CVE-2024-27350
- EPSS 0.04%
- Veröffentlicht 26.02.2024 16:28:00
- Zuletzt bearbeitet 18.09.2025 16:23:23
Amazon Fire OS 7 before 7.6.6.9 and 8 before 8.1.0.3 allows Fire TV applications to establish local ADB (Android Debug Bridge) connections. NOTE: some third parties dispute whether this has security relevance, because an ADB connection is only possib...
CVE-2023-1385
- EPSS 0.04%
- Veröffentlicht 03.05.2023 13:15:10
- Zuletzt bearbeitet 21.11.2024 07:39:04
Improper JPAKE implementation allows offline PIN brute-forcing due to the initialization of random values to a known value, which leads to unauthorized authentication to amzn.lightning services. This issue affects: Amazon Fire TV Stick 3rd gen vers...
CVE-2023-1384
- EPSS 0.15%
- Veröffentlicht 03.05.2023 13:15:09
- Zuletzt bearbeitet 21.11.2024 07:39:04
The setMediaSource function on the amzn.thin.pl service does not sanitize the "source" parameter allowing for arbitrary javascript code to be run This issue affects: Amazon Fire TV Stick 3rd gen versions prior to 6.2.9.5. Insignia TV with FireOS ve...
CVE-2023-1383
- EPSS 0.06%
- Veröffentlicht 03.05.2023 12:16:44
- Zuletzt bearbeitet 21.11.2024 07:39:04
An Improper Enforcement of Behavioral Workflow vulnerability in the exchangeDeviceServices function on the amzn.dmgr service allowed an attacker to register services that are only locally accessible. This issue affects: Amazon Fire TV Stick 3rd gen...
CVE-2019-7399
- EPSS 0.24%
- Veröffentlicht 17.02.2019 04:29:00
- Zuletzt bearbeitet 21.11.2024 04:48:09
Amazon Fire OS before 5.3.6.4 allows a man-in-the-middle attack against HTTP requests for "Terms of Use" and Privacy pages.
CVE-2018-11021
- EPSS 4.01%
- Veröffentlicht 16.10.2018 22:29:01
- Zuletzt bearbeitet 21.11.2024 03:42:30
kernel/omap/drivers/video/omap2/dsscomp/device.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device /dev/dsscomp with the command 1118064517 and c...
CVE-2018-11022
- EPSS 4.01%
- Veröffentlicht 16.10.2018 22:29:01
- Zuletzt bearbeitet 21.11.2024 03:42:30
kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device /dev/gcioctl with the command 3224132973 and cause ...
CVE-2018-11023
- EPSS 4.01%
- Veröffentlicht 16.10.2018 22:29:01
- Zuletzt bearbeitet 21.11.2024 03:42:30
kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD (3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device /dev/gcioctl with the command 3222560159 and cause...
CVE-2018-11024
- EPSS 4.01%
- Veröffentlicht 16.10.2018 22:29:01
- Zuletzt bearbeitet 21.11.2024 03:42:31
kernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD (3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device /dev/gcioctl with the command 1077435789 and cause...
CVE-2018-11025
- EPSS 4.01%
- Veröffentlicht 16.10.2018 22:29:01
- Zuletzt bearbeitet 21.11.2024 03:42:31
kernel/omap/drivers/mfd/twl6030-gpadc.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a crafted argument via the argument of an ioctl on device /dev/twl6030-gpadc with the command 24832 and cause a k...