Vulnerabilities > Amazon

DATE CVE VULNERABILITY TITLE RISK
2022-04-14 CVE-2022-25165 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Amazon AWS Client VPN 2.0.0
An issue was discovered in Amazon AWS VPN Client 2.0.0.
local
high complexity
amazon CWE-367
7.0
2022-04-14 CVE-2022-25166 Information Exposure vulnerability in Amazon AWS Client VPN 2.0.0
An issue was discovered in Amazon AWS VPN Client 2.0.0.
local
low complexity
amazon CWE-200
5.0
2022-02-24 CVE-2022-24709 Unspecified vulnerability in Amazon Awsui/Components-React
@awsui/components-react is the main AWS UI package which contains React components, with TypeScript definitions designed for user interface development.
network
low complexity
amazon
6.1
2022-02-24 CVE-2022-25809 Unspecified vulnerability in Amazon Echo DOT Firmware
Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on these devices via a malicious skill (in the case of remote attackers) or by pairing a malicious Bluetooth device (in the case of physically proximate attackers), aka an "Alexa versus Alexa (AvA)" attack.
network
low complexity
amazon
critical
9.8
2021-12-12 CVE-2021-44833 Incorrect Default Permissions vulnerability in Amazon AWS Opensearch 1.0.0
The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.
network
low complexity
amazon CWE-276
critical
9.8
2021-12-07 CVE-2021-43637 Classic Buffer Overflow vulnerability in Amazon Workspaces 1.0
Amazon WorkSpaces agent is affected by Buffer Overflow.
local
low complexity
amazon CWE-120
8.8
2021-12-07 CVE-2021-43638 Integer Overflow or Wraparound vulnerability in Amazon Workspaces 1.0
Amazon Amazon WorkSpaces agent is affected by Integer Overflow.
local
low complexity
amazon CWE-190
8.8
2021-11-23 CVE-2021-40828 Improper Certificate Validation vulnerability in Amazon products
Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.3.3), Python (versions prior to 1.5.18), C++ (versions prior to 1.12.7) and Node.js (versions prior to 1.5.1) did not verify server certificate hostname during TLS handshake when overriding Certificate Authorities (CA) in their trust stores on Windows.
low complexity
amazon CWE-295
8.8
2021-11-23 CVE-2021-40829 Improper Certificate Validation vulnerability in Amazon web Services Internet of Things Device Software Development KIT V2
Connections initialized by the AWS IoT Device SDK v2 for Java (versions prior to 1.4.2), Python (versions prior to 1.6.1), C++ (versions prior to 1.12.7) and Node.js (versions prior to 1.5.3) did not verify server certificate hostname during TLS handshake when overriding Certificate Authorities (CA) in their trust stores on MacOS.
low complexity
amazon CWE-295
8.8
2021-11-23 CVE-2021-40830 Improper Certificate Validation vulnerability in Amazon products
The AWS IoT Device SDK v2 for Java, Python, C++ and Node.js appends a user supplied Certificate Authority (CA) to the root CAs instead of overriding it on Unix systems.
low complexity
amazon CWE-295
8.8