16:29 UTC

Insufficient input validation in HECI subsystem in Intel(R) CSME before version 11.21.55, Intel® Server Platform Services before version 4.0 and Intel® Trusted Execution Engine Firmware before version 3.1.55 may allow a privileged user to potentially enable escalation of privileges via local access.

CVE-2019-11091 intel vulnerability CVSS: 4.7 30 May 2019, 16:29 UTC

Microarchitectural Data Sampling Uncacheable Memory (MDSUM): Uncacheable memory on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf

CVE-2018-12130 intel vulnerability CVSS: 4.7 30 May 2019, 16:29 UTC

Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf

CVE-2018-12127 intel vulnerability CVSS: 4.7 30 May 2019, 16:29 UTC

Microarchitectural Load Port Data Sampling (MLPDS): Load ports on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf

CVE-2018-12126 intel vulnerability CVSS: 4.7 30 May 2019, 16:29 UTC

Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf

CVE-2019-11114 intel vulnerability CVSS: 2.1 17 May 2019, 16:29 UTC

Insufficient input validation in Intel(R) Driver & Support Assistant version 19.3.12.3 and before may allow a privileged user to potentially enable denial of service via local access.

CVE-2019-11095 intel vulnerability CVSS: 2.1 17 May 2019, 16:29 UTC

Insufficient access control in Intel(R) Driver & Support Assistant version 19.3.12.3 and before may allow a privileged user to potentially enable information disclosure via local access.

CVE-2019-11094 intel vulnerability CVSS: 4.6 17 May 2019, 16:29 UTC

Insufficient input validation in system firmware for Intel (R) NUC Kit may allow an authenticated user to potentially enable escalation of privilege, denial of service, and/or information disclosure via local access.

CVE-2019-11093 intel vulnerability CVSS: 4.6 17 May 2019, 16:29 UTC

Unquoted service path in the installer for the Intel(R) SCS Discovery Utility version 12.0.0.129 and earlier may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-0172 intel vulnerability CVSS: 7.5 17 May 2019, 16:29 UTC

A logic issue in Intel Unite(R) Client for Android prior to version 4.0 may allow a remote attacker to potentially enable escalation of privilege via network access.

CVE-2019-0171 intel vulnerability CVSS: 4.6 17 May 2019, 16:29 UTC

Improper directory permissions in the installer for Intel(R) Quartus(R) software may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-0170 intel vulnerability CVSS: 4.6 17 May 2019, 16:29 UTC

Buffer overflow in subsystem in Intel(R) DAL before version 12.0.35 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2019-0153 intel vulnerability CVSS: 7.5 17 May 2019, 16:29 UTC

Buffer overflow in subsystem in Intel(R) CSME 12.0.0 through 12.0.34 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVE-2019-0138 intel vulnerability CVSS: 4.6 17 May 2019, 16:29 UTC

Improper directory permissions in Intel(R) ACU Wizard version 12.0.0.129 and earlier may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-0132 intel vulnerability CVSS: 5.0 17 May 2019, 16:29 UTC

Data Corruption in Intel Unite(R) Client before version 3.3.176.13 may allow an unauthenticated user to potentially cause a denial of service via network access.

CVE-2019-0126 intel vulnerability CVSS: 7.2 17 May 2019, 16:29 UTC

Insufficient access control in silicon reference firmware for Intel(R) Xeon(R) Scalable Processor, Intel(R) Xeon(R) Processor D Family may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access.

CVE-2019-0120 intel vulnerability CVSS: 2.1 17 May 2019, 16:29 UTC

Insufficient key protection vulnerability in silicon reference firmware for Intel(R) Pentium(R) Processor J Series, Intel(R) Pentium(R) Processor N Series, Intel(R) Celeron(R) J Series, Intel(R) Celeron(R) N Series, Intel(R) Atom(R) Processor A Series, Intel(R) Atom(R) Processor E3900 Series, Intel(R) Pentium(R) Processor Silver Series may allow a privileged user to potentially enable denial of service via local access.

CVE-2019-0119 intel vulnerability CVSS: 7.2 17 May 2019, 16:29 UTC

Buffer overflow vulnerability in system firmware for Intel(R) Xeon(R) Processor D Family, Intel(R) Xeon(R) Scalable Processor, Intel(R) Server Board, Intel(R) Server System and Intel(R) Compute Module may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access.

CVE-2019-0116 intel vulnerability CVSS: 2.1 17 May 2019, 16:29 UTC

An out of bound read in KMD module for Intel(R) Graphics Driver before version 10.18.14.5067 (aka 15.36.x.5067) and 10.18.10.5069 (aka 15.33.x.5069) may allow a privileged user to potentially enable denial of service via local access.

CVE-2019-0115 intel vulnerability CVSS: 2.1 17 May 2019, 16:29 UTC

Insufficient input validation in KMD module for Intel(R) Graphics Driver before version 10.18.14.5067 (aka 15.36.x.5067) and 10.18.10.5069 (aka 15.33.x.5069) may allow an authenticated user to potentially enable denial of service via local access.

CVE-2019-0114 intel vulnerability CVSS: 1.9 17 May 2019, 16:29 UTC

A race condition in Intel(R) Graphics Drivers before version 10.18.14.5067 (aka 15.36.x.5067) and 10.18.10.5069 (aka 15.33.x.5069) may allow an authenticated user to potentially enable a denial of service via local access.

CVE-2019-0113 intel vulnerability CVSS: 2.1 17 May 2019, 16:29 UTC

Insufficient bounds checking in Intel(R) Graphics Drivers before version 10.18.14.5067 (aka 15.36.x.5067) and 10.18.10.5069 (aka 15.33.x.5069) may allow an authenticated user to potentially enable a denial of service via local access.

CVE-2019-0099 intel vulnerability CVSS: 4.6 17 May 2019, 16:29 UTC

Insufficient access control vulnerability in subsystem in Intel(R) SPS before version SPS_E3_05.00.04.027.0 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVE-2019-0098 intel vulnerability CVSS: 7.2 17 May 2019, 16:29 UTC

Logic bug vulnerability in subsystem for Intel(R) CSME before version 12.0.35, Intel(R) TXE before 3.1.65, 4.0.15 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVE-2019-0097 intel vulnerability CVSS: 4.0 17 May 2019, 16:29 UTC

Insufficient input validation vulnerability in subsystem for Intel(R) AMT before version 12.0.35 may allow a privileged user to potentially enable denial of service via network access.

CVE-2019-0096 intel vulnerability CVSS: 5.2 17 May 2019, 16:29 UTC

Out of bound write vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 may allow an authenticated user to potentially enable escalation of privilege via adjacent network access.

CVE-2019-0094 intel vulnerability CVSS: 3.3 17 May 2019, 16:29 UTC

Insufficient input validation vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 may allow an unauthenticated user to potentially enable denial of service via adjacent network access.

CVE-2019-0093 intel vulnerability CVSS: 2.1 17 May 2019, 16:29 UTC

Insufficient data sanitization vulnerability in HECI subsystem for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) SPS before version SPS_E3_05.00.04.027.0 may allow a privileged user to potentially enable information disclosure via local access.

CVE-2019-0092 intel vulnerability CVSS: 4.6 17 May 2019, 16:29 UTC

Insufficient input validation vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVE-2019-0091 intel vulnerability CVSS: 7.2 17 May 2019, 16:29 UTC

Code injection vulnerability in installer for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may allow an unprivileged user to potentially enable escalation of privilege via local access.

CVE-2019-0090 intel vulnerability CVSS: 4.4 17 May 2019, 16:29 UTC

Insufficient access control vulnerability in subsystem for Intel(R) CSME before versions 11.x, 12.0.35 Intel(R) TXE 3.x, 4.x, Intel(R) Server Platform Services 3.x, 4.x, Intel(R) SPS before version SPS_E3_05.00.04.027.0 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVE-2019-0089 intel vulnerability CVSS: 4.6 17 May 2019, 16:29 UTC

Improper data sanitization vulnerability in subsystem in Intel(R) SPS before versions SPS_E5_04.00.04.381.0, SPS_E3_04.01.04.054.0, SPS_SoC-A_04.00.04.181.0, and SPS_SoC-X_04.00.04.086.0 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2019-0086 intel vulnerability CVSS: 4.6 17 May 2019, 16:29 UTC

Insufficient access control vulnerability in Dynamic Application Loader software for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may allow an unprivileged user to potentially enable escalation of privilege via local access.

CVE-2018-3701 intel vulnerability CVSS: 4.6 17 May 2019, 16:29 UTC

Improper directory permissions in the installer for Intel(R) PROSet/Wireless WiFi Software version 20.100 and earlier may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-0162 intel vulnerability CVSS: 2.1 17 Apr 2019, 18:29 UTC

Memory access in virtual memory mapping for some microprocessors may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2019-0158 intel vulnerability CVSS: 4.6 17 Apr 2019, 18:29 UTC

Insufficient path checking in the installation package for Intel(R) Graphics Performance Analyzer for Linux version 18.4 and before may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2018-18094 intel vulnerability CVSS: 4.6 17 Apr 2019, 18:29 UTC

Improper directory permissions in installer for Intel(R) Media SDK before 2018 R2.1 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-0135 intel vulnerability CVSS: 4.6 14 Mar 2019, 20:29 UTC

Improper permissions in the installer for Intel(R) Accelerated Storage Manager in Intel(R) RSTe before version 5.5.0.2015 may allow an authenticated user to potentially enable escalation of privilege via local access. L-SA-00206

CVE-2019-0129 intel vulnerability CVSS: 4.6 14 Mar 2019, 20:29 UTC

Improper permissions for Intel(R) USB 3.0 Creator Utility all versions may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-0122 intel vulnerability CVSS: 3.6 14 Mar 2019, 20:29 UTC

Double free in Intel(R) SGX SDK for Linux before version 2.2 and Intel(R) SGX SDK for Windows before version 2.1 may allow an authenticated user to potentially enable information disclosure or denial of service via local access.

