VYPR

Vendor CVEs

Eclipse

All CVEs

356 total · sorted by risk
  • CVE-2026-16243HigJul 21, 2026
    risk 0.49cvss 7.5epss 0.00

    In Eclipse OMR versions up to 0.11, the arraycmp SIMD implementation for Z and P does not check if the number of bytes to compare is zero.

  • CVE-2026-15076HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.00

    In versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), the WebClientSession component of Eclipse Vert.x Web Client does not validate that the Domain attribute of a Set-Cookie response header matches the originating server's domain, in violation of RFC 6265…

  • CVE-2026-15075HigJul 14, 2026
    risk 0.49cvss 7.5epss 0.00

    In Eclipse Vert.x versions up to and including 4.5.29 (4.x branch) and 5.1.4 (5.x branch), DefaultRedirectHandler (vertx-core) propagates all request headers as-is across cross-origin HTTP 30x redirects. Only Content-Length is stripped; no origin comparison (scheme, host, port)…

  • CVE-2026-11576HigJun 19, 2026
    risk 0.49cvss 7.5epss 0.00

    The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path unconditionally calls fx_file_close() even when the file was never successfully opened. Multiple…

  • CVE-2025-55102HigJan 27, 2026
    risk 0.49cvss 7.5epss 0.00

    A denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A specially crafted network packet of "Packet Too Big" with more than 15 different source address can lead to denial of service. An attacker can send a malicious packet…

  • CVE-2025-11965HigOct 22, 2025
    risk 0.49cvss 7.5epss 0.00

    In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], a StaticHandler configuration for restricting access to hidden files fails to restrict access to hidden directories, allowing unauthorized users to retrieve files within them (e.g. '.git/config').

  • CVE-2025-55085HigOct 17, 2025
    risk 0.49cvss 7.5epss 0.01

    In NextX Duo before 6.4.4, in the HTTP client module, the network support code for Eclipse Foundation ThreadX, the parsing of HTTP header fields was missing bounds verification. A crafted server response could cause undefined behavior.

  • CVE-2025-55094HigOct 17, 2025
    risk 0.49cvss 7.5epss 0.00

    In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_icmpv6_validate_options() when handling a packet with ICMP6 options.

  • CVE-2025-55087HigOct 17, 2025
    risk 0.49cvss 7.5epss 0.00

    In NextX Duo's snmp addon versions before 6.4.4, a part of the Eclipse Foundation ThreadX, an attacker could cause an out-of-bound read by a crafted SNMPv3 security parameters.

  • CVE-2023-7272HigJul 17, 2024
    risk 0.49cvss 8.6epss 0.01

    In Eclipse Parsson before 1.0.4 and 1.1.3, a document with a large depth of nested objects can allow an attacker to cause a Java stack overflow exception and denial of service. Eclipse Parsson allows processing (e.g. parse, generate, transform and query) JSON documents.

  • CVE-2024-3046HigApr 9, 2024
    risk 0.49cvss 7.5epss 0.01

    In Eclipse Kura LogServlet component included in versions 5.0.0 to 5.4.1, a specifically crafted request to the servlet can allow an unauthenticated user to retrieve the device logs. Also, downloaded logs may be used by an attacker to perform privilege escalation by using the…

  • CVE-2022-2191HigJul 7, 2022
    risk 0.49cvss 7.5epss 0.02

    In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffers from configured ByteBufferPool in case of error code paths.

  • CVE-2022-2048HigJul 7, 2022
    risk 0.49cvss 7.5epss 0.02

    In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associated resources. This can lead to a Denial of Service scenario where there are no…

  • CVE-2022-29223HigMay 24, 2022
    risk 0.49cvss 7.5epss 0.01

    Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack. In versions prior to 6.1.10, an attacker can cause a buffer overflow by providing the Azure RTOS USBX host stack a HUB descriptor with `bNbPorts` set to a value greater than `UX_MAX_TT` which defaults to…

  • CVE-2021-41039HigDec 1, 2021
    risk 0.49cvss 7.5epss 0.01

    In versions 1.6 to 2.0.11 of Eclipse Mosquitto, an MQTT v5 client connecting with a large number of user-property properties could cause excessive CPU usage, leading to a loss of performance and possible denial of service.

  • CVE-2020-18735HigAug 23, 2021
    risk 0.49cvss 7.5epss 0.02

    A heap buffer overflow in /src/dds_stream.c of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.

  • CVE-2020-18734HigAug 23, 2021
    risk 0.49cvss 7.5epss 0.02

    A stack buffer overflow in /ddsi/q_bitset.h of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.

  • CVE-2021-34433HigAug 20, 2021
    risk 0.49cvss 7.5epss 0.00

    In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally succeeds without verifying the server side's signature on the client side, if that signature is not included in the server's…

  • CVE-2021-34432HigJul 27, 2021
    risk 0.49cvss 7.5epss 0.01

    In Eclipse Mosquitto versions 2.0.7 and earlier, the server will crash if the client tries to send a PUBLISH packet with topic length = 0.

