Vulnerabilities > Amazon

DATE CVE VULNERABILITY TITLE RISK
2018-12-06 CVE-2018-16523 Divide By Zero vulnerability in Amazon web Services Freertos and Freertos
Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component allow division by zero in prvCheckOptions.
network
amazon CWE-369
5.8
2018-12-06 CVE-2018-16522 Access of Uninitialized Pointer vulnerability in Amazon web Services Freertos
Amazon Web Services (AWS) FreeRTOS through 1.3.1 has an uninitialized pointer free in SOCKETS_SetSockOpt.
network
amazon CWE-824
6.8
2018-11-14 CVE-2018-19190 Cross-site Scripting vulnerability in Amazon Payfort-PHP-Sdk
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the error.php error_msg parameter.
network
amazon CWE-79
4.3
2018-11-14 CVE-2018-19189 Cross-site Scripting vulnerability in Amazon Payfort-PHP-Sdk
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in an error.php echo statement.
network
amazon CWE-79
4.3
2018-11-14 CVE-2018-19188 Cross-site Scripting vulnerability in Amazon Payfort-PHP-Sdk
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the success.php fort_id parameter.
network
amazon CWE-79
4.3
2018-11-14 CVE-2018-19187 Cross-site Scripting vulnerability in Amazon Payfort-PHP-Sdk
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in a success.php echo statement.
network
amazon CWE-79
4.3
2018-11-14 CVE-2018-19186 Cross-site Scripting vulnerability in Amazon Payfort-PHP-Sdk
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the route.php paymentMethod parameter.
network
amazon CWE-79
4.3
2018-10-16 CVE-2018-11025 Argument Injection or Modification vulnerability in Amazon Fire OS 4.5.5.3
kernel/omap/drivers/mfd/twl6030-gpadc.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device /dev/twl6030-gpadc with the command 24832 and cause a kernel crash.
network
low complexity
amazon CWE-88
7.8
2018-10-16 CVE-2018-11024 Argument Injection or Modification vulnerability in Amazon Fire OS 4.5.5.3
kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD (3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device /dev/gcioctl with the command 1077435789 and cause a kernel crash.
network
low complexity
amazon CWE-88
7.8
2018-10-16 CVE-2018-11023 Argument Injection or Modification vulnerability in Amazon Fire OS 4.5.5.3
kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD (3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device /dev/gcioctl with the command 3222560159 and cause a kernel crash.
network
low complexity
amazon CWE-88
7.8