CVE-2019-0121 intel vulnerability CVSS: 4.6 14 Mar 2019, 20:29 UTC

Improper permissions in Intel(R) Matrix Storage Manager 8.9.0.1023 and before may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2018-18091 intel vulnerability CVSS: 2.1 14 Mar 2019, 20:29 UTC

Use after free in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 may allow an unprivileged user to potentially enable a denial of service via local access.

CVE-2018-18090 intel vulnerability CVSS: 2.1 14 Mar 2019, 20:29 UTC

Out of bounds read in igdkm64.sys in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 may allow an authenticated user to potentially enable denial of service via local access.

CVE-2018-18089 intel vulnerability CVSS: 2.1 14 Mar 2019, 20:29 UTC

Multiple out of bounds read in igdkm64.sys in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2018-12224 intel vulnerability CVSS: 2.1 14 Mar 2019, 20:29 UTC

Buffer leakage in igdkm64.sys in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2018-12223 intel vulnerability CVSS: 4.6 14 Mar 2019, 20:29 UTC

Insufficient access control in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables an unprivileged user to escape from a virtual machine guest-to-host via local access.

CVE-2018-12222 intel vulnerability CVSS: 2.1 14 Mar 2019, 20:29 UTC

Insufficient input validation in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables an unprivileged user to cause an out of bound memory read via local access.

CVE-2018-12221 intel vulnerability CVSS: 4.6 14 Mar 2019, 20:29 UTC

Insufficient input validation in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables an unprivileged user to cause an integer overflow via local access.

CVE-2018-12220 intel vulnerability CVSS: 7.2 14 Mar 2019, 20:29 UTC

Logic bug in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables a privileged user to execute arbitrary code via local access.

CVE-2018-12219 intel vulnerability CVSS: 2.1 14 Mar 2019, 20:29 UTC

Insufficient input validation in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables an unprivileged user to read memory via local access via local access.

CVE-2018-12218 intel vulnerability CVSS: 2.1 14 Mar 2019, 20:29 UTC

Unhandled exception in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables an unprivileged user to cause a memory leak via local access.

CVE-2018-12217 intel vulnerability CVSS: 2.1 14 Mar 2019, 20:29 UTC

Insufficient access control in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables a privileged user to read device configuration information via local access.

CVE-2018-12216 intel vulnerability CVSS: 7.2 14 Mar 2019, 20:29 UTC

Insufficient input validation in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables a privileged user to execute arbitrary code via local access via local access.

CVE-2018-12215 intel vulnerability CVSS: 2.1 14 Mar 2019, 20:29 UTC

Insufficient input validation in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables a privileged user to cause a denial of service via local access.

CVE-2018-12214 intel vulnerability CVSS: 7.2 14 Mar 2019, 20:29 UTC

Potential memory corruption in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables a privileged user to execute arbitrary code via local access.

CVE-2018-12213 intel vulnerability CVSS: 2.1 14 Mar 2019, 20:29 UTC

Potential memory corruption in Kernel Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables an unprivileged user to cause a denial of service via local access.

CVE-2018-12212 intel vulnerability CVSS: 2.1 14 Mar 2019, 20:29 UTC

Buffer overflow in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables an unprivileged user to cause a denial of service via local access.

CVE-2018-12211 intel vulnerability CVSS: 2.1 14 Mar 2019, 20:29 UTC

Insufficient input validation in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables an unprivileged user to cause a denial of service via local access.

CVE-2018-12210 intel vulnerability CVSS: 2.1 14 Mar 2019, 20:29 UTC

Multiple pointer dereferences in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables an unprivileged user to cause a denial of service via local access.

CVE-2018-12209 intel vulnerability CVSS: 2.1 14 Mar 2019, 20:29 UTC

Insufficient access control in User Mode Driver in Intel(R) Graphics Driver for Windows* before versions 10.18.x.5059 (aka 15.33.x.5059), 10.18.x.5057 (aka 15.36.x.5057), 20.19.x.5063 (aka 15.40.x.5063) 21.20.x.5064 (aka 15.45.x.5064) and 24.20.100.6373 potentially enables an unprivileged user to read device configuration information via local access.

CVE-2018-12208 intel vulnerability CVSS: 4.6 14 Mar 2019, 20:29 UTC

Buffer overflow in HECI subsystem in Intel(R) CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel(R) TXE version before 3.1.60 or 4.0.10, or Intel(R) Server Platform Services before version 5.00.04.012 may allow an unauthenticated user to potentially execute arbitrary code via physical access.

CVE-2018-12205 intel vulnerability CVSS: 7.2 14 Mar 2019, 20:29 UTC

Improper certificate validation in Platform Sample/ Silicon Reference firmware for 8th Generation Intel(R) Core(tm) Processor, 7th Generation Intel(R) Core(tm) Processor may allow an unauthenticated user to potentially enable an escalation of privilege via physical access.

CVE-2018-12204 intel vulnerability CVSS: 7.2 14 Mar 2019, 20:29 UTC

Improper memory initialization in Platform Sample/Silicon Reference firmware Intel(R) Server Board, Intel(R) Server System and Intel(R) Compute Module may allow privileged user to potentially enable an escalation of privilege via local access.

CVE-2018-12203 intel vulnerability CVSS: 7.2 14 Mar 2019, 20:29 UTC

Denial of service vulnerability in Platform Sample/ Silicon Reference firmware for 8th Generation Intel Core Processor, 7th Generation Intel Core Processor may allow privileged user to potentially execute arbitrary code via local access.

CVE-2018-12202 intel vulnerability CVSS: 7.2 14 Mar 2019, 20:29 UTC

Privilege escalation vulnerability in Platform Sample/ Silicon Reference firmware for 8th Generation Intel(R) Core Processor, 7th Generation Intel(R) Core Processor may allow privileged user to potentially leverage existing features via local access.

CVE-2018-12201 intel vulnerability CVSS: 7.2 14 Mar 2019, 20:29 UTC

Buffer overflow vulnerability in Platform Sample / Silicon Reference firmware for 8th Generation Intel(R) Core Processor, 7th Generation Intel(R) Core Processor, Intel(R) Pentium(R) Silver J5005 Processor, Intel(R) Pentium(R) Silver N5000 Processor, Intel(R) Celeron(R) J4105 Processor, Intel(R) Celeron(R) J4005 Processor, Intel Celeron(R) N4100 Processor and Intel(R) Celeron N4000 Processor may allow privileged user to potentially execute arbitrary code via local access.

CVE-2018-12199 intel vulnerability CVSS: 7.2 14 Mar 2019, 20:29 UTC

Buffer overflow in an OS component in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel TXE version before 3.1.60 or 4.0.10 may allow a privileged user to potentially execute arbitrary code via physical access.

CVE-2018-12198 intel vulnerability CVSS: 2.1 14 Mar 2019, 20:29 UTC

Insufficient input validation in Intel(R) Server Platform Services HECI subsystem before version SPS_E5_04.00.04.393.0 may allow privileged user to potentially cause a denial of service via local access.

CVE-2018-12196 intel vulnerability CVSS: 4.6 14 Mar 2019, 20:29 UTC

Insufficient input validation in Intel(R) AMT in Intel(R) CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow a privileged user to potentially execute arbitrary code via local access.

CVE-2018-12192 intel vulnerability CVSS: 7.2 14 Mar 2019, 20:29 UTC

Logic bug in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before version SPS_E5_04.00.04.393.0 may allow an unauthenticated user to potentially bypass MEBx authentication via physical access.

CVE-2018-12191 intel vulnerability CVSS: 7.2 14 Mar 2019, 20:29 UTC

Bounds check in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before versions 4.00.04.383 or SPS 4.01.02.174, or Intel(R) TXE before versions 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially execute arbitrary code via physical access.

CVE-2018-12190 intel vulnerability CVSS: 4.6 14 Mar 2019, 20:29 UTC

Insufficient input validation in Intel(r) CSME subsystem before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel(r) TXE before 3.1.60 or 4.0.10 may allow a privileged user to potentially enable an escalation of privilege via local access.

CVE-2018-12189 intel vulnerability CVSS: 2.1 14 Mar 2019, 20:29 UTC

Unhandled exception in Content Protection subsystem in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before 3.1.60 or 4.0.10 may allow privileged user to potentially modify data via local access.

CVE-2018-12188 intel vulnerability CVSS: 2.1 14 Mar 2019, 20:29 UTC

Insufficient input validation in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before version 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially modify data via physical access.

CVE-2018-12187 intel vulnerability CVSS: 5.0 14 Mar 2019, 20:29 UTC

Insufficient input validation in Intel(R) Active Management Technology (Intel(R) AMT) before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow an unauthenticated user to potentially cause a denial of service via network access.

CVE-2018-12185 intel vulnerability CVSS: 4.6 14 Mar 2019, 20:29 UTC

Insufficient input validation in Intel(R) AMT in Intel(R) CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow an unauthenticated user to potentially execute arbitrary code via physical access.

CVE-2019-0127 intel vulnerability CVSS: 2.1 18 Feb 2019, 17:29 UTC

Logic error in the installer for Intel(R) OpenVINO(TM) 2018 R3 and before for Linux may allow a privileged user to potentially enable information disclosure via local access.

CVE-2019-0112 intel vulnerability CVSS: 2.1 18 Feb 2019, 17:29 UTC

Improper flow control in crypto routines for Intel(R) Data Center Manager SDK before version 5.0.2 may allow a privileged user to potentially enable a denial of service via local access.

