Amazon
amazon
185 CVEs • 101 products
Products (101)
Click to collapseToggle
Products (101)
Click to collapse
CVEs (185)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in stream_buffer.c for a stream buffer. |
The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in queue.c for queue creation. |
1Amazon 2Aws Sdk For Javascipt Aws Shared Configuration File LoaderJun 17, 2026 Jan 19, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0. If an attacker submits a malicious INI file to an application that parses it with loadSharedConfigFiles , th...Show more |
A weak robustness vulnerability exists in the AWS Encryption SDKs for Java, Python, C and Javalcript prior to versions 2.0.0. Due to the non-committing property of AES-GCM (and other AEAD ciphers such as AES-GCM-SIV or (...Show more |
In Amazon AWS Firecracker before 0.21.3, and 0.22.x before 0.22.1, the serial console buffer can grow its memory usage without limit when data is sent to the standard input. This can result in a memory leak on the microV...Show more |
A vulnerability in the in-band key negotiation exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. An attacker with write access to the targeted bucket can change the encryption algorithm of an object in the...Show more |
A padding oracle vulnerability exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. The SDK allows users to encrypt files with AES-CBC without computing a Message Authentication Code (MAC), which then allows...Show more |
In Firecracker 0.20.x before 0.20.1 and 0.21.x before 0.21.2, the network stack can freeze under heavy ingress traffic. This can result in a denial of service on the microVM when it is configured with a single network in...Show more |
The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signatures. It allows an attacker to duplicate a valid signature in order to circumvent TUF requiring a mi...Show more |
1Amazon 1Aws Javascript S3 Explorer Jun 17, 2026 Feb 13, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 explorer.js in Amazon AWS JavaScript S3 Explorer (aka aws-js-s3-explorer) v2 alpha before 2019-08-02 allows XSS in certain circumstances. |
In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function without any sanitization. It is possible for a user to inject arbitrary commands t...Show more |
1Amazon 1Blink Xt2 Sync Module Firmware Jun 17, 2026 Dec 31, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when the device retrieves updates scripts from the internet. |
1Amazon 1Blink Xt2 Sync Module Firmware Jun 17, 2026 Dec 11, 2019 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when retrieving internal network configuration data. |
1Amazon 1Blink Xt2 Sync Module Firmware Jun 17, 2026 Dec 11, 2019 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the bssid paramete...Show more |
1Amazon 1Blink Xt2 Sync Module Firmware Jun 17, 2026 Dec 11, 2019 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the key parameter. |
1Amazon 1Blink Xt2 Sync Module Firmware Jun 17, 2026 Dec 11, 2019 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the encryption par...Show more |
1Amazon 1Blink Xt2 Sync Module Firmware Jun 17, 2026 Dec 11, 2019 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the ssid parameter...Show more |
1Amazon 1Blink Xt2 Sync Module Firmware Jun 17, 2026 Dec 11, 2019 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary code and commands on the device due to insufficient UART protections. |
Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.0. This can result in potentially exploitable crashes. |
The Audible application through 2.34.0 for Android has Missing SSL Certificate Validation for Adobe SDKs, allowing MITM attackers to cause a denial of service. |