Vulnerability index

Browse CVEs

170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fire Os HIGH 7.5
CVE-2018-11021

kernel/omap/drivers/video/omap2/dsscomp/device.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a c…

No fix yet
Fix from $1,950 2018-10-16
Fire Os HIGH 7.5
CVE-2018-11022

kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafte…

No fix yet
Fix from $1,950 2018-10-16
Fire Os HIGH 7.5
CVE-2018-11023

kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD (3rd) Fire OS 4.5.5.3 allows attackers to inject a craft…

No fix yet
Fix from $1,950 2018-10-16
Fire Os HIGH 7.5
CVE-2018-11024

kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD (3rd) Fire OS 4.5.5.3 allows attackers to inject a craft…

No fix yet
Fix from $1,950 2018-10-16
Fire Os HIGH 7.5
CVE-2018-11025

kernel/omap/drivers/mfd/twl6030-gpadc.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted ar…

No fix yet
Fix from $1,950 2018-10-16
Fire Os HIGH 7.5
CVE-2018-11019

kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafte…

No fix yet
Fix from $1,950 2018-10-16
Amazon Music HIGH 8.8
CVE-2018-1169

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Amazon Music Player 6.1.5.1213. User interaction …

Mitigation only
Fix from $1,950 2018-03-02
Audible HIGH 7.8
CVE-2017-17069

ActiveSetupN.exe in Amazon Audible for Windows before November 2017 allows attackers to execute arbitrary DLL code if ActiveSetupN.exe is launched fr…

No fix yet
Fix from $1,950 2017-12-06
Amazon Key Firmware MEDIUM 6.5
CVE-2017-16867

Amazon Key through 2017-11-16 mishandles Cloud Cam 802.11 deauthentication frames during the delivery process, which makes it easier for (1) delivery…

Fix: after 2017-11-16
Fix from $1,600 2017-11-16
Amazon Web Services Cloudformation Bootstrap HIGH 7.8
CVE-2017-9450

The Amazon Web Services (AWS) CloudFormation bootstrap tools package (aka aws-cfn-bootstrap) before 1.4-19.10 allows local users to execute arbitrary…

Fix: 1.4-19.10+
Fix from $1,950 2017-10-30
Fire Os CRITICAL 9.8
CVE-2015-7292

Stack-based buffer overflow in the havok_write function in drivers/staging/havok/havok.c in Amazon Fire OS before 2016-01-15 allows attackers to caus…

Fix: after 5.0
Fix from $2,300 2017-04-10
Kindle For Pc HIGH 7.3
CVE-2017-6189

Untrusted search path vulnerability in Amazon Kindle for PC before 1.19 allows local users to execute arbitrary code and conduct DLL hijacking attack…

Fix: after 1.17.44183
Fix from $1,950 2017-03-15
Kindle MEDIUM 5.8
CVE-2014-3908

The Amazon.com Kindle application before 4.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attack…

Fix: after 4.4.4
Fix from $1,600 2014-08-30
Ec2 Api Tools Java Library HIGH 7.4
CVE-2012-5817

Codehaus XFire 1.2.6 and earlier, as used in the Amazon EC2 API Tools Java library and other products, does not verify that the server hostname match…

Fix: after 1.2.6
Fix from $1,950 2012-11-04
Merchant Sdk MEDIUM 5.8
CVE-2012-5780

The Amazon merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of t…

No fix yet
Fix from $1,600 2012-11-04
Elastic Load Balancing MEDIUM 5.8
CVE-2012-5781

Amazon Elastic Load Balancing API Tools does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAl…

No fix yet
Fix from $1,600 2012-11-04
Flexible Payments Service MEDIUM 5.8
CVE-2012-5782

Amazon Flexible Payments Service (FPS) PHP Library does not verify that the server hostname matches a domain name in the subject's Common Name (CN) o…

No fix yet
Fix from $1,600 2012-11-04
Kindle For Pc MEDIUM 6.9
CVE-2010-5268

Untrusted search path vulnerability in Amazon Kindle for PC 1.3.0 30884 allows local users to gain privileges via a Trojan horse wintab32.dll file in…

Mitigation only
Fix from $1,600 2012-09-07
Kindle Touch HIGH 10.0
CVE-2012-4249

The Amazon Lab126 com.lab126.system sendEvent implementation on the Kindle Touch before 5.1.2 allows context-dependent attackers to execute arbitrary…

Mitigation only
Fix from $1,950 2012-08-12
Kindle Touch HIGH 9.3
CVE-2012-4248

The Amazon Kindle Touch before 5.1.2 does not properly restrict access to the libkindleplugin.so NPAPI plugin interface, which might allow remote att…

Fix: after 5.1.1
Fix from $1,950 2012-08-12