Amazon kayıtları
amazon üreticisine ait 207 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 2 · %1
- Silahlaştırılmış
- 2 · %1
- Pre-auth RCE
- 17
- Düzeltme kaydı olan
- %44,4
- Yayından KEV’e ortanca
- 5 gün
Tekrar eden sınıflar
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')13
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor11
- CWE-295 Improper Certificate Validation9
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')9
- CWE-863 Incorrect Authorization8
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
207 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
90Hemen | CVE-2023-44487Silahlaştırılmış | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Yüksek7,5 | KEV | %100,0 | 10 Eki 2023 |
62Bu hafta | CVE-2024-6387Kavram kanıtı | Openssh: regresshion - race condition in ssh allows rce/dossonicwall · sma 6200 firmware · CWE-364 | Yüksek8,1 | — | %99,5 | 1 Tem 2024 |
62Bu hafta | CVE-2026-31431Silahlaştırılmış | crypto: algif_aead - Revert to operating out-of-placelinux · linux kernel · CWE-669 | Yüksek7,8 | KEV | %3,4 | 22 Nis 2026 |
41Planlayın | CVE-2012-4249İstismar yok | The Amazon Lab126 com.lab126.system sendEvent implementation on the Kindle Touch before 5.1.2 allows context-dependent attackers to execute amazon · kindle touch · CWE-94 | Kritik10,0 | — | %3,7 | 12 Ağu 2012 |
40Planlayın | CVE-2019-3984İstismar yok | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitiamazon · blink xt2 sync module firmware · CWE-78 | Kritik9,8 | — | %3,8 | 31 Ara 2019 |
40Planlayın | CVE-2019-3989İstismar yok | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitiamazon · blink xt2 sync module firmware · CWE-78 | Kritik9,8 | — | %3,7 | 11 Ara 2019 |
40Planlayın | CVE-2022-25809İstismar yok | Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on thesamazon · echo dot firmware | Kritik9,8 | — | %3,3 | 24 Şub 2022 |
40Planlayın | CVE-2019-18960İstismar yok | Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.0.amazon · firecracker · CWE-120 | Kritik9,8 | — | %3,3 | 11 Ara 2019 |
40Planlayın | CVE-2020-28472İstismar yok | This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0.amazon · aws sdk for javascipt | Kritik9,8 | — | %2,1 | 19 Oca 2021 |
40Planlayın | CVE-2015-7292İstismar yok | Stack-based buffer overflow in the havok_write function in drivers/staging/havok/havok.c in Amazon Fire OS before 2016-01-15 allows attackeramazon · fire os · CWE-119 | Kritik9,8 | — | %1,9 | 9 Nis 2017 |
39İzleyin | CVE-2024-28056İstismar yok | Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects.amazon · aws amplify cli · CWE-276 | Kritik9,8 | — | %1,7 | 15 Nis 2024 |
39İzleyin | CVE-2019-10777İstismar yok | In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function wiamazon · aws lambda · CWE-78 | Kritik9,8 | — | %1,6 | 8 Oca 2020 |
39İzleyin | CVE-2021-44833İstismar yok | The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.amazon · aws opensearch · CWE-276 | Kritik9,8 | — | %1,6 | 12 Ara 2021 |
39İzleyin | CVE-2021-31572İstismar yok | The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in stream_buffer.c for a stream buffer.amazon · freertos · CWE-190 | Kritik9,8 | — | %1,4 | 22 Nis 2021 |
39İzleyin | CVE-2021-31571İstismar yok | The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in queue.c for queue creation.amazon · freertos · CWE-190 | Kritik9,8 | — | %1,4 | 22 Nis 2021 |
39İzleyin | CVE-2021-32020İstismar yok | The kernel in Amazon Web Services FreeRTOS before 10.4.3 has insufficient bounds checking during management of heap memory.amazon · freertos · CWE-119 | Kritik9,8 | — | %1,3 | 3 May 2021 |
39İzleyin | CVE-2025-20286İstismar yok | ISE on AWS Static Credentialcisco · identity services engine · CWE-259 | Kritik9,8 | — | %1,1 | 4 Haz 2025 |
39İzleyin | CVE-2020-36363İstismar yok | Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, which some entitiamazon · amazon cloudfront · CWE-327 | Kritik9,8 | — | %0,7 | 12 Ağu 2021 |
39İzleyin | CVE-2022-4725İstismar yok | AWS SDK XML Parser XpathUtils.java XpathUtils server-side request forgeryamazon · aws software development kit · CWE-918 | Kritik9,8 | — | %0,7 | 27 Ara 2022 |
38İzleyin | CVE-2012-4248İstismar yok | The Amazon Kindle Touch before 5.1.2 does not properly restrict access to the libkindleplugin.so NPAPI plugin interface, which might allow ramazon · kindle touch · CWE-264 | Kritik9,3 | — | %3,5 | 12 Ağu 2012 |
37İzleyin | CVE-2021-30354İstismar yok | Amazon Kindle e-reader prior to and including version 5.13.4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in funcamazon · kindle firmware · CWE-680 | Yüksek8,6 | — | %8,4 | 1 Eyl 2021 |
37İzleyin | CVE-2021-38112İstismar yok | In the Amazon AWS WorkSpaces client 3.0.10 through 3.1.8 on Windows, argument injection in the workspaces:// URI handler can lead to remote amazon · aws workspaces · CWE-88 | Yüksek8,8 | — | %7,5 | 21 Eyl 2021 |
37İzleyin | CVE-2026-77234İstismar yok | Improper input validation in FreeRTOS-Kernel timer command handlingamazon · freertos · CWE-863 | Kritik9,3 | — | %0,2 | 21 Ağu 2026 |
