Записи Amazon
207 опубликованных записей вендора amazon.
Профиль для исследователя
- Попали в KEV
- 2 · 1 %
- С эксплойтом
- 2 · 1 %
- Pre-auth RCE
- 17
- С записью об исправлении
- 44,4 %
- Медиана: публикация → KEV
- 5 дн.
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')13
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor11
- CWE-295 Improper Certificate Validation9
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')9
- CWE-863 Incorrect Authorization8
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
- Amazon Vulnerability Research ProgramHackerOne · с вознаграждением
- AWS VDPHackerOne · только раскрытие (VDP)
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
207 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
90Срочно | CVE-2023-44487Готовый эксплойт | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Высокая7,5 | KEV | 100,0 % | 10 окт. 2023 г. |
62На этой неделе | CVE-2024-6387Proof of concept | Openssh: regresshion - race condition in ssh allows rce/dossonicwall · sma 6200 firmware · CWE-364 | Высокая8,1 | — | 99,5 % | 1 июл. 2024 г. |
62На этой неделе | CVE-2026-31431Готовый эксплойт | crypto: algif_aead - Revert to operating out-of-placelinux · linux kernel · CWE-669 | Высокая7,8 | KEV | 3,4 % | 22 апр. 2026 г. |
41В плане | CVE-2012-4249Эксплойта нет | The Amazon Lab126 com.lab126.system sendEvent implementation on the Kindle Touch before 5.1.2 allows context-dependent attackers to execute amazon · kindle touch · CWE-94 | Критическая10,0 | — | 3,7 % | 12 авг. 2012 г. |
40В плане | CVE-2019-3984Эксплойта нет | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitiamazon · blink xt2 sync module firmware · CWE-78 | Критическая9,8 | — | 3,8 % | 31 дек. 2019 г. |
40В плане | CVE-2019-3989Эксплойта нет | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitiamazon · blink xt2 sync module firmware · CWE-78 | Критическая9,8 | — | 3,7 % | 11 дек. 2019 г. |
40В плане | CVE-2022-25809Эксплойта нет | Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on thesamazon · echo dot firmware | Критическая9,8 | — | 3,3 % | 24 февр. 2022 г. |
40В плане | CVE-2019-18960Эксплойта нет | Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.0.amazon · firecracker · CWE-120 | Критическая9,8 | — | 3,3 % | 11 дек. 2019 г. |
40В плане | CVE-2020-28472Эксплойта нет | This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0.amazon · aws sdk for javascipt | Критическая9,8 | — | 2,1 % | 19 янв. 2021 г. |
40В плане | CVE-2015-7292Эксплойта нет | Stack-based buffer overflow in the havok_write function in drivers/staging/havok/havok.c in Amazon Fire OS before 2016-01-15 allows attackeramazon · fire os · CWE-119 | Критическая9,8 | — | 1,9 % | 9 апр. 2017 г. |
39Наблюдать | CVE-2024-28056Эксплойта нет | Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects.amazon · aws amplify cli · CWE-276 | Критическая9,8 | — | 1,7 % | 15 апр. 2024 г. |
39Наблюдать | CVE-2019-10777Эксплойта нет | In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function wiamazon · aws lambda · CWE-78 | Критическая9,8 | — | 1,6 % | 8 янв. 2020 г. |
39Наблюдать | CVE-2021-44833Эксплойта нет | The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.amazon · aws opensearch · CWE-276 | Критическая9,8 | — | 1,6 % | 12 дек. 2021 г. |
39Наблюдать | CVE-2021-31572Эксплойта нет | The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in stream_buffer.c for a stream buffer.amazon · freertos · CWE-190 | Критическая9,8 | — | 1,4 % | 22 апр. 2021 г. |
39Наблюдать | CVE-2021-31571Эксплойта нет | The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in queue.c for queue creation.amazon · freertos · CWE-190 | Критическая9,8 | — | 1,4 % | 22 апр. 2021 г. |
39Наблюдать | CVE-2021-32020Эксплойта нет | The kernel in Amazon Web Services FreeRTOS before 10.4.3 has insufficient bounds checking during management of heap memory.amazon · freertos · CWE-119 | Критическая9,8 | — | 1,3 % | 3 мая 2021 г. |
39Наблюдать | CVE-2025-20286Эксплойта нет | ISE on AWS Static Credentialcisco · identity services engine · CWE-259 | Критическая9,8 | — | 1,1 % | 4 июн. 2025 г. |
39Наблюдать | CVE-2020-36363Эксплойта нет | Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, which some entitiamazon · amazon cloudfront · CWE-327 | Критическая9,8 | — | 0,7 % | 12 авг. 2021 г. |
39Наблюдать | CVE-2022-4725Эксплойта нет | AWS SDK XML Parser XpathUtils.java XpathUtils server-side request forgeryamazon · aws software development kit · CWE-918 | Критическая9,8 | — | 0,7 % | 27 дек. 2022 г. |
38Наблюдать | CVE-2012-4248Эксплойта нет | The Amazon Kindle Touch before 5.1.2 does not properly restrict access to the libkindleplugin.so NPAPI plugin interface, which might allow ramazon · kindle touch · CWE-264 | Критическая9,3 | — | 3,5 % | 12 авг. 2012 г. |
37Наблюдать | CVE-2021-30354Эксплойта нет | Amazon Kindle e-reader prior to and including version 5.13.4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in funcamazon · kindle firmware · CWE-680 | Высокая8,6 | — | 8,4 % | 1 сент. 2021 г. |
37Наблюдать | CVE-2021-38112Эксплойта нет | In the Amazon AWS WorkSpaces client 3.0.10 through 3.1.8 on Windows, argument injection in the workspaces:// URI handler can lead to remote amazon · aws workspaces · CWE-88 | Высокая8,8 | — | 7,5 % | 21 сент. 2021 г. |
37Наблюдать | CVE-2026-77234Эксплойта нет | Improper input validation in FreeRTOS-Kernel timer command handlingamazon · freertos · CWE-863 | Критическая9,3 | — | 0,2 % | 21 авг. 2026 г. |
36Наблюдать | CVE-2021-30355Эксплойта нет | Amazon Kindle e-reader prior to and including version 5.13.4 improperly manages privileges, allowing the framework user to elevate privilegeamazon · kindle firmware · CWE-269 | Высокая8,6 | — | 6,9 % | 1 сент. 2021 г. |
36Наблюдать | CVE-2018-1169Эксплойта нет | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Amazon Music Player 6.1.5.1213.amazon · amazon music · CWE-78 | Высокая8,8 | — | 2,5 % | 1 мар. 2018 г. |
- CVE-2023-4448790Срочно
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 окт. 2023 г.
