VYPR

Vendor CVEs

Amazon

All CVEs

224 total · sorted by risk
  • CVE-2024-37293HigJun 11, 2024
    risk 0.00cvss 7.5epss 0.00

    The AWS Deployment Framework (ADF) is a framework to manage and deploy resources across multiple AWS accounts and regions within an AWS Organization. ADF allows for staged, parallel, multi-account, cross-region deployments of applications or resources via the structure defined…

  • CVE-2023-51386HigDec 22, 2023
    risk 0.00cvss 7.8epss 0.00

    Sandbox Accounts for Events provides multiple, temporary AWS accounts to a number of authenticated users simultaneously via a browser-based GUI. Authenticated users could potentially read data from the events table by sending request payloads to the events API, collecting…

  • CVE-2023-50928HigDec 22, 2023
    risk 0.00cvss 7.1epss 0.00

    "Sandbox Accounts for Events" provides multiple, temporary AWS accounts to a number of authenticated users simultaneously via a browser-based GUI. Authenticated users could potentially claim and access empty AWS accounts by sending request payloads to the account API containing…

  • CVE-2023-36467HigJun 28, 2023
    risk 0.00cvss 8.0epss 0.01

    AWS data.all is an open source development framework to help users build a data marketplace on Amazon Web Services. data.all versions 1.2.0 through 1.5.1 do not prevent remote code execution when a user injects Python commands into the ‘Template’ field when configuring a…

  • CVE-2022-41917MedNov 16, 2022
    risk 0.00cvss 4.3epss 0.01

    OpenSearch is a community-driven, open source fork of Elasticsearch and Kibana. OpenSearch allows users to specify a local file when defining text analyzers to process data for text analysis. An issue in the implementation of this feature allows certain specially crafted queries…

  • CVE-2022-41906HigNov 11, 2022
    risk 0.00cvss 8.7epss 0.01

    OpenSearch Notifications is a notifications plugin for OpenSearch that enables other plugins to send notifications via Email, Slack, Amazon Chime, Custom web-hook etc channels. A potential SSRF issue in OpenSearch Notifications Plugin starting in 2.0.0 and prior to 2.2.1 could…

  • CVE-2022-29527HigApr 20, 2022
    risk 0.00cvss 7.0epss 0.00

    Amazon AWS amazon-ssm-agent before 3.1.1208.0 creates a world-writable sudoers file, which allows local attackers to inject Sudo rules and escalate privileges to root. This occurs in certain situations involving a race condition.

  • CVE-2021-44833CriDec 12, 2021
    risk 0.00cvss 9.8epss 0.02

    The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.

  • CVE-2021-43811HigDec 8, 2021
    risk 0.00cvss 7.8epss 0.02

    Sockeye is an open-source sequence-to-sequence framework for Neural Machine Translation built on PyTorch. Sockeye uses YAML to store model and data configurations on disk. Versions below 2.3.24 use unsafe YAML loading, which can be made to execute arbitrary code embedded in…

  • CVE-2021-31828HigMay 6, 2021
    risk 0.00cvss 7.1epss 0.01

    An SSRF issue in Open Distro for Elasticsearch (ODFE) before 1.13.1.0 allows an existing privileged user to enumerate listening services or interact with configured resources via HTTP requests exceeding the Alerting plugin's intended scope.

  • CVE-2021-32020CriMay 3, 2021
    risk 0.00cvss 9.8epss 0.01

    The kernel in Amazon Web Services FreeRTOS before 10.4.3 has insufficient bounds checking during management of heap memory.

  • CVE-2021-31572CriApr 22, 2021
    risk 0.00cvss 9.8epss 0.01

    The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in stream_buffer.c for a stream buffer.

  • CVE-2021-31571CriApr 22, 2021
    risk 0.00cvss 9.8epss 0.01

    The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in queue.c for queue creation.

  • CVE-2020-27174HigOct 16, 2020
    risk 0.00cvss 7.5epss 0.02

    In Amazon AWS Firecracker before 0.21.3, and 0.22.x before 0.22.1, the serial console buffer can grow its memory usage without limit when data is sent to the standard input. This can result in a memory leak on the microVM emulation thread, possibly occupying more memory than…

  • CVE-2019-14652MedFeb 13, 2020
    risk 0.00cvss 6.1epss 0.01

    explorer.js in Amazon AWS JavaScript S3 Explorer (aka aws-js-s3-explorer) v2 alpha before 2019-08-02 allows XSS in certain circumstances.

  • CVE-2014-7032Oct 16, 2014
    risk 0.00cvss epss 0.00

    The MYHABIT (aka com.amazon.myhabit) application @7F080041 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

  • CVE-2014-3908Aug 30, 2014
    risk 0.00cvss epss 0.01

    The Amazon.com Kindle application before 4.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

  • CVE-2012-5782Nov 4, 2012
    risk 0.00cvss epss 0.01

    Amazon Flexible Payments Service (FPS) PHP Library does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary…

  • CVE-2012-5781Nov 4, 2012
    risk 0.00cvss epss 0.01

    Amazon Elastic Load Balancing API Tools does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid…

  • CVE-2012-5780Nov 4, 2012
    risk 0.00cvss epss 0.01

    The Amazon merchant SDK does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

  • CVE-2010-5268Sep 7, 2012
    risk 0.00cvss epss 0.00

    Untrusted search path vulnerability in Amazon Kindle for PC 1.3.0 30884 allows local users to gain privileges via a Trojan horse wintab32.dll file in the current working directory, as demonstrated by a directory that contains a .azw file. NOTE: some of these details are…

  • CVE-2012-4249Aug 12, 2012
    risk 0.00cvss epss 0.04

    The Amazon Lab126 com.lab126.system sendEvent implementation on the Kindle Touch before 5.1.2 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a string, as demonstrated by using lipc-set-prop to set an LIPC property, a different…

  • CVE-2012-4248Aug 12, 2012
    risk 0.00cvss epss 0.03

    The Amazon Kindle Touch before 5.1.2 does not properly restrict access to the libkindleplugin.so NPAPI plugin interface, which might allow remote attackers to have an unspecified impact via vectors involving the (1) dev.log, (2) lipc.set, (3) lipc.get, or (4) todo.scheduleItems…

  • CVE-2005-4044Dec 6, 2005
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in search.cgi in Amazon Search Directory 1.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly the search parameter.

Page 5 of 5