Known vulnerabilities in Amazon Linux AMI - page 76

Software CPE: cpe:2.3:o:amazon_web_services:amazon_linux_ami:*:*:*:*:*:*:*:*
Total vulnerabilities: 3943
Public exploits: 290
Known exploited (KEV): 53
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Amazon Linux AMI Amazon Linux AMI is affected by 3943 known vulnerabilities: 26 critical, 592 high, 1559 medium, 1766 low Critical High Medium Low

Vulnerabilities (3943)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU74503 - Double Free
CVE-2021-40145
CWE-415 High
No
No
- 06.04.2023 SB2021090138
SB2023040624
SB2021090852
#VU74499 - NULL Pointer Dereference
CVE-2023-1355
CWE-476 Low
No
No
- 06.04.2023 SB2023040616
SB2023040625
SB2023050455
and 7 more
#VU73172 - NULL Pointer Dereference
CVE-2023-1264
CWE-476 Low
No
No
- 08.03.2023 SB2023030818
SB2023032026
SB2023032045
and 16 more
#VU73171 - Memory corruption
CVE-2023-1175
CWE-119 High
No
No
- 08.03.2023 SB2023030818
SB2023031642
SB2023031656
and 17 more
#VU73170 - Heap-based Buffer Overflow
CVE-2023-1170
CWE-122 High
No
No
- 08.03.2023 SB2023030818
SB2023031642
SB2023031656
and 16 more
#VU72618 - Improper input validation
CVE-2023-24329
CWE-20 Medium
No
No
- 28.02.2023 SB2023022819
SB2023022822
SB2023030832
and 158 more
#VU72575 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-48339
CWE-78 High
No
No
- 26.02.2023 SB2022120142
SB2023022605
SB2023030230
and 50 more
#VU72573 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-48337
CWE-78 High
No
No
- 26.02.2023 SB2022120142
SB2023022605
SB2023030230
and 42 more
#VU72456 - Incorrect Default Permissions
CVE-2022-33196
CWE-276 Low
No
No
- 21.02.2023 SB2023022134
SB2023022140
SB2023022141
and 24 more
#VU71559 - NULL Pointer Dereference
CVE-2022-47024
CWE-476 Low
No
No
- 26.01.2023 SB2023012623
SB2023013121
SB2023022848
and 16 more
#VU70723 - Out-of-bounds write
CVE-2023-0054
CWE-787 High
No
No
- 05.01.2023 SB2023010521
SB2023013071
SB2023013073
and 16 more
#VU70722 - Heap-based Buffer Overflow
CVE-2023-0051
CWE-122 High
No
No
- 05.01.2023 SB2023010521
SB2023010522
SB2023013071
and 14 more
#VU69808 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-45939
CWE-78 High
No
No
- 01.12.2022 SB2022120142
SB2022120148
SB2022120149
and 23 more
#VU69392 - Resource exhaustion
CVE-2022-45061
CWE-400 Medium
No
No
- 16.11.2022 SB2022111650
SB2022112824
SB2022112856
and 125 more
#VU68855 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-39348
CWE-79 Low
No
No
- 31.10.2022 SB2022103137
SB20221115106
SB2022111743
and 12 more
#VU62077 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-24801
CWE-444 Medium
No
No
- 12.04.2022 SB2022041212
SB2022050231
SB2022050232
and 21 more
#VU61608 - Improper Authentication
CVE-2022-0547
CWE-287 Medium
No
No
- 24.03.2022 SB2022032420
SB2022032423
SB2022040412
and 17 more
#VU59693 - Deserialization of Untrusted Data
CVE-2020-9493
CWE-502 High
No
No
- 18.01.2022 SB2021061626
SB2022011819
SB2022012640
and 62 more
#VU59692 - Deserialization of Untrusted Data
CVE-2022-23302
CWE-502 High
No
No
- 18.01.2022 SB2022011818
SB2022012640
SB2022012641
and 60 more
#VU59691 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2022-23305
CWE-89 Medium
No
No
- 18.01.2022 SB2022011818
SB2022012640
SB2022012641
and 94 more


Showing elements 1501 - 1520 out of 3943