Skip to content
Noroxi

Amazon records

207 published records for vendor amazon.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

207 records
  • The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023

  • CVE-2024-6387
    62This week

    Openssh: regresshion - race condition in ssh allows rce/dos

    HighCVSS 8.1Proof of conceptEPSS 100%

    sonicwall · sma 6200 firmwareJul 1, 2024

  • CVE-2026-31431
    62This week

    crypto: algif_aead - Revert to operating out-of-place

    HighCVSS 7.8KEVWeaponizedEPSS 3%

    linux · linux kernelApr 22, 2026

  • The Amazon Lab126 com.lab126.system sendEvent implementation on the Kindle Touch before 5.1.2 allows context-dependent attackers to execute

    CriticalCVSS 10.0No exploitEPSS 4%

    amazon · kindle touchAug 12, 2012

  • Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly saniti

    CriticalCVSS 9.8No exploitEPSS 4%

    amazon · blink xt2 sync module firmwareDec 31, 2019

  • Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly saniti

    CriticalCVSS 9.8No exploitEPSS 4%

    amazon · blink xt2 sync module firmwareDec 11, 2019

  • Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on thes

    CriticalCVSS 9.8No exploitEPSS 3%

    amazon · echo dot firmwareFeb 24, 2022

  • Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.0.

    CriticalCVSS 9.8No exploitEPSS 3%

    amazon · firecrackerDec 11, 2019

  • This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0.

    CriticalCVSS 9.8No exploitEPSS 2%

    amazon · aws sdk for javasciptJan 19, 2021

  • Stack-based buffer overflow in the havok_write function in drivers/staging/havok/havok.c in Amazon Fire OS before 2016-01-15 allows attacker

    CriticalCVSS 9.8No exploitEPSS 2%

    amazon · fire osApr 9, 2017

  • Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects.

    CriticalCVSS 9.8No exploitEPSS 2%

    amazon · aws amplify cliApr 15, 2024

  • In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function wi

    CriticalCVSS 9.8No exploitEPSS 2%

    amazon · aws lambdaJan 8, 2020

  • The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.

    CriticalCVSS 9.8No exploitEPSS 2%

    amazon · aws opensearchDec 12, 2021

  • The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in stream_buffer.c for a stream buffer.

    CriticalCVSS 9.8No exploitEPSS 1%

    amazon · freertosApr 22, 2021

  • The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in queue.c for queue creation.

    CriticalCVSS 9.8No exploitEPSS 1%

    amazon · freertosApr 22, 2021

  • The kernel in Amazon Web Services FreeRTOS before 10.4.3 has insufficient bounds checking during management of heap memory.

    CriticalCVSS 9.8No exploitEPSS 1%

    amazon · freertosMay 3, 2021

  • ISE on AWS Static Credential

    CriticalCVSS 9.8No exploitEPSS 1%

    cisco · identity services engineJun 4, 2025

  • Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, which some entiti

    CriticalCVSS 9.8No exploitEPSS 1%

    amazon · amazon cloudfrontAug 12, 2021

  • CVE-2022-4725
    39Monitor

    AWS SDK XML Parser XpathUtils.java XpathUtils server-side request forgery

    CriticalCVSS 9.8No exploitEPSS 1%

    amazon · aws software development kitDec 27, 2022

  • CVE-2012-4248
    38Monitor

    The Amazon Kindle Touch before 5.1.2 does not properly restrict access to the libkindleplugin.so NPAPI plugin interface, which might allow r

    CriticalCVSS 9.3No exploitEPSS 3%

    amazon · kindle touchAug 12, 2012

  • Amazon Kindle e-reader prior to and including version 5.13.4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in func

    HighCVSS 8.6No exploitEPSS 8%

    amazon · kindle firmwareSep 1, 2021

  • In the Amazon AWS WorkSpaces client 3.0.10 through 3.1.8 on Windows, argument injection in the workspaces:// URI handler can lead to remote

    HighCVSS 8.8No exploitEPSS 7%

    amazon · aws workspacesSep 21, 2021

  • Improper input validation in FreeRTOS-Kernel timer command handling

    CriticalCVSS 9.3No exploitEPSS 0%

    amazon · freertosAug 21, 2026

  • Amazon Kindle e-reader prior to and including version 5.13.4 improperly manages privileges, allowing the framework user to elevate privilege

    HighCVSS 8.6No exploitEPSS 7%

    amazon · kindle firmwareSep 1, 2021

  • CVE-2018-1169
    36Monitor

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Amazon Music Player 6.1.5.1213.

    HighCVSS 8.8No exploitEPSS 3%

    amazon · amazon musicMar 1, 2018