CVE-2019-0111 intel vulnerability CVSS: 2.1 18 Feb 2019, 17:29 UTC

Improper file permissions for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2019-0110 intel vulnerability CVSS: 2.1 18 Feb 2019, 17:29 UTC

Insufficient key management for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2019-0109 intel vulnerability CVSS: 4.6 18 Feb 2019, 17:29 UTC

Improper folder permissions in Intel(R) Data Center Manager SDK before version 5.0.2 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-0108 intel vulnerability CVSS: 2.1 18 Feb 2019, 17:29 UTC

Improper file permissions for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an authenticated user to potentially enable disclosure of information via local access.

CVE-2019-0107 intel vulnerability CVSS: 4.6 18 Feb 2019, 17:29 UTC

Insufficient user prompt in install routine for Intel(R) Data Center Manager SDK before version 5.0.2 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2019-0106 intel vulnerability CVSS: 4.6 18 Feb 2019, 17:29 UTC

Insufficient run protection in install routine for Intel(R) Data Center Manager SDK before version 5.0.2 may allow a privileged user to potentially enable escalation of privilege via local access.

CVE-2019-0105 intel vulnerability CVSS: 4.6 18 Feb 2019, 17:29 UTC

Insufficient file permissions checking in install routine for Intel(R) Data Center Manager SDK before version 5.0.2 may allow authenticated user to potentially enable escalation of privilege via local access.

CVE-2019-0104 intel vulnerability CVSS: 2.1 18 Feb 2019, 17:29 UTC

Insufficient file protection in uninstall routine for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2019-0103 intel vulnerability CVSS: 2.1 18 Feb 2019, 17:29 UTC

Insufficient file protection in install routine for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2019-0102 intel vulnerability CVSS: 5.8 18 Feb 2019, 17:29 UTC

Insufficient session authentication in web server for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

CVE-2019-0101 intel vulnerability CVSS: 7.5 18 Feb 2019, 17:29 UTC

Authentication bypass in the Intel Unite(R) solution versions 3.2 through 3.3 may allow an unauthenticated user to potentially enable escalation of privilege to the Intel Unite(R) Solution administrative portal via network access.

CVE-2018-12159 intel vulnerability CVSS: 2.1 18 Feb 2019, 17:29 UTC

Buffer overflow in the command-line interface for Intel(R) PROSet Wireless v20.50 and before may allow an authenticated user to potentially enable denial of service via local access.

CVE-2018-3703 intel vulnerability CVSS: 4.6 10 Jan 2019, 20:29 UTC

Improper directory permissions in the installer for the Intel(R) SSD Data Center Tool for Windows before v3.0.17 may allow authenticated users to potentially enable an escalation of privilege via local access.

CVE-2018-18098 intel vulnerability CVSS: 4.4 10 Jan 2019, 20:29 UTC

Improper file verification in install routine for Intel(R) SGX SDK and Platform Software for Windows before 2.2.100 may allow an escalation of privilege via local access.

CVE-2018-12177 intel vulnerability CVSS: 4.6 10 Jan 2019, 20:29 UTC

Improper directory permissions in the ZeroConfig service in Intel(R) PROSet/Wireless WiFi Software before version 20.90.0.7 may allow an authorized user to potentially enable escalation of privilege via local access.

CVE-2017-3718 intel vulnerability CVSS: 4.6 10 Jan 2019, 20:29 UTC

Improper setting of device configuration in system firmware for Intel(R) NUC kits may allow a privileged user to potentially enable escalation of privilege via physical access.

CVE-2018-3705 intel vulnerability CVSS: 2.1 14 Dec 2018, 00:29 UTC

Improper directory permissions in the installer for the Intel(R) System Defense Utility (all versions) may allow authenticated users to potentially enable a denial of service via local access.

CVE-2018-3704 intel vulnerability CVSS: 4.6 14 Dec 2018, 00:29 UTC

Improper directory permissions in the installer for the Intel Parallel Studio before 2019 Gold may allow authenticated users to potentially enable an escalation of privilege via local access.

CVE-2018-18097 intel vulnerability CVSS: 4.6 14 Dec 2018, 00:29 UTC

Improper directory permissions in Intel Solid State Drive Toolbox before 3.5.7 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2018-18096 intel vulnerability CVSS: 2.1 14 Dec 2018, 00:29 UTC

Improper memory handling in Intel QuickAssist Technology for Linux (all versions) may allow an authenticated user to potentially enable a denial of service via local access.

CVE-2018-18093 intel vulnerability CVSS: 4.6 14 Dec 2018, 00:29 UTC

Improper file permissions in the installer for Intel VTune Amplifier 2018 Update 3 and before may allow unprivileged user to potentially gain privileged access via local access.

CVE-2018-12206 intel vulnerability CVSS: 2.1 14 Dec 2018, 00:29 UTC

Improper configuration of hardware access in Intel QuickAssist Technology for Linux (all versions) may allow an authenticated user to potentially enable a denial of service via local access.

CVE-2018-12155 intel vulnerability CVSS: 2.1 05 Dec 2018, 21:29 UTC

Data leakage in cryptographic libraries for Intel IPP before 2019 update1 release may allow an authenticated user to potentially enable information disclosure via local access.

CVE-2018-3699 intel vulnerability CVSS: 4.3 14 Nov 2018, 14:29 UTC

Cross-site scripting in the Intel RAID Web Console v3 for Windows may allow an unauthenticated user to elevate privilege via remote access.

CVE-2018-3698 intel vulnerability CVSS: 4.6 14 Nov 2018, 14:29 UTC

Improper file permissions in the installer for the Intel Ready Mode Technology may allow an unprivileged user to potentially gain privileged access via local access.

CVE-2018-3697 intel vulnerability CVSS: 4.6 14 Nov 2018, 14:29 UTC

Improper directory permissions in the installer for the Intel Media Server Studio may allow unprivileged users to potentially enable an escalation of privilege via local access.

CVE-2018-3696 intel vulnerability CVSS: 2.1 14 Nov 2018, 14:29 UTC

Authentication bypass in the Intel RAID Web Console 3 for Windows before 4.186 may allow an unprivileged user to potentially gain administrative privileges via local access.

CVE-2018-3635 intel vulnerability CVSS: 4.6 14 Nov 2018, 14:29 UTC

Insufficient input validation in installer in Intel Rapid Store Technology (RST) before version 16.7 may allow an unprivileged user to potentially elevate privileges or cause an installer denial of service via local access.

CVE-2018-12174 intel vulnerability CVSS: 4.6 14 Nov 2018, 14:29 UTC

Heap overflow in Intel Trace Analyzer 2018 in Intel Parallel Studio XE 2018 Update 3 may allow an authenticated user to potentially escalate privileges via local access.

CVE-2018-12154 intel vulnerability CVSS: 2.1 15 Oct 2018, 18:29 UTC

Denial of Service in Unified Shader Compiler in Intel Graphics Drivers before 10.18.x.5056 (aka 15.33.x.5056), 10.18.x.5057 (aka 15.36.x.5057) and 20.19.x.5058 (aka 15.40.x.5058) may allow an unprivileged user to potentially create an infinite loop and crash an application via local access.

CVE-2018-12193 intel vulnerability CVSS: 2.1 10 Oct 2018, 18:29 UTC

Insufficient access control in driver stack for Intel QuickAssist Technology for Linux before version 4.2 may allow an unprivileged user to potentially disclose information via local access.

CVE-2018-12173 intel vulnerability CVSS: 7.2 10 Oct 2018, 18:29 UTC

Insufficient access protection in firmware in Intel Server Board, Intel Server System and Intel Compute Module before firmware version 00.01.0014 may allow an unauthenticated attacker to potentially execute arbitrary code resulting in information disclosure, escalation of privilege and/or denial of service via local access.

CVE-2018-12172 intel vulnerability CVSS: 2.1 10 Oct 2018, 18:29 UTC

Improper password hashing in firmware in Intel Server Board (S7200AP,S7200APR) and Intel Compute Module (HNS7200AP, HNS7200AP) may allow a privileged user to potentially disclose firmware passwords via local access.

CVE-2018-12161 intel vulnerability CVSS: 4.3 10 Oct 2018, 18:29 UTC

Insufficient session validation in the webserver component of the Intel Rapid Web Server 3 may allow an unauthenticated user to potentially disclose information via network access.

CVE-2018-12153 intel vulnerability CVSS: 4.9 10 Oct 2018, 18:29 UTC

Denial of Service in Unified Shader Compiler in Intel Graphics Drivers before 10.18.x.5056 (aka 15.33.x.5056), 10.18.x.5057 (aka 15.36.x.5057) and 20.19.x.5058 (aka 15.40.x.5058) may allow an unprivileged user from a virtual machine guest to potentially crash the host system via local access.

CVE-2018-12152 intel vulnerability CVSS: 4.6 10 Oct 2018, 18:29 UTC

Pointer corruption in Unified Shader Compiler in Intel Graphics Drivers before 10.18.x.5056 (aka 15.33.x.5056), 10.18.x.5057 (aka 15.36.x.5057) and 20.19.x.5058 (aka 15.40.x.5058) may allow an unauthenticated remote user to potentially execute arbitrary WebGL code via local access.

CVE-2018-12131 intel vulnerability CVSS: 4.6 10 Oct 2018, 14:29 UTC

Permissions in the driver pack installers for Intel NVMe before version 4.0.0.1007 and Intel RSTe before version 4.7.0.2083 may allow an authenticated user to potentially escalate privilege via local access.

CVE-2018-12169 intel vulnerability CVSS: 4.6 21 Sep 2018, 20:29 UTC

Platform sample code firmware in 4th Generation Intel Core Processor, 5th Generation Intel Core Processor, 6th Generation Intel Core Processor, 7th Generation Intel Core Processor and 8th Generation Intel Core Processor contains a logic error which may allow physical attacker to potentially bypass firmware authentication.

