Vulnerabilities > Amazon > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-12-22 CVE-2023-50928 Unspecified vulnerability in Amazon Awslabs Sandbox Accounts for Events
"Sandbox Accounts for Events" provides multiple, temporary AWS accounts to a number of authenticated users simultaneously via a browser-based GUI.
network
low complexity
amazon
critical
9.0
2022-12-27 CVE-2022-4725 Unspecified vulnerability in Amazon AWS Software Development KIT
A vulnerability was found in AWS SDK 2.59.0.
network
low complexity
amazon
critical
9.8
2022-02-24 CVE-2022-25809 Unspecified vulnerability in Amazon Echo DOT Firmware
Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on these devices via a malicious skill (in the case of remote attackers) or by pairing a malicious Bluetooth device (in the case of physically proximate attackers), aka an "Alexa versus Alexa (AvA)" attack.
network
low complexity
amazon
critical
9.8
2021-12-12 CVE-2021-44833 Incorrect Default Permissions vulnerability in Amazon AWS Opensearch 1.0.0
The CLI 1.0.0 for Amazon AWS OpenSearch has weak permissions for the configuration file.
network
low complexity
amazon CWE-276
critical
9.8
2021-08-12 CVE-2020-36363 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Amazon Cloudfront 1.22019
Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, which some entities consider to be weak ciphers.
network
low complexity
amazon CWE-327
critical
9.8
2021-05-03 CVE-2021-32020 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Amazon Freertos
The kernel in Amazon Web Services FreeRTOS before 10.4.3 has insufficient bounds checking during management of heap memory.
network
low complexity
amazon CWE-119
critical
9.8
2021-04-22 CVE-2021-31572 Integer Overflow or Wraparound vulnerability in Amazon Freertos
The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in stream_buffer.c for a stream buffer.
network
low complexity
amazon CWE-190
critical
9.8
2021-04-22 CVE-2021-31571 Integer Overflow or Wraparound vulnerability in Amazon Freertos
The kernel in Amazon Web Services FreeRTOS before 10.4.3 has an integer overflow in queue.c for queue creation.
network
low complexity
amazon CWE-190
critical
9.8
2021-01-19 CVE-2020-28472 Unspecified vulnerability in Amazon products
This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0.
network
low complexity
amazon
critical
9.8
2020-01-08 CVE-2019-10777 OS Command Injection vulnerability in Amazon AWS Lambda
In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function without any sanitization.
network
low complexity
amazon CWE-78
critical
9.8