Vulnerabilidades em amazon

55 resultados
Análise Vexday

A Amazon tem 5 vulnerabilidades catalogadas na base Vexday, nenhuma delas sob ataque ativo ou com severidade crítica. A fraqueza dominante é CWE-863 (controle de acesso impróprio), indicando exposição potencial a escalação de privilégios; porém, a ausência de atualizações recentes sugere que o panorama atual é estável e sem pressão temporal imediata.

CVE-2025-0500HIGHIssue affecting Amazon WorkSpaces (when running Amazon DCV protocol), Amazon AppStream 2.0, and Amazon DCV clientsEPSS 0.5%CVE-2026-35559HIGHOut-of-bounds write in query processing components in Amazon Athena ODBC driverEPSS 0.5%CVE-2024-52311MEDIUMdata.all does not invalidate authentication token upon user logoutEPSS 0.5%CVE-2024-12746HIGHSQL Injection in the Amazon Redshift ODBC Driver affecting v2.1.5.0EPSS 0.5%CVE-2025-0501HIGHIssue affecting Amazon WorkSpaces Clients (when running PCoIP protocol)EPSS 0.5%CVE-2025-11573HIGHDenial of Service issue in Amazon.IonDotnetEPSS 0.4%CVE-2026-15746MEDIUMCredential disclosure in Strands Agents Tools elasticsearch_memory toolEPSS 0.4%CVE-2024-52314MEDIUMdata.all admin user may access potentially sensitive data stored by producers via logsEPSS 0.4%CVE-2020-8897MEDIUMRobustness weakness in AWS KMS and Encryption SDKsEPSS 0.4%CVE-2023-1384MEDIUMThe setMediaSource function on the amzn.thin.pl service does not sanitize the "source" parameter allowing for arbitrary javascript code to bEPSS 0.4%CVE-2026-35560CRITICALImproper certificate validation in identity provider connection components in Amazon Athena ODBC driverEPSS 0.4%CVE-2026-3494MEDIUMMariaDB Server Audit Plugin Comment Handling BypassEPSS 0.4%CVE-2025-8904CRITICALPrivilege escalation issue in Amazon EMR Secret Agent componentEPSS 0.4%CVE-2024-8901MEDIUMLack of JWT issuer and signer validationEPSS 0.4%CVE-2025-5688HIGHOut of Bounds Write in FreeRTOS-Plus-TCPEPSS 0.4%CVE-2024-52312MEDIUMdata.all authenticated users can perform restricted operations against DataSets and EnvironmentsEPSS 0.3%CVE-2026-85787HIGHAn incomplete list of disallowed inputs in the SQL validation component of Amazon awslabs postgres-mcp-serverEPSS 0.3%CVE-2023-1385HIGHImproper JPAKE implementation allows offline PIN brute-forcing due to the initialization of random values to a known value, which leads to uEPSS 0.3%CVE-2026-35558HIGHImproper neutralization of special elements in authentication components in Amazon Athena ODBC driverEPSS 0.3%CVE-2024-10125MEDIUMLack of JWT issuer and signer validationEPSS 0.3%