Show filters
100 Total Results
Displaying 61-70 of 100
Sort by:
Attacker Value
Unknown

CVE-2020-2091

Disclosure Date: January 15, 2020 (last updated February 21, 2025)
A missing permission check in Jenkins Amazon EC2 Plugin 1.47 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL within the AWS region using attacker-specified credentials IDs obtained through another method.
Attacker Value
Unknown

CVE-2015-9506

Disclosure Date: October 23, 2019 (last updated February 08, 2025)
The Easy Digital Downloads (EDD) Amazon S3 extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
Attacker Value
Unknown

CVE-2015-9463

Disclosure Date: October 10, 2019 (last updated November 27, 2024)
The s3bubble-amazon-s3-audio-streaming plugin 2.0 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.
Attacker Value
Unknown

CVE-2015-9464

Disclosure Date: October 10, 2019 (last updated November 27, 2024)
The s3bubble-amazon-s3-html-5-video-with-adverts plugin 0.7 for WordPress has directory traversal via the adverts/assets/plugins/ultimate/content/downloader.php path parameter.
Attacker Value
Unknown

CVE-2019-13120

Disclosure Date: October 07, 2019 (last updated November 27, 2024)
Amazon FreeRTOS up to and including v1.4.8 lacks length checking in prvProcessReceivedPublish, resulting in untargetable leakage of arbitrary memory contents on a device to an attacker. If an attacker has the authorization to send a malformed MQTT publish packet to an Amazon IoT Thing, which interacts with an associated vulnerable MQTT message in the application, specific circumstances could trigger this vulnerability.
Attacker Value
Unknown

CVE-2019-6003

Disclosure Date: September 12, 2019 (last updated November 27, 2024)
Cross-site scripting vulnerability in EC-CUBE plugin 'Amazon Pay Plugin 2.12,2.13' version 2.4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Attacker Value
Unknown

CVE-2019-1003063

Disclosure Date: April 04, 2019 (last updated October 26, 2023)
Jenkins Amazon SNS Build Notifier Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
Attacker Value
Unknown

CVE-2019-9864

Disclosure Date: March 28, 2019 (last updated November 27, 2024)
PHP Scripts Mall Amazon Affiliate Store 2.1.6 allows Parameter Tampering of the payment amount.
0
Attacker Value
Unknown

CVE-2018-16598

Disclosure Date: December 06, 2018 (last updated November 27, 2024)
An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. In xProcessReceivedUDPPacket and prvParseDNSReply, any received DNS response is accepted, without confirming it matches a sent DNS request.
0
Attacker Value
Unknown

CVE-2018-16524

Disclosure Date: December 06, 2018 (last updated November 27, 2024)
Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component allow information disclosure during parsing of TCP options in prvCheckOptions.
0