Vulnerability index

Browse CVEs

170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Blink Xt2 Sync Module Firmware HIGH 8.8
CVE-2019-3985

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input…

Fix: 2.13.11+
Fix from $1,950 2019-12-11
Blink Xt2 Sync Module Firmware HIGH 8.8
CVE-2019-3986

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input…

Fix: 2.13.11+
Fix from $1,950 2019-12-11
Blink Xt2 Sync Module Firmware HIGH 8.8
CVE-2019-3987

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input…

Fix: 2.13.11+
Fix from $1,950 2019-12-11
Blink Xt2 Sync Module Firmware HIGH 8.8
CVE-2019-3988

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input…

Fix: 2.13.11+
Fix from $1,950 2019-12-11
Blink Xt2 Sync Module Firmware MEDIUM 6.8
CVE-2019-3983

Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary code and commands on the device due to insufficient UART…

Fix: 2.13.11+
Fix from $1,600 2019-12-11
Firecracker CRITICAL 9.8
CVE-2019-18960

Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.0. This can result in potentially exploitable crashes.

Mitigation only
Fix from $2,300 2019-12-11
Audible MEDIUM 5.9
CVE-2019-11554

The Audible application through 2.34.0 for Android has Missing SSL Certificate Validation for Adobe SDKs, allowing MITM attackers to cause a denial o…

Fix: after 2.34.0
Fix from $1,600 2019-12-06
Freertos\+fat HIGH 7.5
CVE-2019-18178

Real Time Engineers FreeRTOS+FAT 160919a has a use after free. The function FF_Close() is defined in ff_file.c. The file handler pxFile is freed by f…

No fix yet
Fix from $1,950 2019-11-04
Amazon Web Services Freertos HIGH 7.5
CVE-2019-13120

Amazon FreeRTOS up to and including v1.4.8 lacks length checking in prvProcessReceivedPublish, resulting in untargetable leakage of arbitrary memory …

Fix: after 1.4.8
Fix from $1,950 2019-10-07
Aws Software Development Kit HIGH 7.2
CVE-2018-19981

Amazon AWS SDK <=2.8.5 for Android uses Android SharedPreferences to store plain text AWS STS Temporary Credentials retrieved by AWS Cognito Identity…

Fix: after 2.8.5
Fix from $1,950 2019-04-04
Ring Video Doorbell Firmware CRITICAL 9.1
CVE-2019-9483

Amazon Ring Doorbell before 3.4.7 mishandles encryption, which allows attackers to obtain audio and video data, or insert spoofed video that does not…

Fix: 3.4.7+
Fix from $2,300 2019-03-01
Fire Os HIGH 7.4
CVE-2019-7399

Amazon Fire OS before 5.3.6.4 allows a man-in-the-middle attack against HTTP requests for "Terms of Use" and Privacy pages.

Fix: 5.3.6.4+
Fix from $1,950 2019-02-17
Amazon Web Services Freertos HIGH 8.1
CVE-2018-16601

An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect…

Fix: after 10.0.1
Fix from $1,950 2018-12-06
Amazon Web Services Freertos MEDIUM 5.9
CVE-2018-16602

An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect…

Fix: after 10.0.1
Fix from $1,600 2018-12-06
Amazon Web Services Freertos MEDIUM 5.9
CVE-2018-16603

An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect…

Fix: after 10.0.1
Fix from $1,600 2018-12-06
Amazon Web Services Freertos HIGH 8.1
CVE-2018-16522

Amazon Web Services (AWS) FreeRTOS through 1.3.1 has an uninitialized pointer free in SOCKETS_SetSockOpt.

Fix: after 1.3.1
Fix from $1,950 2018-12-06
Amazon Web Services Freertos HIGH 8.1
CVE-2018-16525

Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP componen…

Fix: after 10.0.1
Fix from $1,950 2018-12-06
Amazon Web Services Freertos HIGH 8.1
CVE-2018-16526

Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP componen…

Fix: after 10.0.1
Fix from $1,950 2018-12-06
Amazon Web Services Freertos HIGH 8.1
CVE-2018-16528

Amazon Web Services (AWS) FreeRTOS through 1.3.1 allows remote attackers to execute arbitrary code because of mbedTLS context object corruption in pr…

Fix: after 1.3.1
Fix from $1,950 2018-12-06
Amazon Web Services Freertos HIGH 7.4
CVE-2018-16523

Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP componen…

Fix: after 10.0.1
Fix from $1,950 2018-12-06
Amazon Web Services Freertos MEDIUM 5.9
CVE-2018-16524

Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP componen…

Fix: after 10.0.1
Fix from $1,600 2018-12-06
Amazon Web Services Freertos MEDIUM 5.9
CVE-2018-16527

Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP componen…

Fix: after 10.0.1
Fix from $1,600 2018-12-06
Amazon Web Services Freertos MEDIUM 5.9
CVE-2018-16598

An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect…

Fix: after 10.0.1
Fix from $1,600 2018-12-06
Amazon Web Services Freertos MEDIUM 5.9
CVE-2018-16599

An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect…

Fix: after 10.0.1
Fix from $1,600 2018-12-06
Amazon Web Services Freertos MEDIUM 5.9
CVE-2018-16600

An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect…

Fix: after 10.0.1
Fix from $1,600 2018-12-06
Payfort Php Sdk MEDIUM 6.1
CVE-2018-19186

The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the route.php paymentMethod parameter.

Fix: after 2018-04-26
Fix from $1,600 2018-11-14
Payfort Php Sdk MEDIUM 6.1
CVE-2018-19187

The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in a su…

Fix: after 2018-04-26
Fix from $1,600 2018-11-14
Payfort Php Sdk MEDIUM 6.1
CVE-2018-19188

The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the success.php fort_id parameter.

Fix: after 2018-04-26
Fix from $1,600 2018-11-14
Payfort Php Sdk MEDIUM 6.1
CVE-2018-19189

The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in an e…

Fix: after 2018-04-26
Fix from $1,600 2018-11-14
Payfort Php Sdk MEDIUM 6.1
CVE-2018-19190

The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the error.php error_msg parameter.

Fix: after 2018-04-26
Fix from $1,600 2018-11-14