Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
431 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 4.2% | — | Amazon WEB Services FreertosAmazon Freertos | 6/12/2018 | 17/6/2026 | An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. A crafted IP header triggers a full memory space copy in prvProcessIPPacket, leading to denial of service and possibly remote code execution. | |
| Modificada | Media (5.9) | 1.8% | — | Amazon WEB Services FreertosAmazon Freertos | 6/12/2018 | 17/6/2026 | An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. Out of bounds memory access during parsing of ARP packets in eARPProcessPacket can be used for information disclosure. | |
| Modificada | Media (5.9) | 1.8% | — | Amazon WEB Services FreertosAmazon Freertos | 6/12/2018 | 17/6/2026 | An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. Out of bounds memory access during parsing of NBNS packets in prvTreatNBNS can be used for information disclosure. | |
| Modificada | Media (5.9) | 1.5% | — | Amazon WEB Services FreertosAmazon Freertos | 6/12/2018 | 17/6/2026 | An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. In xProcessReceivedUDPPacket and prvParseDNSReply, any received DNS response is accepted, without confirming it matches a sent DNS request. | |
| Modificada | Alta (8.1) | 3.3% | — | Amazon WEB Services Freertos | 6/12/2018 | 17/6/2026 | Amazon Web Services (AWS) FreeRTOS through 1.3.1 allows remote attackers to execute arbitrary code because of mbedTLS context object corruption in prvSetupConnection and GGD_SecureConnect_Connect in AWS TLS connectivity modules. | |
| Modificada | Media (5.9) | 1.8% | — | Amazon WEB Services FreertosAmazon Freertos | 6/12/2018 | 17/6/2026 | Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component allow information disclosure during parsing of ICMP packets in prvProcessICMPPacket. | |
| Modificada | Alta (8.1) | 4.4% | — | Amazon WEB Services FreertosAmazon Freertos | 6/12/2018 | 17/6/2026 | Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component allow remote attackers to leak information or execute arbitrary code because of a Buffer Overflow during generation of a protocol checksum in usGenerateProtocolChecksum… | |
| Modificada | Alta (8.1) | 4.4% | — | Amazon WEB Services FreertosAmazon Freertos | 6/12/2018 | 17/6/2026 | Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component allow remote attackers to execute arbitrary code or leak information because of a Buffer Overflow during parsing of DNS\LLMNR packets in prvParseDNSReply. | |
| Modificada | Media (5.9) | 1.8% | — | Amazon WEB Services FreertosAmazon Freertos | 6/12/2018 | 17/6/2026 | Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component allow information disclosure during parsing of TCP options in prvCheckOptions. | |
| Modificada | Alta (7.4) | 2.0% | — | Amazon WEB Services FreertosAmazon Freertos | 6/12/2018 | 17/6/2026 | Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component allow division by zero in prvCheckOptions. | |
| Modificada | Alta (8.1) | 2.0% | — | Amazon WEB Services Freertos | 6/12/2018 | 17/6/2026 | Amazon Web Services (AWS) FreeRTOS through 1.3.1 has an uninitialized pointer free in SOCKETS_SetSockOpt. | |
| Modificada | Media (6.1) | 0.84% | — | Amazon Payfort-php-sdk | 14/11/2018 | 17/6/2026 | The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the error.php error_msg parameter. | |
| Modificada | Media (6.1) | 0.86% | — | Amazon Payfort-php-sdk | 14/11/2018 | 17/6/2026 | The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in an error.php echo statement. | |
| Modificada | Media (6.1) | 1.5% | — | Amazon Payfort-php-sdk | 14/11/2018 | 17/6/2026 | The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the success.php fort_id parameter. | |
| Modificada | Media (6.1) | 0.86% | — | Amazon Payfort-php-sdk | 14/11/2018 | 17/6/2026 | The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in a success.php echo statement. | |
| Modificada | Media (6.1) | 0.68% | — | Amazon Payfort-php-sdk | 14/11/2018 | 17/6/2026 | The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the route.php paymentMethod parameter. | |
| Modificada | Alta (7.5) | 2.6% | — | Amazon Fire OS | 16/10/2018 | 17/6/2026 | kernel/omap/drivers/mfd/twl6030-gpadc.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device /dev/twl6030-gpadc with the command 24832 and cause a kernel crash. | |
| Modificada | Alta (7.5) | 2.6% | — | Amazon Fire OS | 16/10/2018 | 17/6/2026 | kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD (3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device /dev/gcioctl with the command 1077435789 and cause a kernel crash. | |
| Modificada | Alta (7.5) | 2.6% | — | Amazon Fire OS | 16/10/2018 | 17/6/2026 | kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD (3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device /dev/gcioctl with the command 3222560159 and cause a kernel crash. | |
| Modificada | Alta (7.5) | 2.6% | — | Amazon Fire OS | 16/10/2018 | 17/6/2026 | kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device /dev/gcioctl with the command 3224132973 and cause a kernel crash. | |
| Modificada | Alta (7.5) | 3.0% | — | Amazon Fire OS | 16/10/2018 | 17/6/2026 | kernel/omap/drivers/video/omap2/dsscomp/device.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device /dev/dsscomp with the command 1118064517 and cause a kernel crash. | |
| Modificada | Media (4.4) | 0.63% | — | Amazon Fire OS | 16/10/2018 | 17/6/2026 | kernel/omap/drivers/rpmsg/rpmsg_omx.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device file /dev/rpmsg-omx1 with the command 3221772291, and cause a kernel crash. | |
| Modificada | Alta (7.5) | 3.0% | — | Amazon Fire OS | 16/10/2018 | 17/6/2026 | kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device /dev/gcioctl with the command 3221773726 and cause a kernel crash. | |
| Modificada | Baja (3.3) | 1.1% | — | Amazon Echo Show FirmwareAmazon Echo Plus FirmwareAmazon Echo DOT FirmwareAmazon Echo Spot Firmware+1 | 30/5/2018 | 17/6/2026 | Prior to 2018-04-27, the reprompt feature in Amazon Echo devices could be misused by a custom Alexa skill. The reprompt feature is designed so that if Alexa does not receive an input within 8 seconds, the device can speak a reprompt, then wait an additional 8 seconds for input; if the user still does not respond, the… | |
| Modificada | Alta (8.8) | 2.5% | — | Amazon Music | 2/3/2018 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Amazon Music Player 6.1.5.1213. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of URI… |