Vulnerability index

Browse CVEs

170 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2022-25809 Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on these devices… Echo Dot Firmware No fix yet Fix from $2,3002022-02-24 CRITICAL 9.8 CVE-2021-44833 The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file. Aws Opensearch Patch available Fix from $2,3002021-12-12 HIGH 7.8 CVE-2021-43811 Sockeye is an open-source sequence-to-sequence framework for Neural Machine Translation built on PyTorch. Sockeye uses YAML to store model and data c… Sockeye 2.3.24+ Fix from $1,9502021-12-08 HIGH 8.8 CVE-2021-43637 Amazon WorkSpaces agent is affected by Buffer Overflow. IOCTL Handler 0x22001B in the Amazon WorkSpaces agent below v1.0.1.1537 allow local attackers… Workspaces 1.0.1.1537+ Fix from $1,9502021-12-07 HIGH 8.8 CVE-2021-43638 Amazon Amazon WorkSpaces agent is affected by Integer Overflow. IOCTL Handler 0x22001B in the Amazon WorkSpaces agent below v1.0.1.1537 allow local a… Workspaces 1.0.1.1537+ Fix from $1,9502021-12-07 HIGH 8.8 CVE-2021-40828 Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.3.3), Python (versions prior to 1.5.18), C++ (versions prior to 1.… Amazon Web Services Aws C Io 0.9.13 / 1.3.3+ Fix from $1,9502021-11-23 HIGH 8.8 CVE-2021-40829 Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.4.2), Python (versions prior to 1.6.1), C++ (versions prior to 1.1… Amazon Web Services Internet Of Things Device Software Development Kit V2 1.4.2 / 1.5.3+ Fix from $1,9502021-11-23 HIGH 8.8 CVE-2021-40830 The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js appends a user supplied Certificate Authority (CA) to the root CAs instead of overriding … Amazon Web Services Aws C Io 1.5.0 / 1.5.3+ Fix from $1,9502021-11-23 HIGH 7.2 CVE-2021-40831 The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js appends a user supplied Certificate Authority (CA) to the root CAs instead of overriding … Amazon Web Services Aws C Io 1.5.0 / 1.6.0+ Fix from $1,9502021-11-23 HIGH 7.8 CVE-2021-43997 FreeRTOS versions 10.2.0 through 10.4.5 do not prevent non-kernel code from calling the xPortRaisePrivilege internal function to raise privilege. Fre… Freertos 10.4.6+ Fix from $1,9502021-11-17 MEDIUM 6.5 CVE-2021-41150 Tough provides a set of Rust libraries and tools for using and generating the update framework (TUF) repositories. The tough library, prior to 0.12.0… Tough 0.12.0+ Fix from $1,6002021-10-19 HIGH 8.1 CVE-2021-41149 Tough provides a set of Rust libraries and tools for using and generating the update framework (TUF) repositories. The tough library, prior to 0.12.0… Tough 0.12.0+ Fix from $1,9502021-10-19 HIGH 8.8 CVE-2021-38112EPSS 7% In the Amazon AWS WorkSpaces client 3.0.10 through 3.1.8 on Windows, argument injection in the workspaces:// URI handler can lead to remote code exec… Aws Workspaces 3.1.9+ Fix from $1,9502021-09-22 HIGH 8.6 CVE-2021-30355EPSS 7% Amazon Kindle e-reader prior to and including version 5.13.4 improperly manages privileges, allowing the framework user to elevate privileges to root. Kindle Firmware after 5.13.4 Fix from $1,9502021-09-01 HIGH 8.6 CVE-2021-30354EPSS 8% Amazon Kindle e-reader prior to and including version 5.13.4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function CJBi… Kindle Firmware after 5.13.4 Fix from $1,9502021-09-01 CRITICAL 9.8 CVE-2020-36363 Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, which some entities consid… Amazon Cloudfront Mitigation only Fix from $2,3002021-08-12 HIGH 7.1 CVE-2021-31828 An SSRF issue in Open Distro for Elasticsearch (ODFE) before 1.13.1.0 allows an existing privileged user to enumerate listening services or interact … Open Distro 1.13.1.0+ Fix from $1,9502021-05-06 CRITICAL 9.8 CVE-2021-32020 The kernel in Amazon Web Services FreeRTOS before 10.4.3 has insufficient bounds checking during management of heap memory. Freertos 10.4.3+ Fix from $2,3002021-05-03 CRITICAL 9.8 CVE-2021-31571 The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in queue.c for queue creation. Freertos 10.4.3+ Fix from $2,3002021-04-22 CRITICAL 9.8 CVE-2021-31572 The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in stream_buffer.c for a stream buffer. Freertos 10.4.3+ Fix from $2,3002021-04-22 CRITICAL 9.8 CVE-2020-28472 This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0. If an attacker submits a malicious IN… Aws Sdk For Javascipt 2.814.0+ Fix from $2,3002021-01-19 HIGH 8.1 CVE-2020-8897 A weak robustness vulnerability exists in the AWS Encryption SDKs for Java, Python, C and Javalcript prior to versions 2.0.0. Due to the non-committi… Aws Encryption Sdk 2.0.0+ Fix from $1,9502020-11-16 HIGH 7.5 CVE-2020-27174 In Amazon AWS Firecracker before 0.21.3, and 0.22.x before 0.22.1, the serial console buffer can grow its memory usage without limit when data is sen… Firecracker 0.21.3 / 0.22.1+ Fix from $1,9502020-10-16 MEDIUM 5.6 CVE-2020-8911 A padding oracle vulnerability exists in the AWS S3 Crypto SDK for GoLang versions prior to V2. The SDK allows users to encrypt files with AES-CBC wi… Aws S3 Crypto Sdk 2.0+ Fix from $1,6002020-08-11 MEDIUM 5.9 CVE-2020-16843 In Firecracker 0.20.x before 0.20.1 and 0.21.x before 0.21.2, the network stack can freeze under heavy ingress traffic. This can result in a denial o… Firecracker Mitigation only Fix from $1,6002020-08-04 HIGH 8.6 CVE-2020-15093 The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signatures. It allows an attacker t… Tough 0.7.1+ Fix from $1,9502020-07-09 MEDIUM 6.1 CVE-2019-14652 explorer.js in Amazon AWS JavaScript S3 Explorer (aka aws-js-s3-explorer) v2 alpha before 2019-08-02 allows XSS in certain circumstances. Aws Javascript S3 Explorer 2019-08-02+ Fix from $1,6002020-02-13 CRITICAL 9.8 CVE-2019-10777 In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function without any… Aws Lambda 1.0.5+ Fix from $2,3002020-01-08 CRITICAL 9.8 CVE-2019-3984 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input… Blink Xt2 Sync Module Firmware 2.3.11+ Fix from $2,3002019-12-31 CRITICAL 9.8 CVE-2019-3989 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input… Blink Xt2 Sync Module Firmware 2.13.11+ Fix from $2,3002019-12-11