İçeriğe atla
Noroxi

Amazon kayıtları

amazon üreticisine ait 207 yayımlanmış kayıt.

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

207 kayıt
  • The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100

    siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 Eki 2023

  • CVE-2024-6387
    62Bu hafta

    Openssh: regresshion - race condition in ssh allows rce/dos

    YüksekCVSS 8,1Kavram kanıtıEPSS %100

    sonicwall · sma 6200 firmware1 Tem 2024

  • CVE-2026-31431
    62Bu hafta

    crypto: algif_aead - Revert to operating out-of-place

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %3

    linux · linux kernel22 Nis 2026

  • CVE-2012-4249
    41Planlayın

    The Amazon Lab126 com.lab126.system sendEvent implementation on the Kindle Touch before 5.1.2 allows context-dependent attackers to execute

    KritikCVSS 10,0İstismar yokEPSS %4

    amazon · kindle touch12 Ağu 2012

  • CVE-2019-3984
    40Planlayın

    Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly saniti

    KritikCVSS 9,8İstismar yokEPSS %4

    amazon · blink xt2 sync module firmware31 Ara 2019

  • CVE-2019-3989
    40Planlayın

    Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly saniti

    KritikCVSS 9,8İstismar yokEPSS %4

    amazon · blink xt2 sync module firmware11 Ara 2019

  • CVE-2022-25809
    40Planlayın

    Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on thes

    KritikCVSS 9,8İstismar yokEPSS %3

    amazon · echo dot firmware24 Şub 2022

  • CVE-2019-18960
    40Planlayın

    Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.0.

    KritikCVSS 9,8İstismar yokEPSS %3

    amazon · firecracker11 Ara 2019

  • CVE-2020-28472
    40Planlayın

    This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0.

    KritikCVSS 9,8İstismar yokEPSS %2

    amazon · aws sdk for javascipt19 Oca 2021

  • CVE-2015-7292
    40Planlayın

    Stack-based buffer overflow in the havok_write function in drivers/staging/havok/havok.c in Amazon Fire OS before 2016-01-15 allows attacker

    KritikCVSS 9,8İstismar yokEPSS %2

    amazon · fire os9 Nis 2017

  • CVE-2024-28056
    39İzleyin

    Amazon AWS Amplify CLI before 12.10.1 incorrectly configures the role trust policy of IAM roles associated with Amplify projects.

    KritikCVSS 9,8İstismar yokEPSS %2

    amazon · aws amplify cli15 Nis 2024

  • CVE-2019-10777
    39İzleyin

    In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function wi

    KritikCVSS 9,8İstismar yokEPSS %2

    amazon · aws lambda8 Oca 2020

  • CVE-2021-44833
    39İzleyin

    The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.

    KritikCVSS 9,8İstismar yokEPSS %2

    amazon · aws opensearch12 Ara 2021

  • CVE-2021-31572
    39İzleyin

    The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in stream_buffer.c for a stream buffer.

    KritikCVSS 9,8İstismar yokEPSS %1

    amazon · freertos22 Nis 2021

  • CVE-2021-31571
    39İzleyin

    The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in queue.c for queue creation.

    KritikCVSS 9,8İstismar yokEPSS %1

    amazon · freertos22 Nis 2021

  • CVE-2021-32020
    39İzleyin

    The kernel in Amazon Web Services FreeRTOS before 10.4.3 has insufficient bounds checking during management of heap memory.

    KritikCVSS 9,8İstismar yokEPSS %1

    amazon · freertos3 May 2021

  • CVE-2025-20286
    39İzleyin

    ISE on AWS Static Credential

    KritikCVSS 9,8İstismar yokEPSS %1

    cisco · identity services engine4 Haz 2025

  • CVE-2020-36363
    39İzleyin

    Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, which some entiti

    KritikCVSS 9,8İstismar yokEPSS %1

    amazon · amazon cloudfront12 Ağu 2021

  • CVE-2022-4725
    39İzleyin

    AWS SDK XML Parser XpathUtils.java XpathUtils server-side request forgery

    KritikCVSS 9,8İstismar yokEPSS %1

    amazon · aws software development kit27 Ara 2022

  • CVE-2012-4248
    38İzleyin

    The Amazon Kindle Touch before 5.1.2 does not properly restrict access to the libkindleplugin.so NPAPI plugin interface, which might allow r

    KritikCVSS 9,3İstismar yokEPSS %3

    amazon · kindle touch12 Ağu 2012

  • CVE-2021-30354
    37İzleyin

    Amazon Kindle e-reader prior to and including version 5.13.4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in func

    YüksekCVSS 8,6İstismar yokEPSS %8

    amazon · kindle firmware1 Eyl 2021

  • CVE-2021-38112
    37İzleyin

    In the Amazon AWS WorkSpaces client 3.0.10 through 3.1.8 on Windows, argument injection in the workspaces:// URI handler can lead to remote

    YüksekCVSS 8,8İstismar yokEPSS %7

    amazon · aws workspaces21 Eyl 2021

  • CVE-2026-77234
    37İzleyin

    Improper input validation in FreeRTOS-Kernel timer command handling

    KritikCVSS 9,3İstismar yokEPSS %0

    amazon · freertos21 Ağu 2026

  • CVE-2021-30355
    36İzleyin

    Amazon Kindle e-reader prior to and including version 5.13.4 improperly manages privileges, allowing the framework user to elevate privilege

    YüksekCVSS 8,6İstismar yokEPSS %7

    amazon · kindle firmware1 Eyl 2021

  • CVE-2018-1169
    36İzleyin

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Amazon Music Player 6.1.5.1213.

    YüksekCVSS 8,8İstismar yokEPSS %3

    amazon · amazon music1 Mar 2018