CVE-2018-3686 intel vulnerability CVSS: 4.6 12 Sep 2018, 19:29 UTC

Code injection vulnerability in INTEL-SA-00086 Detection Tool before version 1.2.7.0 may allow a privileged user to potentially execute arbitrary code via local access.

CVE-2018-3679 intel vulnerability CVSS: 8.3 12 Sep 2018, 19:29 UTC

Escalation of privilege in Reference UI in Intel Data Center Manager SDK 5.0 and before may allow an unauthorized remote unauthenticated user to potentially execute code via administrator privileges.

CVE-2018-3669 intel vulnerability CVSS: 7.8 12 Sep 2018, 19:29 UTC

A STOP error (BSoD) in the ibtfltcoex.sys driver for Intel Centrino Wireless N and Intel Centrino Advanced N adapters may allow an unauthenticated user to potentially send a malformed L2CAP Connection Request is sent to the Intel Bluetooth device via the network.

CVE-2018-3659 intel vulnerability CVSS: 4.6 12 Sep 2018, 19:29 UTC

A vulnerability in Intel PTT module in Intel CSME firmware before version 12.0.5 and Intel TXE firmware before version 4.0 may allow an unauthenticated user to potentially disclose information via physical access.

CVE-2018-3658 intel vulnerability CVSS: 5.0 12 Sep 2018, 19:29 UTC

Multiple memory leaks in Intel AMT in Intel CSME firmware versions before 12.0.5 may allow an unauthenticated user with Intel AMT provisioned to potentially cause a partial denial of service via network access.

CVE-2018-3657 intel vulnerability CVSS: 7.2 12 Sep 2018, 19:29 UTC

Multiple buffer overflows in Intel AMT in Intel CSME firmware versions before version 12.0.5 may allow a privileged user to potentially execute arbitrary code with Intel AMT execution privilege via local access.

CVE-2018-3655 intel vulnerability CVSS: 3.6 12 Sep 2018, 19:29 UTC

A vulnerability in a subsystem in Intel CSME before version 11.21.55, Intel Server Platform Services before version 4.0 and Intel Trusted Execution Engine Firmware before version 3.1.55 may allow an unauthenticated user to potentially modify or disclose information via physical access.

CVE-2018-3643 intel vulnerability CVSS: 4.6 12 Sep 2018, 19:29 UTC

A vulnerability in Power Management Controller firmware in systems using specific Intel(R) Converged Security and Management Engine (CSME) before version 11.8.55, 11.11.55, 11.21.55, 12.0.6 or Intel(R) Server Platform Services firmware before version 4.x.04 may allow an attacker with administrative privileges to uncover certain platform secrets via local access or to potentially execute arbitrary code.

CVE-2018-3616 intel vulnerability CVSS: 4.3 12 Sep 2018, 19:29 UTC

Bleichenbacher-style side channel vulnerability in TLS implementation in Intel Active Management Technology before 12.0.5 may allow an unauthenticated user to potentially obtain the TLS session key via the network.

CVE-2018-12176 intel vulnerability CVSS: 7.2 12 Sep 2018, 19:29 UTC

Improper input validation in firmware for Intel NUC Kits may allow a privileged user to potentially execute arbitrary code resulting in information disclosure, escalation of privilege and/or denial of service via local access.

CVE-2018-12175 intel vulnerability CVSS: 4.6 12 Sep 2018, 19:29 UTC

Default install directory permissions in Intel Distribution for Python (IDP) version 2018 may allow an unprivileged user to escalate privileges via local access.

CVE-2018-12171 intel vulnerability CVSS: 7.5 12 Sep 2018, 19:29 UTC

Privilege escalation in Intel Baseboard Management Controller (BMC) firmware before version 1.43.91f76955 may allow an unprivileged user to potentially execute arbitrary code or perform denial of service over the network.

CVE-2018-12168 intel vulnerability CVSS: 7.2 12 Sep 2018, 19:29 UTC

Privilege escalation in file permissions in Intel Computing Improvement Program before version 2.2.0.03942 may allow an authenticated user to potentially execute code as administrator via local access.

CVE-2018-12163 intel vulnerability CVSS: 6.8 12 Sep 2018, 19:29 UTC

A DLL injection vulnerability in the Intel IoT Developers Kit 4.0 installer may allow an authenticated user to potentially escalate privileges using file modification via local access.

CVE-2018-12160 intel vulnerability CVSS: 4.6 12 Sep 2018, 19:29 UTC

DLL injection vulnerability in software installer for Intel Data Center Migration Center Software v3.1 and before may allow an authenticated user to potentially execute code using default directory permissions via local access.

CVE-2018-12151 intel vulnerability CVSS: 2.1 12 Sep 2018, 19:29 UTC

Buffer overflow in installer for Intel Extreme Tuning Utility before 6.4.1.21 may allow an authenticated user to potentially cause a buffer overflow potentially leading to a denial of service via local access.

CVE-2018-12150 intel vulnerability CVSS: 4.6 12 Sep 2018, 19:29 UTC

Escalation of privilege in Installer for Intel Extreme Tuning Utility before 6.4.1.21 may allow an authenticated user to potentially execute code or disclose information as administrator via local access.

CVE-2018-12149 intel vulnerability CVSS: 2.1 12 Sep 2018, 19:29 UTC

Buffer overflow in input handling in Intel Extreme Tuning Utility before 6.4.1.21 may allow an authenticated user to potentially deny service to the application via local access.

CVE-2018-12148 intel vulnerability CVSS: 7.2 12 Sep 2018, 19:29 UTC

Privilege escalation in file permissions in Intel Driver and Support Assistant before 3.5.0.1 may allow an authenticated user to potentially execute code as administrator via local access.

CVE-2018-10932 intel vulnerability CVSS: 3.3 21 Aug 2018, 18:29 UTC

lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is displayed. This may allow an attacker to inject shell control characters into the buffer and impact the behavior of the terminal.

CVE-2018-3646 intel vulnerability CVSS: 4.7 14 Aug 2018, 19:29 UTC

Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access with guest OS privilege via a terminal page fault and a side-channel analysis.

CVE-2018-3620 intel vulnerability CVSS: 4.7 14 Aug 2018, 19:29 UTC

Systems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in the L1 data cache to an attacker with local user access via a terminal page fault and a side-channel analysis.

CVE-2018-3615 intel vulnerability CVSS: 5.4 14 Aug 2018, 19:29 UTC

Systems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of information residing in the L1 data cache from an enclave to an attacker with local user access via a side-channel analysis.

CVE-2018-3650 intel vulnerability CVSS: 4.6 01 Aug 2018, 15:29 UTC

Insufficient Input Validation in Bleach module in INTEL Distribution for Python versions prior to IDP 2018 Update 2 allows unprivileged user to bypass URI sanitization via local vector.

CVE-2017-5692 intel vulnerability CVSS: 2.1 01 Aug 2018, 15:29 UTC

Out-of-bounds read condition in older versions of some Intel Graphics Driver for Windows code branches allows local users to perform a denial of service attack.

CVE-2017-5693 intel vulnerability CVSS: 7.8 31 Jul 2018, 19:29 UTC

Firmware in the Intel Puma 5, 6, and 7 Series might experience resource depletion or timeout, which allows a network attacker to create a denial of service via crafted network traffic.

CVE-2018-3693 intel vulnerability CVSS: 4.7 10 Jul 2018, 21:29 UTC

Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and side-channel analysis.

CVE-2018-3688 intel vulnerability CVSS: 4.6 10 Jul 2018, 21:29 UTC

Unquoted service paths in Intel Quartus Prime Programmer and Tools in versions 15.1 - 18.0 allow a local attacker to potentially execute arbitrary code.

CVE-2018-3687 intel vulnerability CVSS: 4.6 10 Jul 2018, 21:29 UTC

Unquoted service paths in Intel Quartus II Programmer and Tools in versions 11.0 - 15.0 allow a local attacker to potentially execute arbitrary code.

CVE-2018-3684 intel vulnerability CVSS: 4.6 10 Jul 2018, 21:29 UTC

Unquoted service paths in Intel Quartus II in versions 11.0 - 15.0 allow a local attacker to potentially execute arbitrary code.

CVE-2018-3683 intel vulnerability CVSS: 4.6 10 Jul 2018, 21:29 UTC

Unquoted service paths in Intel Quartus Prime in versions 15.1 - 18.0 allow a local attacker to potentially execute arbitrary code.

CVE-2018-3682 intel vulnerability CVSS: 4.6 10 Jul 2018, 21:29 UTC

BMC Firmware in Intel server boards, compute modules, and systems potentially allow an attacker with administrative privileges to make unauthorized read\writes to the SMBUS.

CVE-2018-3668 intel vulnerability CVSS: 4.6 10 Jul 2018, 21:29 UTC

Unquoted service paths in Intel Processor Diagnostic Tool (IPDT) before version 4.1.0.27 allows a local attacker to potentially execute arbitrary code.

CVE-2018-3667 intel vulnerability CVSS: 4.6 10 Jul 2018, 21:29 UTC

Installation tool IPDT (Intel Processor Diagnostic Tool) 4.1.0.24 sets permissions of installed files incorrectly, allowing for execution of arbitrary code and potential privilege escalation.

CVE-2018-3652 intel vulnerability CVSS: 4.6 10 Jul 2018, 21:29 UTC

Existing UEFI setting restrictions for DCI (Direct Connect Interface) in 5th and 6th generation Intel Xeon Processor E3 Family, Intel Xeon Scalable processors, and Intel Xeon Processor D Family allows a limited physical presence attacker to potentially access platform secrets via debug interfaces.

