Vulnerabilities > Amazon

DATE CVE VULNERABILITY TITLE RISK
2019-12-06 CVE-2019-11554 Improper Certificate Validation vulnerability in Amazon Audible 2.34.0
The Audible application through 2.34.0 for Android has Missing SSL Certificate Validation for Adobe SDKs, allowing MITM attackers to cause a denial of service.
network
high complexity
amazon CWE-295
5.9
2019-11-04 CVE-2019-18178 Use After Free vulnerability in Amazon Freertos+Fat 160919A
Real Time Engineers FreeRTOS+FAT 160919a has a use after free.
network
low complexity
amazon CWE-416
7.5
2019-10-07 CVE-2019-13120 Out-of-bounds Read vulnerability in Amazon web Services Freertos
Amazon FreeRTOS up to and including v1.4.8 lacks length checking in prvProcessReceivedPublish, resulting in untargetable leakage of arbitrary memory contents on a device to an attacker.
network
low complexity
amazon CWE-125
7.5
2019-04-04 CVE-2018-19981 Cleartext Storage of Sensitive Information vulnerability in Amazon AWS Software Development KIT
Amazon AWS SDK <=2.8.5 for Android uses Android SharedPreferences to store plain text AWS STS Temporary Credentials retrieved by AWS Cognito Identity Service.
network
low complexity
amazon CWE-312
7.2
2019-03-01 CVE-2019-9483 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Amazon Ring Video Doorbell Firmware
Amazon Ring Doorbell before 3.4.7 mishandles encryption, which allows attackers to obtain audio and video data, or insert spoofed video that does not correspond to the actual person at the door.
network
low complexity
amazon CWE-327
critical
9.1
2019-02-17 CVE-2019-7399 Origin Validation Error vulnerability in Amazon Fire OS
Amazon Fire OS before 5.3.6.4 allows a man-in-the-middle attack against HTTP requests for "Terms of Use" and Privacy pages.
network
high complexity
amazon CWE-346
7.4
2018-12-06 CVE-2018-16603 Information Exposure vulnerability in Amazon web Services Freertos and Freertos
An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component.
network
high complexity
amazon CWE-200
5.9
2018-12-06 CVE-2018-16602 Information Exposure vulnerability in Amazon web Services Freertos and Freertos
An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component.
network
high complexity
amazon CWE-200
5.9
2018-12-06 CVE-2018-16601 Integer Underflow (Wrap or Wraparound) vulnerability in Amazon web Services Freertos and Freertos
An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component.
network
high complexity
amazon CWE-191
8.1
2018-12-06 CVE-2018-16600 Information Exposure vulnerability in Amazon web Services Freertos and Freertos
An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component.
network
high complexity
amazon CWE-200
5.9