- CVE-2024-638762На этой неделе
Openssh: regresshion - race condition in ssh allows rce/dos
ВысокаяCVSS 8,1Proof of conceptEPSS 100 %sonicwall · sma 6200 firmware1 июл. 2024 г.
- CVE-2026-3143162На этой неделе
crypto: algif_aead - Revert to operating out-of-place
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 3 %linux · linux kernel22 апр. 2026 г.
- CVE-2012-424941В плане
The Amazon Lab126 com.lab126.system sendEvent implementation on the Kindle Touch before 5.1.2 allows context-dependent attackers to execute
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %amazon · kindle touch12 авг. 2012 г.
- CVE-2019-398440В плане
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly saniti
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %amazon · blink xt2 sync module firmware31 дек. 2019 г.
- CVE-2019-398940В плане
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly saniti
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %amazon · blink xt2 sync module firmware11 дек. 2019 г.
- CVE-2022-2580940В плане
Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on thes
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %amazon · echo dot firmware24 февр. 2022 г.
- CVE-2019-1896040В плане
Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %amazon · firecracker11 дек. 2019 г.
- CVE-2020-2847240В плане
This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %amazon · aws sdk for javascipt19 янв. 2021 г.
- CVE-2015-729240В плане
Stack-based buffer overflow in the havok_write function in drivers/staging/havok/havok.c in Amazon Fire OS before 2016-01-15 allows attacker
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %amazon · fire os9 апр. 2017 г.
- CVE-2024-2805639Наблюдать
Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %amazon · aws amplify cli15 апр. 2024 г.
- CVE-2019-1077739Наблюдать
In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function wi
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %amazon · aws lambda8 янв. 2020 г.
- CVE-2021-4483339Наблюдать
The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %amazon · aws opensearch12 дек. 2021 г.
- CVE-2021-3157239Наблюдать
The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in stream_buffer.c for a stream buffer.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %amazon · freertos22 апр. 2021 г.
- CVE-2021-3157139Наблюдать
The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in queue.c for queue creation.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %amazon · freertos22 апр. 2021 г.
- CVE-2021-3202039Наблюдать
The kernel in Amazon Web Services FreeRTOS before 10.4.3 has insufficient bounds checking during management of heap memory.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %amazon · freertos3 мая 2021 г.
- CVE-2025-2028639Наблюдать
ISE on AWS Static Credential
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %cisco · identity services engine4 июн. 2025 г.
- CVE-2020-3636339Наблюдать
Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, which some entiti
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %amazon · amazon cloudfront12 авг. 2021 г.
- CVE-2022-472539Наблюдать
AWS SDK XML Parser XpathUtils.java XpathUtils server-side request forgery
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %amazon · aws software development kit27 дек. 2022 г.
- CVE-2012-424838Наблюдать
The Amazon Kindle Touch before 5.1.2 does not properly restrict access to the libkindleplugin.so NPAPI plugin interface, which might allow r
КритическаяCVSS 9,3Эксплойта нетEPSS 3 %amazon · kindle touch12 авг. 2012 г.
- CVE-2021-3035437Наблюдать
Amazon Kindle e-reader prior to and including version 5.13.4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in func
ВысокаяCVSS 8,6Эксплойта нетEPSS 8 %amazon · kindle firmware1 сент. 2021 г.
- CVE-2021-3811237Наблюдать
In the Amazon AWS WorkSpaces client 3.0.10 through 3.1.8 on Windows, argument injection in the workspaces:// URI handler can lead to remote
ВысокаяCVSS 8,8Эксплойта нетEPSS 7 %amazon · aws workspaces21 сент. 2021 г.
- CVE-2026-7723437Наблюдать
Improper input validation in FreeRTOS-Kernel timer command handling
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %amazon · freertos21 авг. 2026 г.
- CVE-2021-3035536Наблюдать
Amazon Kindle e-reader prior to and including version 5.13.4 improperly manages privileges, allowing the framework user to elevate privilege
ВысокаяCVSS 8,6Эксплойта нетEPSS 7 %amazon · kindle firmware1 сент. 2021 г.
- CVE-2018-116936Наблюдать
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Amazon Music Player 6.1.5.1213.
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %amazon · amazon music1 мар. 2018 г.