CVE-2018-3632 intel vulnerability CVSS: 7.2 10 Jul 2018, 21:29 UTC

Memory corruption in Intel Active Management Technology in Intel Converged Security Manageability Engine Firmware 6.x / 7.x / 8.x / 9.x / 10.x / 11.0 / 11.5 / 11.6 / 11.7 / 11.10 / 11.20 could be triggered by an attacker with local administrator permission on the system.

CVE-2018-3629 intel vulnerability CVSS: 3.3 10 Jul 2018, 21:29 UTC

Buffer overflow in event handler in Intel Active Management Technology in Intel Converged Security Manageability Engine Firmware 3.x, 4.x, 5.x, 6.x, 7.x, 8.x, 9.x, 10.x, and 11.x may allow an attacker to cause a denial of service via the same subnet.

CVE-2018-3628 intel vulnerability CVSS: 8.3 10 Jul 2018, 21:29 UTC

Buffer overflow in HTTP handler in Intel Active Management Technology in Intel Converged Security Manageability Engine Firmware 3.x, 4.x, 5.x, 6.x, 7.x, 8.x, 9.x, 10.x, and 11.x may allow an attacker to execute arbitrary code via the same subnet.

CVE-2018-3627 intel vulnerability CVSS: 4.6 10 Jul 2018, 21:29 UTC

Logic bug in Intel Converged Security Management Engine 11.x may allow an attacker to execute arbitrary code via local privileged access.

CVE-2018-3619 intel vulnerability CVSS: 2.1 10 Jul 2018, 21:29 UTC

Information disclosure vulnerability in storage media in systems with Intel Optane memory module with Whole Disk Encryption may allow an attacker to recover data via physical access.

CVE-2017-5704 intel vulnerability CVSS: 2.1 10 Jul 2018, 21:29 UTC

Platform sample code firmware included with 4th Gen Intel Core Processor, 5th Gen Intel Core Processor, 6th Gen Intel Core Processor, and 7th Gen Intel Core Processor potentially exposes password information in memory to a local attacker with administrative privileges.

CVE-2018-3665 intel vulnerability CVSS: 4.7 21 Jun 2018, 20:29 UTC

System software utilizing Lazy FP state restore technique on systems using Intel Core-based microprocessors may potentially allow a local process to infer data from another process through a speculative execution side channel.

CVE-2018-3691 intel vulnerability CVSS: 1.9 05 Jun 2018, 21:29 UTC

Some implementations in Intel Integrated Performance Primitives Cryptography Library before version 2018 U3.1 do not properly ensure constant execution time.

CVE-2018-3640 intel vulnerability CVSS: 4.7 22 May 2018, 12:29 UTC

Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a.

CVE-2018-3639 intel vulnerability CVSS: 2.1 22 May 2018, 12:29 UTC

Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.

CVE-2018-3661 intel vulnerability CVSS: 2.1 15 May 2018, 14:29 UTC

Buffer overflow in Intel system Configuration utilities selview.exe and syscfg.exe before version 14 build 11 allows a local user to crash these services potentially resulting in a denial of service.

CVE-2018-3634 intel vulnerability CVSS: 4.9 15 May 2018, 14:29 UTC

Parameter corruption in NDIS filter driver in Intel Online Connect Access 1.9.22.0 allows an attacker to cause a denial of service via local access.

CVE-2018-3611 intel vulnerability CVSS: 4.0 15 May 2018, 14:29 UTC

Bounds check vulnerability in User Mode Driver in Intel Graphics Driver 15.40.x.4 and 21.20.x.x allows unprivileged user to cause a denial of service via local access.

CVE-2018-3649 intel vulnerability CVSS: 4.6 10 May 2018, 22:29 UTC

DLL injection vulnerability in the installation executables (Autorun.exe and Setup.exe) for Intel's wireless drivers and related software in Intel Dual Band Wireless-AC, Tri-Band Wireless-AC and Wireless-AC family of products allows a local attacker to cause escalation of privilege via remote code execution.

CVE-2018-3612 intel vulnerability CVSS: 7.2 10 May 2018, 22:29 UTC

Intel NUC kits with insufficient input validation in system firmware, potentially allows a local attacker to elevate privileges to System Management Mode (SMM).

CVE-2018-3624 intel vulnerability CVSS: 5.4 05 Apr 2018, 16:29 UTC

Buffer overflow in ETWS processing module Intel XMM71xx, XMM72xx, XMM73xx, XMM74xx and Sofia 3G/R allows remote attacker to potentially execute arbitrary code via an adjacent network.

CVE-2018-3645 intel vulnerability CVSS: 4.6 03 Apr 2018, 21:29 UTC

Escalation of privilege in all versions of the Intel Remote Keyboard allows a local attacker to inject keystrokes into another remote keyboard session.

CVE-2018-3641 intel vulnerability CVSS: 7.5 03 Apr 2018, 21:29 UTC

Escalation of privilege in all versions of the Intel Remote Keyboard allows a network attacker to inject keystrokes as a local user.

CVE-2018-3638 intel vulnerability CVSS: 7.2 03 Apr 2018, 21:29 UTC

Escalation of privilege in all versions of the Intel Remote Keyboard allows an authorized local attacker to execute arbitrary code as a privileged user.

CVE-2017-5703 intel vulnerability CVSS: 3.6 03 Apr 2018, 21:29 UTC

Configuration of SPI Flash in platforms based on multiple Intel platforms allow a local attacker to alter the behavior of the SPI flash potentially leading to a Denial of Service.

CVE-2018-3689 intel vulnerability CVSS: 2.1 03 Apr 2018, 16:29 UTC

AESM daemon in Intel Software Guard Extensions Platform Software Component for Linux before 2.1.102 can effectively be disabled by a local attacker creating a denial of services like remote attestation provided by the AESM.

CVE-2018-9056 intel vulnerability CVSS: 4.7 27 Mar 2018, 17:29 UTC

Systems with microprocessors utilizing speculative execution may allow unauthorized disclosure of information to an attacker with local user access via a side-channel attack on the directional branch predictor, as demonstrated by a pattern history table (PHT), aka BranchScope.

CVE-2014-2312 intel vulnerability CVSS: 6.6 26 Mar 2018, 18:29 UTC

The main function in android_main.cpp in thermald allows local users to write to arbitrary files via a symlink attack on /tmp/thermald.pid.

CVE-2018-3626 intel vulnerability CVSS: 1.9 20 Mar 2018, 20:29 UTC

Edger8r tool in the Intel SGX SDK before version 2.1.2 (Linux) and 1.9.6 (Windows) may generate code that is susceptible to a side channel potentially allowing a local user to access unauthorized information.

CVE-2017-5736 intel vulnerability CVSS: 7.2 20 Mar 2018, 20:29 UTC

An elevation of privilege in Intel Software Guard Extensions Platform Software Component before 1.9.105.42329 allows a local attacker to execute arbitrary code as administrator.

CVE-2017-5727 intel vulnerability CVSS: 7.2 02 Feb 2018, 15:29 UTC

Pointer dereference in subsystem in Intel Graphics Driver 15.40.x.x, 15.45.x.x, 15.46.x.x allows unprivileged user to elevate privileges via local access.

CVE-2015-1142857 intel vulnerability CVSS: 5.0 23 Jan 2018, 14:29 UTC

On multiple SR-IOV cars it is possible for VF's assigned to guests to send ethernet flow control pause frames via the PF. This includes Linux kernel ixgbe driver before commit f079fa005aae08ee0e1bc32699874ff4f02e11c1, the Linux Kernel i40e/i40evf driver before e7358f54a3954df16d4f87e3cad35063f1c17de5 and the DPDK before commit 3f12b9f23b6499ff66ec8b0de941fb469297e5d0, additionally Multiple vendor NIC firmware is affected.

CVE-2017-5696 intel vulnerability CVSS: 6.8 18 Jan 2018, 01:29 UTC

Untrusted search path in Intel Graphics Driver 15.40.x.x, 15.45.x.x, and 21.20.x.x allows unprivileged user to elevate privileges via local access.

CVE-2018-3610 intel vulnerability CVSS: 3.6 09 Jan 2018, 21:29 UTC

SEMA driver in Intel Driver and Support Assistant before version 3.1.1 allows a local attacker the ability to read and writing to Memory Status registers potentially allowing information disclosure or a denial of service condition.

CVE-2017-5754 intel vulnerability CVSS: 4.7 04 Jan 2018, 13:29 UTC

Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.

CVE-2017-5753 intel vulnerability CVSS: 4.7 04 Jan 2018, 13:29 UTC

Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.

CVE-2017-5715 intel vulnerability CVSS: 1.9 04 Jan 2018, 13:29 UTC

Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.

CVE-2017-5717 intel vulnerability CVSS: 7.2 12 Dec 2017, 20:29 UTC

Type Confusion in Content Protection HECI Service in Intel Graphics Driver allows unprivileged user to elevate privileges via local access.

CVE-2017-5729 intel vulnerability CVSS: 5.8 21 Nov 2017, 14:29 UTC

Frame replay vulnerability in Wi-Fi subsystem in Intel Dual-Band and Tri-Band Wireless-AC Products allows remote attacker to replay frames via channel-based man-in-the-middle.

CVE-2017-5719 intel vulnerability CVSS: 7.5 21 Nov 2017, 14:29 UTC

A vulnerability in the Intel Deep Learning Training Tool Beta 1 allows a network attacker to remotely execute code as a local user.

CVE-2017-5712 intel vulnerability CVSS: 9.0 21 Nov 2017, 14:29 UTC

Buffer overflow in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allows attacker with remote Admin access to the system to execute arbitrary code with AMT execution privilege.

CVE-2017-5711 intel vulnerability CVSS: 7.2 21 Nov 2017, 14:29 UTC

Multiple buffer overflows in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code with AMT execution privilege.

