Show filters
151 Total Results
Displaying 1-10 of 151
Sort by:
Attacker Value
High
CVE-2024-6387
Disclosure Date: July 01, 2024 (last updated July 28, 2024)
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.
13
Attacker Value
Unknown
CVE-2023-44487
Disclosure Date: October 10, 2023 (last updated June 28, 2024)
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
1
Attacker Value
Unknown
CVE-2025-0501
Disclosure Date: January 15, 2025 (last updated January 29, 2025)
An issue in the native clients for Amazon WorkSpaces (when running PCoIP protocol) may allow an attacker to access remote sessions via man-in-the-middle.
0
Attacker Value
Unknown
CVE-2025-0500
Disclosure Date: January 15, 2025 (last updated January 29, 2025)
An issue in the native clients for Amazon WorkSpaces (when running Amazon DCV protocol), Amazon AppStream 2.0, and Amazon DCV Clients may allow an attacker to access remote sessions via man-in-the-middle.
0
Attacker Value
Unknown
CVE-2024-12746
Disclosure Date: December 24, 2024 (last updated January 05, 2025)
A SQL injection in the Amazon Redshift ODBC Driver v2.1.5.0 (Windows or Linux) allows a user to gain escalated privileges via the SQLTables or SQLColumns Metadata APIs. Users are recommended to upgrade to the driver version 2.1.6.0 or revert to driver version 2.1.4.0.
0
Attacker Value
Unknown
CVE-2024-12745
Disclosure Date: December 24, 2024 (last updated January 05, 2025)
A SQL injection in the Amazon Redshift Python Connector v2.1.4 allows a user to gain escalated privileges via the get_schemas, get_tables, or get_columns Metadata APIs. Users are recommended to upgrade to the driver version 2.1.5 or revert to driver version 2.1.3.
0
Attacker Value
Unknown
CVE-2024-12744
Disclosure Date: December 24, 2024 (last updated January 05, 2025)
A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSchemas, getTables, or getColumns Metadata APIs. Users should upgrade to the driver version 2.1.0.32 or revert to driver version 2.1.0.30.
0
Attacker Value
Unknown
CVE-2024-52314
Disclosure Date: November 09, 2024 (last updated November 09, 2024)
A data.all admin team member who has access to the customer-owned AWS Account where data.all is deployed may be able to extract user data from data.all application logs in data.all via CloudWatch log scanning for particular operations that interact with customer producer teams data.
0
Attacker Value
Unknown
CVE-2024-52313
Disclosure Date: November 09, 2024 (last updated November 09, 2024)
An authenticated data.all user is able to manipulate a getDataset query to fetch additional information regarding the parent Environment resource that the user otherwise would not able to fetch by directly querying the object via getEnvironment in data.all.
0
Attacker Value
Unknown
CVE-2024-52312
Disclosure Date: November 09, 2024 (last updated November 09, 2024)
Due to inconsistent authorization permissions, data.all may allow an external actor with an authenticated account to perform restricted operations against DataSets and Environments.
0