Vulnerability index

Browse CVEs

170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Echo Dot Firmware CRITICAL 9.8
CVE-2022-25809

Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on these devices…

No fix yet
Fix from $2,300 2022-02-24
Aws Opensearch CRITICAL 9.8
CVE-2021-44833

The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.

Patch available
Fix from $2,300 2021-12-12
Sockeye HIGH 7.8
CVE-2021-43811

Sockeye is an open-source sequence-to-sequence framework for Neural Machine Translation built on PyTorch. Sockeye uses YAML to store model and data c…

Fix: 2.3.24+
Fix from $1,950 2021-12-08
Workspaces HIGH 8.8
CVE-2021-43637

Amazon WorkSpaces agent is affected by Buffer Overflow. IOCTL Handler 0x22001B in the Amazon WorkSpaces agent below v1.0.1.1537 allow local attackers…

Fix: 1.0.1.1537+
Fix from $1,950 2021-12-07
Workspaces HIGH 8.8
CVE-2021-43638

Amazon Amazon WorkSpaces agent is affected by Integer Overflow. IOCTL Handler 0x22001B in the Amazon WorkSpaces agent below v1.0.1.1537 allow local a…

Fix: 1.0.1.1537+
Fix from $1,950 2021-12-07
Amazon Web Services Aws C Io HIGH 8.8
CVE-2021-40828

Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.3.3), Python (versions prior to 1.5.18), C++ (versions prior to 1.…

Fix: 0.9.13 / 1.3.3+
Fix from $1,950 2021-11-23
Amazon Web Services Internet Of Things Device Software Development Kit V2 HIGH 8.8
CVE-2021-40829

Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.4.2), Python (versions prior to 1.6.1), C++ (versions prior to 1.1…

Fix: 1.4.2 / 1.5.3+
Fix from $1,950 2021-11-23
Amazon Web Services Aws C Io HIGH 8.8
CVE-2021-40830

The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js appends a user supplied Certificate Authority (CA) to the root CAs instead of overriding …

Fix: 1.5.0 / 1.5.3+
Fix from $1,950 2021-11-23
Amazon Web Services Aws C Io HIGH 7.2
CVE-2021-40831

The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js appends a user supplied Certificate Authority (CA) to the root CAs instead of overriding …

Fix: 1.5.0 / 1.6.0+
Fix from $1,950 2021-11-23
Freertos HIGH 7.8
CVE-2021-43997

FreeRTOS versions 10.2.0 through 10.4.5 do not prevent non-kernel code from calling the xPortRaisePrivilege internal function to raise privilege. Fre…

Fix: 10.4.6+
Fix from $1,950 2021-11-17
Tough MEDIUM 6.5
CVE-2021-41150

Tough provides a set of Rust libraries and tools for using and generating the update framework (TUF) repositories. The tough library, prior to 0.12.0…

Fix: 0.12.0+
Fix from $1,600 2021-10-19
Tough HIGH 8.1
CVE-2021-41149

Tough provides a set of Rust libraries and tools for using and generating the update framework (TUF) repositories. The tough library, prior to 0.12.0…

Fix: 0.12.0+
Fix from $1,950 2021-10-19
Aws Workspaces HIGH 8.8
CVE-2021-38112EPSS 7%

In the Amazon AWS WorkSpaces client 3.0.10 through 3.1.8 on Windows, argument injection in the workspaces:// URI handler can lead to remote code exec…

Fix: 3.1.9+
Fix from $1,950 2021-09-22
Kindle Firmware HIGH 8.6
CVE-2021-30355EPSS 7%

Amazon Kindle e-reader prior to and including version 5.13.4 improperly manages privileges, allowing the framework user to elevate privileges to root.

Fix: after 5.13.4
Fix from $1,950 2021-09-01
Kindle Firmware HIGH 8.6
CVE-2021-30354EPSS 8%

Amazon Kindle e-reader prior to and including version 5.13.4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function CJBi…

Fix: after 5.13.4
Fix from $1,950 2021-09-01
Amazon Cloudfront CRITICAL 9.8
CVE-2020-36363

Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, which some entities consid…

Mitigation only
Fix from $2,300 2021-08-12
Open Distro HIGH 7.1
CVE-2021-31828

An SSRF issue in Open Distro for Elasticsearch (ODFE) before 1.13.1.0 allows an existing privileged user to enumerate listening services or interact …

Fix: 1.13.1.0+
Fix from $1,950 2021-05-06
Freertos CRITICAL 9.8
CVE-2021-32020

The kernel in Amazon Web Services FreeRTOS before 10.4.3 has insufficient bounds checking during management of heap memory.

Fix: 10.4.3+
Fix from $2,300 2021-05-03
Freertos CRITICAL 9.8
CVE-2021-31571

The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in queue.c for queue creation.

Fix: 10.4.3+
Fix from $2,300 2021-04-22
Freertos CRITICAL 9.8
CVE-2021-31572

The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in stream_buffer.c for a stream buffer.

Fix: 10.4.3+
Fix from $2,300 2021-04-22
Aws Sdk For Javascipt CRITICAL 9.8
CVE-2020-28472

This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0. If an attacker submits a malicious IN…

Fix: 2.814.0+
Fix from $2,300 2021-01-19
Aws Encryption Sdk HIGH 8.1
CVE-2020-8897

A weak robustness vulnerability exists in the AWS Encryption SDKs for Java, Python, C and Javalcript prior to versions 2.0.0. Due to the non-committi…

Fix: 2.0.0+
Fix from $1,950 2020-11-16
Firecracker HIGH 7.5
CVE-2020-27174

In Amazon AWS Firecracker before 0.21.3, and 0.22.x before 0.22.1, the serial console buffer can grow its memory usage without limit when data is sen…

Fix: 0.21.3 / 0.22.1+
Fix from $1,950 2020-10-16
Aws S3 Crypto Sdk MEDIUM 5.6
CVE-2020-8911

A padding oracle vulnerability exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. The SDK allows users to encrypt files with AES-CBC wi…

Fix: 2.0+
Fix from $1,600 2020-08-11
Firecracker MEDIUM 5.9
CVE-2020-16843

In Firecracker 0.20.x before 0.20.1 and 0.21.x before 0.21.2, the network stack can freeze under heavy ingress traffic. This can result in a denial o…

Mitigation only
Fix from $1,600 2020-08-04
Tough HIGH 8.6
CVE-2020-15093

The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signatures. It allows an attacker t…

Fix: 0.7.1+
Fix from $1,950 2020-07-09
Aws Javascript S3 Explorer MEDIUM 6.1
CVE-2019-14652

explorer.js in Amazon AWS JavaScript S3 Explorer (aka aws-js-s3-explorer) v2 alpha before 2019-08-02 allows XSS in certain circumstances.

Fix: 2019-08-02+
Fix from $1,600 2020-02-13
Aws Lambda CRITICAL 9.8
CVE-2019-10777

In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function without any…

Fix: 1.0.5+
Fix from $2,300 2020-01-08
Blink Xt2 Sync Module Firmware CRITICAL 9.8
CVE-2019-3984

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input…

Fix: 2.3.11+
Fix from $2,300 2019-12-31
Blink Xt2 Sync Module Firmware CRITICAL 9.8
CVE-2019-3989

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input…

Fix: 2.13.11+
Fix from $2,300 2019-12-11