Vulnerabilities > Amazon > Fire OS > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-05-03 CVE-2023-1384 Cross-site Scripting vulnerability in Amazon Fire OS
The setMediaSource function on the amzn.thin.pl service does not sanitize the "source" parameter allowing for arbitrary javascript code to be run This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS versions prior to 7.6.3.3.
network
low complexity
amazon CWE-79
6.1
2023-05-03 CVE-2023-1383 Unspecified vulnerability in Amazon Fire OS
An Improper Enforcement of Behavioral Workflow vulnerability in the exchangeDeviceServices function on the amzn.dmgr service allowed an attacker to register services that are only locally accessible. This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5.
low complexity
amazon
4.3
2018-10-16 CVE-2018-11020 Argument Injection or Modification vulnerability in Amazon Fire OS 4.5.5.3
kernel/omap/drivers/rpmsg/rpmsg_omx.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device file /dev/rpmsg-omx1 with the command 3221772291, and cause a kernel crash.
local
low complexity
amazon CWE-88
4.4