Amazon
amazon
185 CVEs • 101 products
Products (101)
Click to collapseToggle
Products (101)
Click to collapse
CVEs (185)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Real Time Engineers FreeRTOS+FAT 160919a has a use after free. The function FF_Close() is defined in ff_file.c. The file handler pxFile is freed by ffconfigFREE, which (by default) is a macro definition of vPortFree(), b...Show more |
1Amazon 1Amazon Web Services Freertos Jun 17, 2026 Oct 7, 2019 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Amazon FreeRTOS up to and including v1.4.8 lacks length checking in prvProcessReceivedPublish, resulting in untargetable leakage of arbitrary memory contents on a device to an attacker. If an attacker has the authorizati...Show more |
1Amazon 1Aws Software Development Kit Nov 21, 2024 Apr 4, 2019 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Amazon AWS SDK <=2.8.5 for Android uses Android SharedPreferences to store plain text AWS STS Temporary Credentials retrieved by AWS Cognito Identity Service. An attacker can use these credentials to create authenticated...Show more |
1Amazon 1Ring Video Doorbell Firmware Jun 17, 2026 Mar 1, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Amazon Ring Doorbell before 3.4.7 mishandles encryption, which allows attackers to obtain audio and video data, or insert spoofed video that does not correspond to the actual person at the door. |
Amazon Fire OS before 5.3.6.4 allows a man-in-the-middle attack against HTTP requests for "Terms of Use" and Privacy pages. |
1Amazon 2Amazon Web Services Freertos FreertosNov 21, 2024 Dec 6, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. Out of bounds access to TCP source and de...Show more |
1Amazon 2Amazon Web Services Freertos FreertosNov 21, 2024 Dec 6, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. Out of bounds memory access during parsin...Show more |
1Amazon 2Amazon Web Services Freertos FreertosNov 21, 2024 Dec 6, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. A crafted IP header triggers a full memor...Show more |
1Amazon 2Amazon Web Services Freertos FreertosNov 21, 2024 Dec 6, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. Out of bounds memory access during parsin...Show more |
1Amazon 2Amazon Web Services Freertos FreertosNov 21, 2024 Dec 6, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. Out of bounds memory access during parsin...Show more |
1Amazon 2Amazon Web Services Freertos FreertosNov 21, 2024 Dec 6, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. In xProcessReceivedUDPPacket and prvParse...Show more |
1Amazon 1Amazon Web Services Freertos Nov 21, 2024 Dec 6, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Amazon Web Services (AWS) FreeRTOS through 1.3.1 allows remote attackers to execute arbitrary code because of mbedTLS context object corruption in prvSetupConnection and GGD_SecureConnect_Connect in AWS TLS connectivity...Show more |
1Amazon 2Amazon Web Services Freertos FreertosNov 21, 2024 Dec 6, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component allow information disclosure during parsing of ICMP packets in prvPro...Show more |
1Amazon 2Amazon Web Services Freertos FreertosNov 21, 2024 Dec 6, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component allow remote attackers to leak information or execute arbitrary code...Show more |
1Amazon 2Amazon Web Services Freertos FreertosNov 21, 2024 Dec 6, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component allow remote attackers to execute arbitrary code or leak information...Show more |
1Amazon 2Amazon Web Services Freertos FreertosNov 21, 2024 Dec 6, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component allow information disclosure during parsing of TCP options in prvChec...Show more |
1Amazon 2Amazon Web Services Freertos FreertosNov 21, 2024 Dec 6, 2018 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component allow division by zero in prvCheckOptions. |
1Amazon 1Amazon Web Services Freertos Nov 21, 2024 Dec 6, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Amazon Web Services (AWS) FreeRTOS through 1.3.1 has an uninitialized pointer free in SOCKETS_SetSockOpt. |
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the error.php error_msg parameter. |
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in an error.php echo statement. |