| Deserialization of Untrusted Data | <0:2.0.0.648-36.amzn2.0.18 |
| Out-of-bounds Write | <0:2.0.0.648-36.amzn2.0.17 |
| Resource Exhaustion | <0:2.0.0.648-36.amzn2.0.16 |
| HTTP Request Smuggling | <0:2.0.0.648-36.amzn2.0.15 |
| HTTP Request Smuggling | <0:2.0.0.648-36.amzn2.0.13 |
| Arbitrary Code Injection | <0:2.0.0.648-36.amzn2.0.11 |
| Out-of-bounds Read | <0:2.0.0.648-36.amzn2.0.12 |
| XML External Entity (XXE) Injection | <0:2.0.0.648-36.amzn2.0.12 |
| Cleartext Transmission of Sensitive Information | <0:2.0.0.648-36.amzn2.0.10 |
| Information Exposure | <0:2.0.0.648-36.amzn2.0.9 |
| HTTP Response Splitting | <0:2.0.0.648-36.amzn2.0.8 |
| Null Byte Interaction Error (Poison Null Byte) | <0:2.0.0.648-36.amzn2.0.7 |
| HTTP Response Splitting | <0:2.0.0.648-36.amzn2.0.7 |
| Arbitrary Code Injection | <0:2.0.0.648-36.amzn2.0.7 |
| Reliance on Cookies without Validation and Integrity Checking | <0:2.0.0.648-36.amzn2.0.7 |
| Resource Exhaustion | <0:2.0.0.648-36.amzn2.0.7 |
| Resource Exhaustion | <0:2.0.0.648-36.amzn2.0.6 |
| Out-of-bounds Read | <0:2.0.0.648-36.amzn2.0.5 |
| Improper Input Validation | <0:2.0.0.648-36.amzn2.0.4 |
| Arbitrary Command Injection | <0:2.0.0.648-36.amzn2.0.2 |
| Out-of-bounds Read | <0:2.0.0.648-36.amzn2.0.3 |
| HTTP Request Smuggling | <0:2.0.0.648-36.amzn2.0.2 |
| Improperly Controlled Modification of Dynamically-Determined Object Attributes | <0:2.0.0.648-36.amzn2.0.2 |
| Improper Input Validation | <0:2.0.0.648-36.amzn2.0.1 |
| Directory Traversal | <0:2.0.0.648-36.amzn2.0.1 |
| Use of Externally-Controlled Format String | <0:2.0.0.648-36.amzn2.0.1 |
| Resource Exhaustion | <0:2.0.0.648-36.amzn2.0.1 |
| Directory Traversal | <0:2.0.0.648-36.amzn2.0.1 |
| Directory Traversal | <0:2.0.0.648-36.amzn2.0.1 |
| Cross-site Scripting (XSS) | <0:2.0.0.648-36.amzn2.0.1 |
| CVE-2018-16396 | <0:2.0.0.648-36.amzn2.0.1 |
| Improper Input Validation | <0:2.0.0.648-36.amzn2.0.1 |
| Deserialization of Untrusted Data | <0:2.0.0.648-36.amzn2.0.1 |
| Link Following | <0:2.0.0.648-36.amzn2.0.1 |
| Improper Verification of Cryptographic Signature | <0:2.0.0.648-36.amzn2.0.1 |
| HTTP Response Splitting | <0:2.0.0.648-36.amzn2.0.1 |
| Loop with Unreachable Exit Condition ('Infinite Loop') | <0:2.0.0.648-36.amzn2.0.1 |
| Arbitrary Code Injection | <0:2.0.0.648-35.amzn2.0.1 |
| Arbitrary Code Injection | <0:2.0.0.648-35.amzn2.0.1 |
| Arbitrary Code Injection | <0:2.0.0.648-35.amzn2.0.1 |
| Arbitrary Code Injection | <0:2.0.0.648-35.amzn2.0.1 |
| CVE-2018-16395 | <0:2.0.0.648-34.amzn2.0.1 |
| Cross-site Scripting (XSS) | <0:2.0.0.648-33.amzn2.0.1 |
| Directory Traversal | <0:2.0.0.648-33.amzn2.0.1 |
| Improper Input Validation | <0:2.0.0.648-33.amzn2.0.1 |
| Loop with Unreachable Exit Condition ('Infinite Loop') | <0:2.0.0.648-33.amzn2.0.1 |
| Deserialization of Untrusted Data | <0:2.0.0.648-33.amzn2.0.1 |
| Improper Verification of Cryptographic Signature | <0:2.0.0.648-33.amzn2.0.1 |
| Link Following | <0:2.0.0.648-33.amzn2.0.1 |
| Arbitrary Code Injection | <0:2.0.0.648-33.amzn2.0.1 |