CVE-2017-5710 intel vulnerability CVSS: 7.2 21 Nov 2017, 14:29 UTC

Multiple privilege escalations in kernel in Intel Trusted Execution Engine Firmware 3.0 allows unauthorized process to access privileged content via unspecified vector.

CVE-2017-5709 intel vulnerability CVSS: 7.2 21 Nov 2017, 14:29 UTC

Multiple privilege escalations in kernel in Intel Server Platform Services Firmware 4.0 allows unauthorized process to access privileged content via unspecified vector.

CVE-2017-5708 intel vulnerability CVSS: 7.2 21 Nov 2017, 14:29 UTC

Multiple privilege escalations in kernel in Intel Manageability Engine Firmware 11.0/11.5/11.6/11.7/11.10/11.20 allow unauthorized process to access privileged content via unspecified vector.

CVE-2017-5707 intel vulnerability CVSS: 7.2 21 Nov 2017, 14:29 UTC

Multiple buffer overflows in kernel in Intel Trusted Execution Engine Firmware 3.0 allow attacker with local access to the system to execute arbitrary code.

CVE-2017-5706 intel vulnerability CVSS: 7.2 21 Nov 2017, 14:29 UTC

Multiple buffer overflows in kernel in Intel Server Platform Services Firmware 4.0 allow attacker with local access to the system to execute arbitrary code.

CVE-2017-5705 intel vulnerability CVSS: 7.2 21 Nov 2017, 14:29 UTC

Multiple buffer overflows in kernel in Intel Manageability Engine Firmware 11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code.

CVE-2017-5738 intel vulnerability CVSS: 6.4 16 Nov 2017, 14:29 UTC

Escalation of privilege vulnerability in admin portal for Intel Unite App versions 3.1.32.12, 3.1.41.18 and 3.1.45.26 allows an attacker with network access to cause a denial of service and/or information disclosure.

CVE-2017-5722 intel vulnerability CVSS: 4.4 11 Oct 2017, 00:29 UTC

Incorrect policy enforcement in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows attackers with local or physical access to bypass enforcement of integrity protections via manipulation of firmware storage.

CVE-2017-5721 intel vulnerability CVSS: 4.4 11 Oct 2017, 00:29 UTC

Insufficient input validation in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows local attackers to execute arbitrary code via manipulation of memory.

CVE-2017-5701 intel vulnerability CVSS: 4.4 11 Oct 2017, 00:29 UTC

Insecure platform configuration in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows an attacker with physical presence to run arbitrary code via unauthorized firmware modification during BIOS Recovery.

CVE-2017-5700 intel vulnerability CVSS: 7.2 11 Oct 2017, 00:29 UTC

Insufficient protection of password storage in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows local attackers to bypass Administrator and User passwords via access to password storage.

CVE-2017-5698 intel vulnerability CVSS: 4.9 05 Sep 2017, 19:29 UTC

Intel Active Management Technology, Intel Standard Manageability, and Intel Small Business Technology firmware versions 11.0.25.3001 and 11.0.26.3000 anti-rollback will not prevent upgrading to firmware version 11.6.x.1xxx which is vulnerable to CVE-2017-5689 and can be performed by a local user with administrative privileges.

CVE-2017-12865 intel vulnerability CVSS: 7.5 29 Aug 2017, 16:29 UTC

Stack-based buffer overflow in "dnsproxy.c" in connman 1.34 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted response query string passed to the "name" variable.

CVE-2015-2291 intel vulnerability CVSS: 7.2 09 Aug 2017, 18:29 UTC

(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call.

CVE-2017-5695 intel vulnerability CVSS: 2.1 09 Aug 2017, 14:29 UTC

Data corruption vulnerability in firmware in Intel Solid-State Drive Consumer, Professional, Embedded, Data Center affected firmware versions LSBG200, LSF031C, LSF036C, LBF010C, LSBG100, LSF031C, LSF036C, LBF010C, LSF031P, LSF036P, LBF010P, LSF031P, LSF036P, LBF010P, LSMG200, LSF031E, LSF036E, LSMG100, LSF031E, LSF036E, LSDG200, LSF031D, LSF036D allows local users to cause a denial of service via unspecified vectors.

CVE-2017-5694 intel vulnerability CVSS: 4.9 09 Aug 2017, 14:29 UTC

Data corruption vulnerability in firmware in Intel Solid-State Drive Professional PSF104P, PSF109P allows local users to cause a denial of service via unspecified vectors.

CVE-2017-5691 intel vulnerability CVSS: 9.3 26 Jul 2017, 15:29 UTC

Incorrect check in Intel processors from 6th and 7th Generation Intel Core Processor Families, Intel Xeon E3-1500M v5 and v6 Product Families, and Intel Xeon E3-1200 v5 and v6 Product Families allows compromised system firmware to impact SGX security via incorrect early system state.

CVE-2017-5697 intel vulnerability CVSS: 4.3 14 Jun 2017, 12:29 UTC

Insufficient clickjacking protection in the Web User Interface of Intel AMT firmware versions before 9.1.40.1000, 9.5.60.1952, 10.0.50.1004, 11.0.0.1205, and 11.6.25.1129 potentially allowing a remote attacker to hijack users web clicks via attacker's crafted web page.

CVE-2017-5688 intel vulnerability CVSS: 7.2 31 May 2017, 14:29 UTC

There is an escalation of privilege vulnerability in the Intel Solid State Drive Toolbox versions before 3.4.5 which allow a local administrative attacker to load and execute arbitrary code.

CVE-2017-5689 intel vulnerability CVSS: 10.0 02 May 2017, 14:59 UTC

An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).

CVE-2017-5683 intel vulnerability CVSS: 7.2 04 Apr 2017, 14:59 UTC

Privilege escalation in IntelHAXM.sys driver in the Intel Hardware Accelerated Execution Manager before version 6.0.6 allows a local user to gain system level access.

CVE-2017-5686 intel vulnerability CVSS: 2.1 03 Apr 2017, 21:59 UTC

The BIOS in Intel NUC systems based on 6th Gen Intel Core processors prior to version SY0059 may allow may allow an attacker with physical access to the system to gain access to personal information.

CVE-2017-5685 intel vulnerability CVSS: 2.1 03 Apr 2017, 21:59 UTC

The BIOS in Intel NUC systems based on 6th Gen Intel Core processors prior to version KY0045 may allow may allow an attacker with physical access to the system to gain access to personal information.

CVE-2017-5684 intel vulnerability CVSS: 2.1 03 Apr 2017, 21:59 UTC

The BIOS in Intel Compute Stick systems based on 6th Gen Intel Core processors prior to version CC047 may allow an attacker with physical access to the system to gain access to personal information.

CVE-2017-5681 intel vulnerability CVSS: 5.0 07 Mar 2017, 18:59 UTC

The RSA-CRT implementation in the Intel QuickAssist Technology (QAT) Engine for OpenSSL versions prior to 0.5.19 may allow remote attackers to obtain private RSA keys by conducting a Lenstra side-channel attack.

CVE-2017-5682 intel vulnerability CVSS: 9.3 28 Feb 2017, 19:59 UTC

Intel PSET Application Install wrapper of Intel Parallel Studio XE, Intel System Studio, Intel VTune Amplifier, Intel Inspector, Intel Advisor, Intel MPI Library, Intel Trace Analyzer and Collector, Intel Integrated Performance Primitives, Cryptography for Intel Integrated Performance Primitives, Intel Math Kernel Library, Intel Data Analytics Acceleration Library, and Intel Threading Building Blocks before 2017 Update 2 allows an attacker to launch a process with escalated privileges.

CVE-2016-8105 intel vulnerability CVSS: 6.1 27 Feb 2017, 18:59 UTC

Drivers for the Intel Ethernet Controller X710 and Intel Ethernet Controller XL710 families before version 22.0 are vulnerable to a denial of service in certain layer 2 network configurations.

CVE-2017-5927 intel vulnerability CVSS: 5.0 27 Feb 2017, 07:59 UTC

Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern ARM processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.

CVE-2017-5926 intel vulnerability CVSS: 5.0 27 Feb 2017, 07:59 UTC

Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.

CVE-2017-5925 intel vulnerability CVSS: 5.0 27 Feb 2017, 07:59 UTC

Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.

CVE-2016-8106 intel vulnerability CVSS: 4.3 09 Jan 2017, 21:59 UTC

A Denial of Service in Intel Ethernet Controller's X710/XL710 with Non-Volatile Memory Images before version 5.05 allows a remote attacker to stop the controller from processing network traffic working under certain network use conditions.

CVE-2016-5647 intel vulnerability CVSS: 4.6 13 Dec 2016, 18:59 UTC

The igdkmd64 module in the Intel Graphics Driver through 15.33.42.435, 15.36.x through 15.36.30.4385, and 15.40.x through 15.40.4404 on Windows allows local users to cause a denial of service (crash) or gain privileges via a crafted D3DKMTEscape request.

CVE-2016-8104 intel vulnerability CVSS: 2.1 08 Dec 2016, 17:59 UTC

Buffer overflow in Intel PROSet/Wireless Software and Drivers in versions before 19.20.3 allows a local user to crash iframewrk.exe causing a potential denial of service.

CVE-2016-8103 intel vulnerability CVSS: 6.8 08 Dec 2016, 17:59 UTC

SMM call out in all Intel Branded NUC Kits allows a local privileged user to access the System Management Mode and take full control of the platform.

CVE-2016-8102 intel vulnerability CVSS: 7.2 08 Dec 2016, 17:59 UTC

Unquoted service path vulnerability in Intel Wireless Bluetooth Drivers 16.x, 17.x, and before 18.1.1607.3129 allows local users to launch processes with elevated privileges.

