Перейти к содержимому
Noroxi

Записи Amazon

207 опубликованных записей вендора amazon.

Профиль для исследователя

Попали в KEV
2 · 1 %
С эксплойтом
2 · 1 %
Pre-auth RCE
17
С записью об исправлении
44,4 %
Медиана: публикация → KEV
5 дн.

Охват bug bounty

Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.

Все записи

207 записей
  • CVE-2023-44487
    90Срочно

    The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %

    siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 окт. 2023 г.

  • CVE-2024-6387
    62На этой неделе

    Openssh: regresshion - race condition in ssh allows rce/dos

    ВысокаяCVSS 8,1Proof of conceptEPSS 100 %

    sonicwall · sma 6200 firmware1 июл. 2024 г.

  • CVE-2026-31431
    62На этой неделе

    crypto: algif_aead - Revert to operating out-of-place

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 3 %

    linux · linux kernel22 апр. 2026 г.

  • CVE-2012-4249
    41В плане

    The Amazon Lab126 com.lab126.system sendEvent implementation on the Kindle Touch before 5.1.2 allows context-dependent attackers to execute

    КритическаяCVSS 10,0Эксплойта нетEPSS 4 %

    amazon · kindle touch12 авг. 2012 г.

  • CVE-2019-3984
    40В плане

    Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly saniti

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    amazon · blink xt2 sync module firmware31 дек. 2019 г.

  • CVE-2019-3989
    40В плане

    Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly saniti

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    amazon · blink xt2 sync module firmware11 дек. 2019 г.

  • CVE-2022-25809
    40В плане

    Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on thes

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    amazon · echo dot firmware24 февр. 2022 г.

  • CVE-2019-18960
    40В плане

    Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.0.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    amazon · firecracker11 дек. 2019 г.

  • CVE-2020-28472
    40В плане

    This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    amazon · aws sdk for javascipt19 янв. 2021 г.

  • CVE-2015-7292
    40В плане

    Stack-based buffer overflow in the havok_write function in drivers/staging/havok/havok.c in Amazon Fire OS before 2016-01-15 allows attacker

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    amazon · fire os9 апр. 2017 г.

  • CVE-2024-28056
    39Наблюдать

    Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    amazon · aws amplify cli15 апр. 2024 г.

  • CVE-2019-10777
    39Наблюдать

    In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function wi

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    amazon · aws lambda8 янв. 2020 г.

  • CVE-2021-44833
    39Наблюдать

    The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    amazon · aws opensearch12 дек. 2021 г.

  • CVE-2021-31572
    39Наблюдать

    The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in stream_buffer.c for a stream buffer.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    amazon · freertos22 апр. 2021 г.

  • CVE-2021-31571
    39Наблюдать

    The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in queue.c for queue creation.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    amazon · freertos22 апр. 2021 г.

  • CVE-2021-32020
    39Наблюдать

    The kernel in Amazon Web Services FreeRTOS before 10.4.3 has insufficient bounds checking during management of heap memory.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    amazon · freertos3 мая 2021 г.

  • CVE-2025-20286
    39Наблюдать

    ISE on AWS Static Credential

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    cisco · identity services engine4 июн. 2025 г.

  • CVE-2020-36363
    39Наблюдать

    Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, which some entiti

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    amazon · amazon cloudfront12 авг. 2021 г.

  • CVE-2022-4725
    39Наблюдать

    AWS SDK XML Parser XpathUtils.java XpathUtils server-side request forgery

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    amazon · aws software development kit27 дек. 2022 г.

  • CVE-2012-4248
    38Наблюдать

    The Amazon Kindle Touch before 5.1.2 does not properly restrict access to the libkindleplugin.so NPAPI plugin interface, which might allow r

    КритическаяCVSS 9,3Эксплойта нетEPSS 3 %

    amazon · kindle touch12 авг. 2012 г.

  • CVE-2021-30354
    37Наблюдать

    Amazon Kindle e-reader prior to and including version 5.13.4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in func

    ВысокаяCVSS 8,6Эксплойта нетEPSS 8 %

    amazon · kindle firmware1 сент. 2021 г.

  • CVE-2021-38112
    37Наблюдать

    In the Amazon AWS WorkSpaces client 3.0.10 through 3.1.8 on Windows, argument injection in the workspaces:// URI handler can lead to remote

    ВысокаяCVSS 8,8Эксплойта нетEPSS 7 %

    amazon · aws workspaces21 сент. 2021 г.

  • CVE-2026-77234
    37Наблюдать

    Improper input validation in FreeRTOS-Kernel timer command handling

    КритическаяCVSS 9,3Эксплойта нетEPSS 0 %

    amazon · freertos21 авг. 2026 г.

  • CVE-2021-30355
    36Наблюдать

    Amazon Kindle e-reader prior to and including version 5.13.4 improperly manages privileges, allowing the framework user to elevate privilege

    ВысокаяCVSS 8,6Эксплойта нетEPSS 7 %

    amazon · kindle firmware1 сент. 2021 г.

  • CVE-2018-1169
    36Наблюдать

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Amazon Music Player 6.1.5.1213.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    amazon · amazon music1 мар. 2018 г.