AWS Security Advisories · June 2014 — AWS Security Advisories
20 advisories 37 CVEs 1 EXPLOITED

Amazon Linux (AL1, AL2, AL2023), AWS Security Bulletins, and AWS SDK CVEs for 2014-06. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ALAS-2014-363

ALAS · AL1ExploitedCISA KEV listedMedium2014-06-15

ALAS-2014-363: kernel (medium)

CVEs:CVE-2014-3153

Affected products

ProductStatusVendorPackageEcosystem
kernel affected Amazon kernel
Upstream advisory

ALAS-2014-350

ALAS · AL1Weaponized exploitImportant2014-06-05

ALAS-2014-350: openssl098e (important)

CVEs:CVE-2014-0224

Affected products

ProductStatusVendorPackageEcosystem
openssl098e affected Amazon openssl098e
Upstream advisory

ALAS-2014-351

ALAS · AL1Weaponized exploitImportant2014-06-05

ALAS-2014-351: openssl097a (important)

CVEs:CVE-2014-0224

Affected products

ProductStatusVendorPackageEcosystem
openssl097a affected Amazon openssl097a
Upstream advisory

ALAS-2014-364

ALAS · AL1Weaponized exploitImportant2014-06-26

ALAS-2014-364: nrpe (important)

CVEs:CVE-2014-2913

Affected products

ProductStatusVendorPackageEcosystem
nrpe affected Amazon nrpe
Upstream advisory

ALAS-2014-352

ALAS · AL1PoC exploitImportant2014-06-05

ALAS-2014-352: gnutls (important)

CVEs:CVE-2014-3466

Affected products

ProductStatusVendorPackageEcosystem
gnutls affected Amazon gnutls
Upstream advisory

ALAS-2014-358

ALAS · AL1EPSS <= 49%Low2014-06-15

ALAS-2014-358: perl-Capture-Tiny (low)

CVEs:CVE-2014-1875

Affected products

ProductStatusVendorPackageEcosystem
perl-Capture-Tiny affected Amazon perl-Capture-Tiny
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.