6
CVE-2025-10699 -
A vulnerability was reported in the Lenovo LeCloud client application that, under certain conditions, could allow information disclosure.
8.5
CVE-2025-10581 -
A potential DLL hijacking vulnerability was discovered in the Lenovo PC Manager during an internal security assessment that could allow a local authenticated user to execute code with elevated privileges.
6.8
CVE-2025-9548 -
A potential null pointer dereference vulnerability was reported in the Lenovo Power Management Driver that could allow a local authenticated user to cause a Windows blue screen error.
8.5
CVE-2025-8486 -
A potential vulnerability was reported in PC Manager that could allow a local authenticated user to execute code with elevated privileges.
2.3
CVE-2025-6026 -
An improper certificate validation vulnerability was reported in the Lenovo Universal Device Client (UDC) that could allow a user capable of intercepting network traffic to obtain application metadata, including device information, geolocation, and telemetry data.
6.9
CVE-2025-55083 - Broken bounds check in Broken bounds check in _nx_secure_tls_process_clienthello_psk_extension()
In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check resulting it out by two out of bound read.
6.9
CVE-2025-60015 - F5OS out-of-bounds write vulnerability
An out-of-bounds write vulnerability exists in F5OS-A and F5OS-C that could lead to memory corruption.Β Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
6.9
CVE-2025-54755 - BIG-IP Configuration utility vulnerability
A directory traversal vulnerability exists in TMUI that allows a highly privilegedΒ authenticated attacker to access files which are not limited to the intended files.Β Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
8.5
CVE-2025-59483 - BIG-IP Configuration utility and tmsh vulnerability
A validation vulnerability exists in an undisclosed URL in the Configuration utility.Β Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
8.7
CVE-2025-61974 - BIG-IP SSL/TLS vulnerability
When a client SSL profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.Β Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.