Vulnerabilities > Amazon
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-05-24 | CVE-2023-33248 | Unspecified vulnerability in Amazon Alexa 8960323972 Amazon Alexa software version 8960323972 on Echo Dot 2nd generation and 3rd generation devices potentially allows attackers to deliver security-relevant commands via an audio signal between 16 and 22 kHz (often outside the range of human adult hearing). low complexity amazon | 7.6 |
2023-05-08 | CVE-2023-31141 | Incorrect Authorization vulnerability in Amazon Opensearch Security OpenSearch is open-source software suite for search, analytics, and observability applications. | 5.9 |
2023-05-03 | CVE-2023-1384 | Cross-site Scripting vulnerability in Amazon Fire OS The setMediaSource function on the amzn.thin.pl service does not sanitize the "source" parameter allowing for arbitrary javascript code to be run This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS versions prior to 7.6.3.3. | 6.1 |
2023-05-03 | CVE-2023-1385 | Use of Insufficiently Random Values vulnerability in Amazon Fire OS Improper JPAKE implementation allows offline PIN brute-forcing due to the initialization of random values to a known value, which leads to unauthorized authentication to amzn.lightning services. This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS 7.6.3.3. | 8.8 |
2023-05-03 | CVE-2023-1383 | Unspecified vulnerability in Amazon Fire OS An Improper Enforcement of Behavioral Workflow vulnerability in the exchangeDeviceServices function on the amzn.dmgr service allowed an attacker to register services that are only locally accessible. This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. low complexity amazon | 4.3 |
2023-04-19 | CVE-2023-30610 | Information Exposure Through Log Files vulnerability in Amazon Aws-Sigv4 aws-sigv4 is a rust library for low level request signing in the aws cloud platform. | 5.5 |
2023-03-02 | CVE-2023-25806 | Information Exposure Through Discrepancy vulnerability in Amazon Opensearch and Opensearch Security OpenSearch Security is a plugin for OpenSearch that offers encryption, authentication and authorization. | 5.3 |
2023-02-03 | CVE-2023-23933 | Out-of-bounds Read vulnerability in Amazon Opensearch OpenSearch Anomaly Detection identifies atypical data and receives automatic notifications. | 4.3 |
2023-01-26 | CVE-2023-23612 | Improper Authentication vulnerability in Amazon Opensearch OpenSearch is an open source distributed and RESTful search engine. | 8.8 |
2023-01-26 | CVE-2023-23613 | Information Exposure vulnerability in Amazon Opensearch OpenSearch is an open source distributed and RESTful search engine. | 6.5 |