36İzleyin | CVE-2021-30355İstismar yok | Amazon Kindle e-reader prior to and including version 5.13.4 improperly manages privileges, allowing the framework user to elevate privilegeamazon · kindle firmware · CWE-269 | Yüksek8,6 | — | %6,9 | 1 Eyl 2021 |
36İzleyin | CVE-2018-1169İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Amazon Music Player 6.1.5.1213.amazon · amazon music · CWE-78 | Yüksek8,8 | — | %2,5 | 1 Mar 2018 |
- CVE-2023-4448790Hemen
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 Eki 2023
- CVE-2024-638762Bu hafta
Openssh: regresshion - race condition in ssh allows rce/dos
YüksekCVSS 8,1Kavram kanıtıEPSS %100sonicwall · sma 6200 firmware1 Tem 2024
- CVE-2026-3143162Bu hafta
crypto: algif_aead - Revert to operating out-of-place
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %3linux · linux kernel22 Nis 2026
- CVE-2012-424941Planlayın
The Amazon Lab126 com.lab126.system sendEvent implementation on the Kindle Touch before 5.1.2 allows context-dependent attackers to execute
KritikCVSS 10,0İstismar yokEPSS %4amazon · kindle touch12 Ağu 2012
- CVE-2019-398440Planlayın
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly saniti
KritikCVSS 9,8İstismar yokEPSS %4amazon · blink xt2 sync module firmware31 Ara 2019
- CVE-2019-398940Planlayın
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly saniti
KritikCVSS 9,8İstismar yokEPSS %4amazon · blink xt2 sync module firmware11 Ara 2019
- CVE-2022-2580940Planlayın
Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on thes
KritikCVSS 9,8İstismar yokEPSS %3amazon · echo dot firmware24 Şub 2022
- CVE-2019-1896040Planlayın
Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.0.
KritikCVSS 9,8İstismar yokEPSS %3amazon · firecracker11 Ara 2019
- CVE-2020-2847240Planlayın
This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0.
KritikCVSS 9,8İstismar yokEPSS %2amazon · aws sdk for javascipt19 Oca 2021
- CVE-2015-729240Planlayın
Stack-based buffer overflow in the havok_write function in drivers/staging/havok/havok.c in Amazon Fire OS before 2016-01-15 allows attacker
KritikCVSS 9,8İstismar yokEPSS %2amazon · fire os9 Nis 2017
- CVE-2024-2805639İzleyin
Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects.
KritikCVSS 9,8İstismar yokEPSS %2amazon · aws amplify cli15 Nis 2024
- CVE-2019-1077739İzleyin
In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function wi
KritikCVSS 9,8İstismar yokEPSS %2amazon · aws lambda8 Oca 2020
- CVE-2021-4483339İzleyin
The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.
KritikCVSS 9,8İstismar yokEPSS %2amazon · aws opensearch12 Ara 2021
- CVE-2021-3157239İzleyin
The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in stream_buffer.c for a stream buffer.
KritikCVSS 9,8İstismar yokEPSS %1amazon · freertos22 Nis 2021
- CVE-2021-3157139İzleyin
The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in queue.c for queue creation.
KritikCVSS 9,8İstismar yokEPSS %1amazon · freertos22 Nis 2021
- CVE-2021-3202039İzleyin
The kernel in Amazon Web Services FreeRTOS before 10.4.3 has insufficient bounds checking during management of heap memory.
KritikCVSS 9,8İstismar yokEPSS %1amazon · freertos3 May 2021
- CVE-2025-2028639İzleyin
ISE on AWS Static Credential
KritikCVSS 9,8İstismar yokEPSS %1cisco · identity services engine4 Haz 2025
- CVE-2020-3636339İzleyin
Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, which some entiti
KritikCVSS 9,8İstismar yokEPSS %1amazon · amazon cloudfront12 Ağu 2021
- CVE-2022-472539İzleyin
AWS SDK XML Parser XpathUtils.java XpathUtils server-side request forgery
KritikCVSS 9,8İstismar yokEPSS %1amazon · aws software development kit27 Ara 2022
- CVE-2012-424838İzleyin
The Amazon Kindle Touch before 5.1.2 does not properly restrict access to the libkindleplugin.so NPAPI plugin interface, which might allow r
KritikCVSS 9,3İstismar yokEPSS %3amazon · kindle touch12 Ağu 2012
- CVE-2021-3035437İzleyin
Amazon Kindle e-reader prior to and including version 5.13.4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in func
YüksekCVSS 8,6İstismar yokEPSS %8amazon · kindle firmware1 Eyl 2021
- CVE-2021-3811237İzleyin
In the Amazon AWS WorkSpaces client 3.0.10 through 3.1.8 on Windows, argument injection in the workspaces:// URI handler can lead to remote
YüksekCVSS 8,8İstismar yokEPSS %7amazon · aws workspaces21 Eyl 2021
- CVE-2026-7723437İzleyin
Improper input validation in FreeRTOS-Kernel timer command handling
KritikCVSS 9,3İstismar yokEPSS %0amazon · freertos21 Ağu 2026
- CVE-2021-3035536İzleyin
Amazon Kindle e-reader prior to and including version 5.13.4 improperly manages privileges, allowing the framework user to elevate privilege
YüksekCVSS 8,6İstismar yokEPSS %7amazon · kindle firmware1 Eyl 2021
- CVE-2018-116936İzleyin
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Amazon Music Player 6.1.5.1213.
YüksekCVSS 8,8İstismar yokEPSS %3amazon · amazon music1 Mar 2018