Vulnerabilidades em Amazon

54 resultados
Análise Vexday

A Amazon apresenta 35 vulnerabilidades catalogadas na base, com 5 classificadas como críticas, mas nenhuma sob ataque ativo confirmado no momento. A fraqueza dominante é validação inadequada de certificados (CWE-295), padrão típico em integrações cloud, e apenas 4 CVEs foram publicadas nos últimos 90 dias, indicando risco atual moderado e sem pressão imediata de exploração.

CVE-2024-52314MEDIUMdata.all admin user may access potentially sensitive data stored by producers via logsEPSS 0.4%CVE-2020-8897MEDIUMRobustness weakness in AWS KMS and Encryption SDKsEPSS 0.4%CVE-2026-16318MEDIUMQUIC Transport Parameters Memory Leak During HelloRetryRequest in s2n-tlsEPSS 0.4%CVE-2023-1384MEDIUMThe setMediaSource function on the amzn.thin.pl service does not sanitize the "source" parameter allowing for arbitrary javascript code to bEPSS 0.4%CVE-2026-85228HIGHInteger overflow in tensor buffer validation in Deep Java LibraryEPSS 0.4%CVE-2026-35562HIGHAllocation of resources without limits in parsing components in Amazon Athena ODBC driverEPSS 0.4%CVE-2024-8901MEDIUMLack of JWT issuer and signer validationEPSS 0.4%CVE-2025-5688HIGHOut of Bounds Write in FreeRTOS-Plus-TCPEPSS 0.4%CVE-2024-52312MEDIUMdata.all authenticated users can perform restricted operations against DataSets and EnvironmentsEPSS 0.3%CVE-2025-8904CRITICALPrivilege escalation issue in Amazon EMR Secret Agent componentEPSS 0.3%CVE-2026-84851HIGHUncontrolled recursion in the Ion reader in Amazon Ion-C before 1.1.6EPSS 0.3%CVE-2023-1385HIGHImproper JPAKE implementation allows offline PIN brute-forcing due to the initialization of random values to a known value, which leads to uEPSS 0.3%CVE-2026-85786HIGHIncomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-javaEPSS 0.3%CVE-2024-10125MEDIUMLack of JWT issuer and signer validationEPSS 0.3%CVE-2026-78379CRITICALConsent bypass in python_repl tool via batch kwargs forwarding in Amazon Strands Agents ToolsEPSS 0.3%CVE-2024-52313MEDIUMdata.all authenticated users can obtain incorrect object level authorizationsEPSS 0.3%CVE-2024-10953MEDIUMdata.all authenticated users can perform mutating update operations on persisted notification recordsEPSS 0.3%CVE-2025-6031HIGHInsecure device pairing in end of life Amazon Cloud CamEPSS 0.3%CVE-2025-5279HIGHIssue with Amazon Redshift Python Connector and the BrowserAzureOAuth2CredentialsProvider pluginEPSS 0.3%CVE-2026-35558HIGHImproper neutralization of special elements in authentication components in Amazon Athena ODBC driverEPSS 0.3%