CVE-2016-8101 intel vulnerability CVSS: 7.2 10 Oct 2016, 16:59 UTC

The updater subsystem in Intel SSD Toolbox before 3.3.7 allows local users to gain privileges via unspecified vectors.

CVE-2016-8100 intel vulnerability CVSS: 2.1 10 Oct 2016, 16:59 UTC

Intel Integrated Performance Primitives (aka IPP) Cryptography before 9.0.4 makes it easier for local users to discover RSA private keys via a side-channel attack.

CVE-2016-5672 intel vulnerability CVSS: 5.8 01 Aug 2016, 02:59 UTC

Intel Crosswalk before 19.49.514.5, 20.x before 20.50.533.11, 21.x before 21.51.546.0, and 22.x before 22.51.549.0 interprets a user's acceptance of one invalid X.509 certificate to mean that all invalid X.509 certificates should be accepted without prompting, which makes it easier for man-in-the-middle attackers to spoof SSL servers and obtain sensitive information via a crafted certificate.

CVE-2016-1349 intel vulnerability CVSS: 7.8 26 Mar 2016, 01:59 UTC

The Smart Install client implementation in Cisco IOS 12.2, 15.0, and 15.2 and IOS XE 3.2 through 3.7 allows remote attackers to cause a denial of service (device reload) via crafted image list parameters in a Smart Install packet, aka Bug ID CSCuv45410.

CVE-2016-1493 intel vulnerability CVSS: 7.6 29 Jan 2016, 20:59 UTC

Intel Driver Update Utility before 2.4 retrieves driver updates in cleartext, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted file.

CVE-2014-8272 intel vulnerability CVSS: 5.0 19 Dec 2014, 11:59 UTC

The IPMI 1.5 functionality in Dell iDRAC6 modular before 3.65, iDRAC6 monolithic before 1.98, and iDRAC7 before 1.57.57 does not properly select session ID values, which makes it easier for remote attackers to execute arbitrary commands via a brute-force attack.

CVE-2014-3735 intel vulnerability CVSS: 4.3 19 May 2014, 14:55 UTC

ir41_32.ax 4.51.16.3 for Intel Indeo Video 4.5 allows remote attackers to cause a denial of service (crash) via a crafted .avi file.

CVE-2014-2536 intel vulnerability CVSS: 4.3 18 Mar 2014, 17:04 UTC

Directory traversal vulnerability in McAfee Cloud Identity Manager 3.0, 3.1, and 3.5.1, McAfee Cloud Single Sign On (MCSSO) before 4.0.1, and Intel Expressway Cloud Access 360-SSO 2.1 and 2.5 allows remote authenticated users to read an unspecified file containing a hash of the administrator password via unknown vectors.

CVE-2013-5740 intel vulnerability CVSS: 6.9 12 Sep 2013, 18:37 UTC

Unspecified vulnerability in the Intel Trusted Execution Technology (TXT) SINIT Authenticated Code Modules (ACM) before 1.2, as used by the Intel QM77, QS77, Q77 Express, C216, Q67 Express, C202, C204, and C206 chipsets and Mobile Intel QM67 and QS67 chipsets, when the measured launch environment (MLE) is invoked, allows local users to bypass the Trusted Execution Technology protection mechanism and perform other unspecified SINIT ACM functions via unspecified vectors.

CVE-2013-4219 intel vulnerability CVSS: 7.5 25 Aug 2013, 03:27 UTC

Multiple integer overflows in the Intel WiMAX Network Service through 1.5.2 for Intel Wireless WiMAX Connection 2400 devices allow remote attackers to cause a denial of service (component crash) or possibly execute arbitrary code via an L5 connection with a crafted PDU value that triggers a heap-based buffer overflow within (1) L5SocketsDispatcher.c or (2) L5Connector.c.

CVE-2013-4218 intel vulnerability CVSS: 2.1 25 Aug 2013, 03:27 UTC

The InitMethodAndPassword function in InfraStack/OSAgnostic/WiMax/Agents/Supplicant/Source/SupplicantAgent.c in the Intel WiMAX Network Service through 1.5.2 for Intel Wireless WiMAX Connection 2400 devices uses the same RSA private key in supplicant_key.pem on all systems, which allows local users to obtain sensitive information via unspecified decryption operations.

CVE-2013-4217 intel vulnerability CVSS: 2.1 25 Aug 2013, 03:27 UTC

The OSAL_Crypt_SetEncryptedPassword function in InfraStack/OSDependent/Linux/OSAL/Services/wimax_osal_crypt_services.c in the OSAL crypt module in the Intel WiMAX Network Service through 1.5.2 for Intel Wireless WiMAX Connection 2400 devices logs a cleartext password during certain attempts to set a password, which allows local users to obtain sensitive information by reading a log file.

CVE-2013-4216 intel vulnerability CVSS: 2.1 25 Aug 2013, 03:27 UTC

The Trace_OpenLogFile function in InfraStack/OSDependent/Linux/InfraStackModules/TraceModule/TraceModule.c in the Trace module in the Intel WiMAX Network Service through 1.5.2 for Intel Wireless WiMAX Connection 2400 devices uses world-writable permissions for wimaxd.log, which allows local users to cause a denial of service (data corruption) by modifying this file.

CVE-2013-4786 intel vulnerability CVSS: 7.8 08 Jul 2013, 22:55 UTC

The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC.

CVE-2012-6459 intel vulnerability CVSS: 4.3 01 Jan 2013, 15:55 UTC

ConnMan 1.3 on Tizen continues to list the bluetooth service after offline mode has been enabled, which might allow remote attackers to obtain sensitive information via Bluetooth packets.

CVE-2011-5174 intel vulnerability CVSS: 7.2 15 Sep 2012, 17:55 UTC

Buffer overflow in Intel Trusted Execution Technology (TXT) SINIT Authenticated Code Modules (ACM) in Intel Q67 Express, C202, C204, C206 Chipsets, and Mobile Intel QM67, and QS67 Chipset before 2nd_gen_i5_i7_SINIT_51.BIN Express; Intel Q57, 3450 Chipsets and Mobile Intel QM57 and QS57 Express Chipset before i5_i7_DUAL_SINIT_51.BIN and i7_QUAD_SINIT_51.BIN; Mobile Intel GM45, GS45, and PM45 Express Chipset before GM45_GS45_PM45_SINIT_51.BIN; Intel Q35 Express Chipsets before Q35_SINIT_51.BIN; and Intel 5520, 5500, X58, and 7500 Chipsets before SINIT ACM 1.1 allows local users to bypass the Trusted Execution Technology protection mechanism and perform other unspecified SINIT ACM functions via unspecified vectors.

CVE-2010-5269 intel vulnerability CVSS: 6.9 07 Sep 2012, 10:32 UTC

Untrusted search path vulnerability in tbb.dll in Intel Threading Building Blocks (TBB) 2.2.013 allows local users to gain privileges via a Trojan horse tbbmalloc.dll file in the current working directory, as demonstrated by a directory that contains a .pbk file. NOTE: some of these details are obtained from third party information.

CVE-2011-2604 intel vulnerability CVSS: 7.1 30 Jun 2011, 15:55 UTC

The Intel G41 driver 6.14.10.5355 on Windows XP SP3 allows remote attackers to cause a denial of service (system crash) via a crafted web page that is visited with Google Chrome or Mozilla Firefox, as demonstrated by the lots-of-polys-example.html test page in the Khronos WebGL SDK.

CVE-2010-3268 intel vulnerability CVSS: 5.0 22 Dec 2010, 21:00 UTC

The GetStringAMSHandler function in prgxhndl.dll in hndlrsvc.exe in the Intel Alert Handler service (aka Symantec Intel Handler service) in Intel Alert Management System (AMS), as used in Symantec Antivirus Corporate Edition 10.1.4.4010 on Windows 2000 SP4 and Symantec Endpoint Protection before 11.x, does not properly validate the CommandLine field of an AMS request, which allows remote attackers to cause a denial of service (application crash) via a crafted request.

CVE-2010-0560 intel vulnerability CVSS: 4.6 08 Feb 2010, 21:30 UTC

Unspecified vulnerability in the BIOS in Intel Desktop Board DB, DG, DH, DP, and DQ Series allows local administrators to execute arbitrary code in System Management Mode (SSM) via unknown attack vectors.

CVE-2009-4419 intel vulnerability CVSS: 7.2 24 Dec 2009, 17:30 UTC

Intel Q35, GM45, PM45 Express, Q45, and Q43 Express chipsets in the SINIT Authenticated Code Module (ACM), which allows local users to bypass the Trusted Execution Technology protection mechanism and gain privileges by modifying the MCHBAR register to point to an attacker-controlled region, which prevents the SENTER instruction from properly applying VT-d protection while an MLE is being loaded.

CVE-2008-7096 intel vulnerability CVSS: 6.9 27 Aug 2009, 20:30 UTC

Intel Desktop and Intel Mobile Boards with BIOS firmware DQ35JO, DQ35MP, DP35DP, DG33FB, DG33BU, DG33TL, MGM965TW, D945GCPE, and DX38BT allows local administrators with ring 0 privileges to gain additional privileges and modify code that is running in System Management Mode, or access hypervisory memory as demonstrated at Black Hat 2008 by accessing certain remapping registers in Xen 3.3.

CVE-2009-1385 intel vulnerability CVSS: 7.8 04 Jun 2009, 16:30 UTC

Integer underflow in the e1000_clean_rx_irq function in drivers/net/e1000/e1000_main.c in the e1000 driver in the Linux kernel before 2.6.30-rc8, the e1000e driver in the Linux kernel, and Intel Wired Ethernet (aka e1000) before 7.5.5 allows remote attackers to cause a denial of service (panic) via a crafted frame size.

