CVE-2026-35558
- EPSS 0.04%
- Veröffentlicht 03.04.2026 20:15:09
- Zuletzt bearbeitet 14.04.2026 16:17:04
Improper neutralization of special elements in the authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to execute arbitrary code or redirect authentication flows by using specially crafted connection param...
CVE-2026-35559
- EPSS 0.08%
- Veröffentlicht 03.04.2026 20:13:29
- Zuletzt bearbeitet 14.04.2026 16:14:00
Out-of-bounds write in the query processing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to crash the driver by using specially crafted data that is processed by the driver during query operations. To remediate t...
CVE-2026-5485
- EPSS 0.1%
- Veröffentlicht 03.04.2026 20:13:14
- Zuletzt bearbeitet 14.04.2026 16:14:49
OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2.0.5.1 on Linux might allow a threat actor to execute arbitrary code by using specially crafted connection parameters that are loaded by the drive...
CVE-2026-35562
- EPSS 0.11%
- Veröffentlicht 03.04.2026 20:10:51
- Zuletzt bearbeitet 14.04.2026 16:14:38
Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to cause a denial of service by delivering crafted input that triggers excessive resource consumption during the d...
CVE-2026-35561
- EPSS 0.03%
- Veröffentlicht 03.04.2026 20:10:40
- Zuletzt bearbeitet 14.04.2026 16:14:29
Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to intercept or hijack authentication sessions due to insufficient protections in the ...
CVE-2026-35560
- EPSS 0.02%
- Veröffentlicht 03.04.2026 20:10:38
- Zuletzt bearbeitet 14.04.2026 16:14:15
Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-middle threat actor to intercept authentication credentials due to insufficient default transport secu...