Vulnerability index

Browse CVEs

31 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.9 CVE-2026-19642 An out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862 might allow a remote authenticated user to cause a crash or … Aws Software Development Kit No fix yet Fix from $4,0002026-08-12 MEDIUM 5.3 CVE-2026-19643 An out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862, on some platforms, might allow a remote authenticated user t… Aws Software Development Kit No fix yet Fix from $4,0002026-08-12 HIGH 7.8 CVE-2026-18656 An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary cod… Kiro Ide No fix yet Fix from $1,9502026-08-04 HIGH 7.8 CVE-2026-18657 An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code… Kiro Cli No fix yet Fix from $1,9502026-08-04 CRITICAL 9.8 CVE-2026-13762 Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule bod… Cloudfront Mitigation only Fix from $2,3002026-06-29 CRITICAL 9.8 CVE-2026-13763 Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF mana… Application Load Balancer Mitigation only Fix from $2,3002026-06-29 HIGH 8.0 CVE-2024-12745 A SQL injection in the Amazon Redshift Python Connector v2.1.4 allows a user to gain escalated privileges via the get_schemas, get_tables, or get_col… Redshift Connector Mitigation only Fix from $1,9502024-12-24 HIGH 8.0 CVE-2024-12746 A SQL injection in the Amazon Redshift ODBC Driver v2.1.5.0 (Windows or Linux) allows a user to gain escalated privileges via the SQLTables or SQLCol… Redshift Odbc Driver Mitigation only Fix from $1,9502024-12-24 HIGH 8.0 CVE-2024-12744 A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSchemas, getTables, or getColum… Amazon Web Services Redshift Java Database Connectivity Driver Mitigation only Fix from $1,9502024-12-24 HIGH 7.6 CVE-2023-33248 Amazon Alexa software version 8960323972 on Echo Dot 2nd generation and 3rd generation devices potentially allows attackers to deliver security-relev… Alexa No fix yet Fix from $1,9502023-05-24 MEDIUM 5.5 CVE-2023-30610 aws-sigv4 is a rust library for low level request signing in the aws cloud platform. The `aws_sigv4::SigningParams` struct had a derived `Debug` impl… Aws Sigv4 Mitigation only Fix from $1,6002023-04-19 HIGH 7.0 CVE-2022-25165 An issue was discovered in Amazon AWS VPN Client 2.0.0. A TOCTOU race condition exists during the validation of VPN configuration files. This allows … Aws Client Vpn No fix yet Fix from $1,9502022-04-14 MEDIUM 5.0 CVE-2022-25166 An issue was discovered in Amazon AWS VPN Client 2.0.0. It is possible to include a UNC path in the OpenVPN configuration file when referencing file … Aws Client Vpn No fix yet Fix from $1,6002022-04-14 CRITICAL 9.8 CVE-2022-25809 Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on these devices… Echo Dot Firmware No fix yet Fix from $2,3002022-02-24 CRITICAL 9.8 CVE-2020-36363 Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, which some entities consid… Amazon Cloudfront Mitigation only Fix from $2,3002021-08-12 MEDIUM 5.9 CVE-2020-16843 In Firecracker 0.20.x before 0.20.1 and 0.21.x before 0.21.2, the network stack can freeze under heavy ingress traffic. This can result in a denial o… Firecracker Mitigation only Fix from $1,6002020-08-04 CRITICAL 9.8 CVE-2019-18960 Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.0. This can result in potentially exploitable crashes. Firecracker Mitigation only Fix from $2,3002019-12-11 HIGH 7.5 CVE-2019-18178 Real Time Engineers FreeRTOS+FAT 160919a has a use after free. The function FF_Close() is defined in ff_file.c. The file handler pxFile is freed by f… Freertos\+fat No fix yet Fix from $1,9502019-11-04 HIGH 7.5 CVE-2018-11021 kernel/omap/drivers/video/omap2/dsscomp/device.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a c… Fire Os No fix yet Fix from $1,9502018-10-16 HIGH 7.5 CVE-2018-11022 kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafte… Fire Os No fix yet Fix from $1,9502018-10-16 HIGH 7.5 CVE-2018-11023 kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD (3rd) Fire OS 4.5.5.3 allows attackers to inject a craft… Fire Os No fix yet Fix from $1,9502018-10-16 HIGH 7.5 CVE-2018-11024 kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD (3rd) Fire OS 4.5.5.3 allows attackers to inject a craft… Fire Os No fix yet Fix from $1,9502018-10-16 HIGH 7.5 CVE-2018-11025 kernel/omap/drivers/mfd/twl6030-gpadc.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted ar… Fire Os No fix yet Fix from $1,9502018-10-16 HIGH 7.5 CVE-2018-11019 kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafte… Fire Os No fix yet Fix from $1,9502018-10-16 HIGH 8.8 CVE-2018-1169 This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Amazon Music Player 6.1.5.1213. User interaction … Amazon Music Mitigation only Fix from $1,9502018-03-02 HIGH 7.8 CVE-2017-17069 ActiveSetupN.exe in Amazon Audible for Windows before November 2017 allows attackers to execute arbitrary DLL code if ActiveSetupN.exe is launched fr… Audible No fix yet Fix from $1,9502017-12-06 MEDIUM 5.8 CVE-2012-5780 The Amazon merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of t… Merchant Sdk No fix yet Fix from $1,6002012-11-04 MEDIUM 5.8 CVE-2012-5781 Amazon Elastic Load Balancing API Tools does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAl… Elastic Load Balancing No fix yet Fix from $1,6002012-11-04 MEDIUM 5.8 CVE-2012-5782 Amazon Flexible Payments Service (FPS) PHP Library does not verify that the server hostname matches a domain name in the subject's Common Name (CN) o… Flexible Payments Service No fix yet Fix from $1,6002012-11-04 MEDIUM 6.9 CVE-2010-5268 Untrusted search path vulnerability in Amazon Kindle for PC 1.3.0 30884 allows local users to gain privileges via a Trojan horse wintab32.dll file in… Kindle For Pc Mitigation only Fix from $1,6002012-09-07