VYPR

Cyclone Data Distribution Service

by Eclipse

CVEs (4)

  • CVE-2025-67109CriDec 23, 2025
    risk 0.65cvss 10.0epss 0.00

    Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute commands with System privileges.

  • CVE-2024-10838CriMar 12, 2025
    risk 0.59cvss 9.1epss 0.01

    An integer underflow during deserialization may allow any unauthenticated user to read out of bounds heap memory. This may result into secret data or pointers revealing the layout of the address space to be included into a deserialized data structure, which may potentially lead…

  • CVE-2020-18735HigAug 23, 2021
    risk 0.49cvss 7.5epss 0.02

    A heap buffer overflow in /src/dds_stream.c of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.

  • CVE-2020-18734HigAug 23, 2021
    risk 0.49cvss 7.5epss 0.02

    A stack buffer overflow in /ddsi/q_bitset.h of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.