CVE-2009-0066 intel vulnerability CVSS: 7.6 07 Jan 2009, 19:30 UTC

Multiple unspecified vulnerabilities in Intel system software for Trusted Execution Technology (TXT) allow attackers to bypass intended loader integrity protections, as demonstrated by exploitation of tboot. NOTE: as of 20090107, the only disclosure is a vague pre-advisory with no actionable information. However, because it is from a well-known researcher, it is being assigned a CVE identifier for tracking purposes.

CVE-2008-3635 intel vulnerability CVSS: 9.3 11 Sep 2008, 01:13 UTC

Stack-based buffer overflow in QuickTimeInternetExtras.qtx in an unspecified third-party Indeo v3.2 (aka IV32) codec for QuickTime, when used with Apple QuickTime before 7.5.5 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.

CVE-2008-3900 intel vulnerability CVSS: 2.1 03 Sep 2008, 14:12 UTC

Intel firmware PE94510M.86A.0050.2007.0710.1559 stores pre-boot authentication passwords in the BIOS Keyboard buffer and does not clear this buffer after use, which allows local users to obtain sensitive information by reading the physical memory locations associated with this buffer.

CVE-2008-2707 intel vulnerability CVSS: 7.8 16 Jun 2008, 18:41 UTC

Unspecified vulnerability in the e1000g driver in Sun Solaris 10 and OpenSolaris before snv_93 allows remote attackers to cause a denial of service (network connectivity loss) via unknown vectors.

CVE-2007-5938 intel vulnerability CVSS: 5.0 06 Dec 2007, 15:46 UTC

The iwl_set_rate function in compatible/iwl3945-base.c in iwlwifi 1.1.21 and earlier dereferences an iwl_get_hw_mode return value without checking for NULL, which might allow remote attackers to cause a denial of service (kernel panic) via unspecified vectors during module initialization.

CVE-2006-7215 intel vulnerability CVSS: 2.1 03 Jul 2007, 21:30 UTC

The Intel Core 2 Extreme processor X6800 and Core 2 Duo desktop processor E6000 and E4000 incorrectly set the memory page Access (A) bit for a page in certain circumstances involving proximity of the code segment limit to the end of a code page, which has unknown impact and attack vectors on certain operating systems other than OpenBSD, aka AI90.

CVE-2007-1307 intel vulnerability CVSS: 10.0 07 Mar 2007, 00:19 UTC

Unspecified vulnerability in Lenovo Intel PRO/1000 LAN adapter before Build 135400, as used on IBM Lenovo ThinkPad systems, has unknown impact and attack vectors.

CVE-2007-0686 intel vulnerability CVSS: 7.1 03 Feb 2007, 01:28 UTC

The Intel 2200BG 802.11 Wireless Mini-PCI driver 9.0.3.9 (w29n51.sys) allows remote attackers to cause a denial of service (system crash) via crafted disassociation packets, which triggers memory corruption of "internal kernel structures," a different vulnerability than CVE-2006-6651. NOTE: this issue might overlap CVE-2006-3992.

CVE-2007-0661 intel vulnerability CVSS: 5.4 01 Feb 2007, 22:28 UTC

Intel Enterprise Southbridge 2 Baseboard Management Controller (BMC), Intel Server Boards 5000XAL, S5000PAL, S5000PSL, S5000XVN, S5000VCL, S5000VSA, SC5400RA, and OEM Firmware for Intel Enterprise Southbridge Baseboard Management Controller before 20070119, when Intelligent Platform Management Interface (IPMI) is enabled, allow remote attackers to connect and issue arbitrary IPMI commands, possibly triggering a denial of service.

CVE-2006-6651 intel vulnerability CVSS: 6.8 20 Dec 2006, 02:28 UTC

Race condition in W29N51.SYS in the Intel 2200BG wireless driver 9.0.3.9 allows remote attackers to cause memory corruption and execute arbitrary code via a series of crafted beacon frames. NOTE: some details are obtained solely from third party information.

CVE-2006-4022 intel vulnerability CVSS: 4.6 09 Aug 2006, 00:04 UTC

Intel 2100 PRO/Wireless Network Connection driver PROSet before 7.1.4.6 allows local users to corrupt memory and execute code via "requests for capabilities from higher-level protocol drivers or user-level applications" involving crafted frames, a different issue than CVE-2006-3992.

CVE-2006-3992 intel vulnerability CVSS: 5.1 05 Aug 2006, 00:04 UTC

Unspecified vulnerability in the Centrino (1) w22n50.sys, (2) w22n51.sys, (3) w29n50.sys, and (4) w29n51.sys Microsoft Windows drivers for Intel 2200BG and 2915ABG PRO/Wireless Network Connection before 10.5 with driver 9.0.4.16 allows remote attackers to execute arbitrary code via certain frames that trigger memory corruption.

CVE-2006-0081 intel vulnerability CVSS: 7.8 04 Jan 2006, 06:03 UTC

ialmnt5.sys in the ialmrnt5 display driver in Intel Graphics Accelerator Driver 6.14.10.4308 allows attackers to cause a denial of service (crash or screen resolution change) via a long text field, as demonstrated using a long window title.

CVE-2005-4625 intel vulnerability CVSS: 7.1 31 Dec 2005, 05:00 UTC

Drivers for certain display adapters, including (1) an unspecified ATI driver and (2) an unspecified Intel driver, might allow remote attackers to cause a denial of service (system crash) via a large JPEG image, as demonstrated in Internet Explorer using stoopid.jpg with a width and height of 9999999.

CVE-2004-2600 intel vulnerability CVSS: 5.0 31 Dec 2004, 05:00 UTC

The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped with an Authentication Type Enables parameter set to an invalid None parameter, which allows remote attackers to obtain sensitive information when LAN management functionality is enabled.

CVE-2003-0859 intel vulnerability CVSS: 4.9 15 Dec 2003, 05:00 UTC

The getifaddrs function in GNU libc (glibc) 2.2.4 and earlier allows local users to cause a denial of service by sending spoofed messages as other users to the kernel netlink interface.

CVE-2002-2059 intel vulnerability CVSS: 4.6 31 Dec 2002, 05:00 UTC

BIOS D845BG, D845HV, D845PT and D845WN on Intel motherboards does not properly restrict access to configuration information when BIOS passwords are enabled, which could allow local users to change the default boot device via the F8 key.

CVE-2002-0214 intel vulnerability CVSS: 2.1 16 May 2002, 04:00 UTC

Compaq Intel PRO/Wireless 2011B LAN USB Device Driver 1.5.16.0 through 1.5.18.0 stores the 128-bit WEP (Wired Equivalent Privacy) key in plaintext in a registry key with weak permissions, which allows local users to decrypt network traffic by reading the WEP key from the registry key.

CVE-2001-1520 intel vulnerability CVSS: 2.1 31 Dec 2001, 05:00 UTC

Xircom REX 6000 allows local users to obtain the 10 digit PIN by starting a serial monitor, connecting to the personal digital assistant (PDA) via Rextools, and capturing the cleartext PIN.

CVE-2001-0903 intel vulnerability CVSS: 7.5 20 Nov 2001, 05:00 UTC

Linear key exchange process in High-bandwidth Digital Content Protection (HDCP) System allows remote attackers to access data as plaintext, avoid device blacklists, clone devices, and create new device keyvectors by computing and using alternate key combinations for authentication.

CVE-2000-0989 intel vulnerability CVSS: 5.0 19 Dec 2000, 05:00 UTC

Buffer overflow in Intel InBusiness eMail Station 1.04.87 POP service allows remote attackers to cause a denial of service and possibly execute commands via a long username.

CVE-2000-0882 intel vulnerability CVSS: 5.0 14 Nov 2000, 05:00 UTC

Intel Express 500 series switches allow a remote attacker to cause a denial of service via a malformed ICMP packet, which causes the CPU to crash.

CVE-2000-0764 intel vulnerability CVSS: 5.0 20 Oct 2000, 04:00 UTC

Intel Express 500 series switches allow a remote attacker to cause a denial of service via a malformed IP packet.

CVE-2000-0516 intel vulnerability CVSS: 7.2 06 Jun 2000, 04:00 UTC

When configured to store configuration information in an LDAP directory, Shiva Access Manager 5.0.0 stores the root DN (Distinguished Name) name and password in cleartext in a file that is world readable, which allows local users to compromise the LDAP server.

CVE-2000-0451 intel vulnerability CVSS: 5.0 19 May 2000, 04:00 UTC

The Intel express 8100 ISDN router allows remote attackers to cause a denial of service via oversized or fragmented ICMP packets.

CVE-2000-0384 intel vulnerability CVSS: 10.0 08 May 2000, 04:00 UTC

NetStructure 7110 and 7180 have undocumented accounts (servnow, root, and wizard) whose passwords are easily guessable from the NetStructure's MAC address, which could allow remote attackers to gain root access.

CVE-1999-1476 intel vulnerability CVSS: 2.1 31 Dec 1999, 05:00 UTC

A bug in Intel Pentium processor (MMX and Overdrive) allows local users to cause a denial of service (hang) in Intel-based operating systems such as Windows NT and Windows 95, via an invalid instruction, aka the "Invalid Operand with Locked CMPXCHG8B Instruction" problem.

CVE-2000-0068 intel vulnerability CVSS: 7.5 14 Dec 1999, 05:00 UTC

daynad program in Intel InBusiness E-mail Station does not require authentication, which allows remote attackers to modify its configuration, delete files, or read mail.

CVE-1999-1566 intel vulnerability CVSS: 5.0 08 May 1999, 04:00 UTC

Buffer overflow in iParty server 1.2 and earlier allows remote attackers to cause a denial of service (crash) by connecting to default port 6004 and sending repeated extended characters.