AWS Security Advisories · October 2016 — AWS Security Advisories
9 advisories 29 CVEs 1 EXPLOITED

Amazon Linux (AL1, AL2, AL2023), AWS Security Bulletins, and AWS SDK CVEs for 2016-10. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

ALAS-2016-757

ALAS · AL1ExploitedCISA KEV listedCritical2016-10-20

ALAS-2016-757: kernel (critical)

CVEs:CVE-2016-5195

Affected products

ProductStatusVendorPackageEcosystem
kernel affected Amazon kernel
Upstream advisory

ALAS-2016-756

ALAS · AL1Weaponized exploitImportant2016-10-12

ALAS-2016-756: mysql55, mysql56 (important)

CVEs:CVE-2016-6662

Affected products

ProductStatusVendorPackageEcosystem
mysql55, mysql56 affected Amazon mysql55, mysql56
Upstream advisory

ALAS-2016-760

ALAS · AL1EPSS <= 49%Important2016-10-27

ALAS-2016-760: python-twisted-web (important)

CVEs:CVE-2016-1000111

Affected products

ProductStatusVendorPackageEcosystem
python-twisted-web affected Amazon python-twisted-web
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.