amazon
196 tracked vulnerabilities.
CVE-2021-30355
HIGH
Amazon Kindle <5.13.4 - Privilege Escalation
Sep 01, 2021
CVSS 8.6
EPSS 0.00
CVE-2021-30354
HIGH
Amazon Kindle <5.13.4 - Code Injection
Sep 01, 2021
CVSS 8.6
EPSS 0.01
CVE-2021-37436
MEDIUM
Amazon Echo Dot Firmware < 2021-07-02 - Unprotected User Data Exposure via Factory Reset Bypass
Jul 24, 2021
CVSS 4.2
EPSS 0.00
CVE-2021-31828
HIGH
Amazon Open Distro for Elasticsearch < 1.13.1.0 - Authenticated Server-Side Request Forgery via Alerting Plugin
May 06, 2021
CVSS 7.1
EPSS 0.00
CVE-2021-32020
CRITICAL
Amazon FreeRTOS < 10.4.3 - Heap-Based Buffer Overflow
May 03, 2021
CVSS 9.8
EPSS 0.00
CVE-2021-31572
CRITICAL
Amazon FreeRTOS < 10.4.3 - Integer Overflow in Stream Buffer
Apr 22, 2021
CVSS 9.8
EPSS 0.00
CVE-2021-31571
CRITICAL
Amazon FreeRTOS < 10.4.3 - Integer Overflow in Queue Creation
Apr 22, 2021
CVSS 9.8
EPSS 0.00
CVE-2020-36363
CRITICAL
Amazon CloudFront TLSv1.2_2019 - Use of Weak TLS Ciphers
Aug 12, 2021
CVSS 9.8
EPSS 0.00
CVE-2020-28472
HIGH
@aws-sdk/shared-ini-file-loader <1.0.0-rc.9 - Prototype Pollution
Jan 19, 2021
CVSS 7.3
EPSS 0.02
CVE-2020-8897
MEDIUM
AWS Encryption SDK <2.0.0 - Info Disclosure
Nov 16, 2020
CVSS 4.8
EPSS 0.00
CVE-2020-27174
HIGH
Amazon AWS Firecracker <0.21.3-0.22.1 - Memory Corruption
Oct 16, 2020
CVSS 7.5
EPSS 0.01
CVE-2020-8912
LOW
AWS S3 Crypto SDK for GoLang < 2.0 - Use of a Broken or Risky Cryptographic Algorithm via In-Band Key Negotiation
Aug 11, 2020
CVSS 2.5
EPSS 0.00
CVE-2020-8911
MEDIUM
AWS S3 Crypto SDK for GoLang < 2.0 - Padding Oracle Attack via AES-CBC Without MAC
Aug 11, 2020
CVSS 5.6
EPSS 0.00
CVE-2020-16843
MEDIUM
Firecracker 0.20.x-0.20.1 and 0.21.x-0.21.2 - Denial of Service via Network Stack Freeze
Aug 04, 2020
CVSS 5.9
EPSS 0.00
CVE-2020-15093
HIGH
tough < 0.7.1 - Cryptographic Signature Verification Bypass via Duplicate Signature
Jul 09, 2020
CVSS 8.6
EPSS 0.00
CVE-2019-14652
MEDIUM
Amazon AWS JavaScript S3 Explorer <2019-08-02 - XSS
Feb 13, 2020
CVSS 6.1
EPSS 0.00
CVE-2019-10777
CRITICAL
aws-lambda < 1.0.5 - OS Command Injection via config.FunctionName
Jan 08, 2020
CVSS 9.8
EPSS 0.01
CVE-2019-3984
CRITICAL
Blink XT2 Sync Module Firmware < 2.3.11 - Remote Code Execution via Update Script Retrieval
Dec 31, 2019
CVSS 9.8
EPSS 0.03
CVE-2019-3989
CRITICAL
Blink XT2 Sync Module Firmware < 2.13.11 - Remote Code Execution via Network Configuration Retrieval
Dec 11, 2019
CVSS 9.8
EPSS 0.01
CVE-2019-3988
HIGH
Blink XT2 Sync Module Firmware < 2.13.11 - Remote Code Execution via BSSID Parameter
Dec 11, 2019
CVSS 8.8
EPSS 0.01
CVE-2019-3987
HIGH
Blink XT2 Sync Module Firmware < 2.13.11 - Remote Code Execution via WiFi Configuration Key Parameter
Dec 11, 2019
CVSS 8.8
EPSS 0.01
CVE-2019-3986
HIGH
Blink XT2 Sync Module Firmware < 2.13.11 - Remote Code Execution via WiFi Configuration Encryption Parameter
Dec 11, 2019
CVSS 8.8
EPSS 0.01
CVE-2019-3985
HIGH
Blink XT2 Sync Module Firmware < 2.13.11 - Remote Code Execution via SSID Parameter
Dec 11, 2019
CVSS 8.8
EPSS 0.01
CVE-2019-3983
MEDIUM
Blink XT2 Sync Module Firmware < 2.13.11 - Remote Code Execution via UART
Dec 11, 2019
CVSS 6.8
EPSS 0.02
CVE-2019-18960
CRITICAL
Firecracker <0.19.0 - Buffer Overflow
Dec 11, 2019
CVSS 9.8
EPSS 0.02
Products
freertos 17
amazon_web_services_freertos 14
fire_os 13
opensearch 11
tough 10
freertos-plus-tcp 9
blink_xt2_sync_module_firmware 7
Amazon Athena ODBC driver 6
athena_odbc 6
data.all 5
payfort-php-sdk 5
amazon_web_services_internet_of_things_device_software_development_kit_v2 4
aws_cloud_development_kit 4
aws_software_development_kit 4
firecracker 4
amazon_web_services_aws-c-io 3
aws-lc-sys 3
aws_libcrypto 3
echo_dot_firmware 3
opensearch_data_prepper 3
research_and_engineering_studio 3
tuftool 3
WorkSpaces Client 2
amazon_linux 2
amazon_web_services_redshift_java_database_connectivity_driver 2
audible 2
aws_client_vpn 2
aws_encryption_sdk 2
aws_s3_crypto_sdk 2
awslabs_sandbox_accounts_for_events 2
Quick Filters