Amazon
amazon
198 CVEs • 107 products
Products (107)
Click to collapseToggle
Products (107)
Click to collapse
CVEs (198)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Firecracker 0.20.x before 0.20.1 and 0.21.x before 0.21.2, the network stack can freeze under heavy ingress traffic. This can result in a denial of service on the microVM when it is configured with a single network in...Show more |
The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signatures. It allows an attacker to duplicate a valid signature in order to circumvent TUF requiring a mi...Show more |
1Amazon 1Aws Javascript S3 Explorer Jun 17, 2026 Feb 13, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 explorer.js in Amazon AWS JavaScript S3 Explorer (aka aws-js-s3-explorer) v2 alpha before 2019-08-02 allows XSS in certain circumstances. |
In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function without any sanitization. It is possible for a user to inject arbitrary commands t...Show more |
1Amazon 1Blink Xt2 Sync Module Firmware Jun 17, 2026 Dec 31, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when the device retrieves updates scripts from the internet. |
1Amazon 1Blink Xt2 Sync Module Firmware Jun 17, 2026 Dec 11, 2019 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when retrieving internal network configuration data. |
1Amazon 1Blink Xt2 Sync Module Firmware Jun 17, 2026 Dec 11, 2019 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the bssid paramete...Show more |
1Amazon 1Blink Xt2 Sync Module Firmware Jun 17, 2026 Dec 11, 2019 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the key parameter. |
1Amazon 1Blink Xt2 Sync Module Firmware Jun 17, 2026 Dec 11, 2019 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the encryption par...Show more |
1Amazon 1Blink Xt2 Sync Module Firmware Jun 17, 2026 Dec 11, 2019 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the ssid parameter...Show more |
1Amazon 1Blink Xt2 Sync Module Firmware Jun 17, 2026 Dec 11, 2019 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary code and commands on the device due to insufficient UART protections. |
Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.0. This can result in potentially exploitable crashes. |
The Audible application through 2.34.0 for Android has Missing SSL Certificate Validation for Adobe SDKs, allowing MITM attackers to cause a denial of service. |
Real Time Engineers FreeRTOS+FAT 160919a has a use after free. The function FF_Close() is defined in ff_file.c. The file handler pxFile is freed by ffconfigFREE, which (by default) is a macro definition of vPortFree(), b...Show more |
1Amazon 1Amazon Web Services Freertos Jun 17, 2026 Oct 7, 2019 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Amazon FreeRTOS up to and including v1.4.8 lacks length checking in prvProcessReceivedPublish, resulting in untargetable leakage of arbitrary memory contents on a device to an attacker. If an attacker has the authorizati...Show more |
1Amazon 1Aws Software Development Kit Nov 21, 2024 Apr 4, 2019 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Amazon AWS SDK <=2.8.5 for Android uses Android SharedPreferences to store plain text AWS STS Temporary Credentials retrieved by AWS Cognito Identity Service. An attacker can use these credentials to create authenticated...Show more |
1Amazon 1Ring Video Doorbell Firmware Jun 17, 2026 Mar 1, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Amazon Ring Doorbell before 3.4.7 mishandles encryption, which allows attackers to obtain audio and video data, or insert spoofed video that does not correspond to the actual person at the door. |
Amazon Fire OS before 5.3.6.4 allows a man-in-the-middle attack against HTTP requests for "Terms of Use" and Privacy pages. |
1Amazon 2Amazon Web Services Freertos FreertosNov 21, 2024 Dec 6, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. Out of bounds access to TCP source and de...Show more |
1Amazon 2Amazon Web Services Freertos FreertosNov 21, 2024 Dec 6, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. Out of bounds memory access during parsin...Show more |