Vulnerabilities > Amazon > Firecracker

DATE CVE VULNERABILITY TITLE RISK
2020-10-16 CVE-2020-27174 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Amazon Firecracker
In Amazon AWS Firecracker before 0.21.3, and 0.22.x before 0.22.1, the serial console buffer can grow its memory usage without limit when data is sent to the standard input.
network
low complexity
amazon CWE-119
5.0
2020-08-04 CVE-2020-16843 Unspecified vulnerability in Amazon Firecracker 0.20.0/0.21.0/0.21.1
In Firecracker 0.20.x before 0.20.1 and 0.21.x before 0.21.2, the network stack can freeze under heavy ingress traffic.
network
amazon
4.3
2019-12-11 CVE-2019-18960 Classic Buffer Overflow vulnerability in Amazon Firecracker 0.18.0/0.19.0
Firecracker vsock implementation buffer overflow in versions 0.18.0 and 0.19.0.
network
low complexity
amazon CWE-120
7.5