  • CVE-2021-34430HigJul 8, 2021
    risk 0.49cvss 7.5epss 0.01

    Eclipse TinyDTLS through 0.9-rc1 relies on the rand function in the C library, which makes it easier for remote attackers to compute the master key and then decrypt DTLS traffic.

  • CVE-2020-27222HigFeb 3, 2021
    risk 0.49cvss 7.5epss 0.01

    In Eclipse Californium version 2.3.0 to 2.6.0, the certificate based (x509 and RPK) DTLS handshakes accidentally fails, because the DTLS server side sticks to a wrong internal state. That wrong internal state is set by a previous certificate based DTLS handshake failure with TLS…

  • CVE-2020-27217HigNov 13, 2020
    risk 0.49cvss 7.5epss 0.01

    In Eclipse Hono version 1.3.0 and 1.4.0 the AMQP protocol adapter does not verify the size of AMQP messages received from devices. In particular, a device may send messages that are bigger than the max-message-size that the protocol adapter has indicated during link…

  • CVE-2009-5045HigNov 6, 2019
    risk 0.49cvss 7.5epss 0.02

    Dump Servlet information leak in jetty before 6.1.22.

  • CVE-2019-11777HigSep 11, 2019
    risk 0.49cvss 7.5epss 0.01

    In the Eclipse Paho Java client library version 1.2.0, when connecting to an MQTT server using TLS and setting a host name verifier, the result of that verification is not checked. This could allow one MQTT server to impersonate another and provide the client library with…

  • CVE-2019-10245HigApr 19, 2019
    risk 0.49cvss 7.5epss 0.02

    In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causing crashes. Eclipse OpenJ9 v0.14.0 correctly detects this case and rejects the attempted class load.

  • CVE-2019-10244HigApr 9, 2019
    risk 0.49cvss 7.5epss 0.02

    In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service (not part of the device distribution) could potentially be target of XXE attack due to an improper factory and parser…

  • CVE-2018-12545HigMar 27, 2019
    risk 0.49cvss 7.5epss 0.05

    In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs frames container containing many settings, or many small SETTINGs frames. The vulnerability is due to the additional CPU and memory…

  • CVE-2017-7655HigMar 27, 2019
    risk 0.49cvss 7.5epss 0.02

    In Eclipse Mosquitto version from 1.0 to 1.4.15, a Null Dereference vulnerability was found in the Mosquitto library which could lead to crashes for those applications using the library.

  • CVE-2019-9004HigFeb 22, 2019
    risk 0.49cvss 7.5epss 0.01

    In Eclipse Wakaama (formerly liblwm2m) 1.0, core/er-coap-13/er-coap-13.c in lwm2mserver in the LWM2M server mishandles invalid options, leading to a memory leak. Processing of a single crafted packet leads to leaking (wasting) 24 bytes of memory. This can lead to termination of…

  • CVE-2017-7656HigJun 26, 2018
    risk 0.49cvss 7.5epss 0.06

    In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), HTTP/0.9 is handled poorly. An HTTP/1 style request line (i.e. method space URI space version) that declares a version of HTTP/0.9 was…

  • CVE-2017-7654HigJun 5, 2018
    risk 0.49cvss 7.5epss 0.02

    In Eclipse Mosquitto 1.4.15 and earlier, a Memory Leak vulnerability was found within the Mosquitto Broker. Unauthenticated clients can send crafted CONNECT packets which could cause a denial of service in the Mosquitto Broker.

  • CVE-2017-7652HigApr 25, 2018
    risk 0.49cvss 7.5epss 0.01

    In Eclipse Mosquitto 1.4.14, if a Mosquitto instance is set running with a configuration file, then sending a HUP signal to server triggers the configuration to be reloaded from disk. If there are lots of clients connected so that there are no more file descriptors/sockets…

  • CVE-2017-7651HigApr 24, 2018
    risk 0.49cvss 7.5epss 0.05

    In Eclipse Mosquitto 1.4.14, a user can shutdown the Mosquitto server simply by filling the RAM memory with a lot of connections with large payload. This can be done without authentications if occur in connection phase of MQTT protocol.

  • CVE-2017-8315HigApr 20, 2018
    risk 0.49cvss 7.5epss 0.01

    Eclipse XML parser for the Eclipse IDE versions 2017.2.5 and earlier was found vulnerable to an XML External Entity attack. An attacker can exploit the vulnerability by implementing malicious code on Androidmanifest.xml.

  • CVE-2017-7243HigMar 24, 2017
    risk 0.49cvss 7.5epss 0.02

    Eclipse tinydtls 0.8.2 for Eclipse IoT allows remote attackers to cause a denial of service (DTLS peer crash) by sending a "Change cipher spec" packet without pre-handshake.

  • CVE-2026-86836HigSep 14, 2026
    risk 0.48cvss —epss 0.00

    In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictable path derived from the agent name and a hash of the workload's runtime configuration. If a directory or FIFO already exists at that path…

  • CVE-2026-19884HigAug 14, 2026
    risk 0.48cvss —epss 0.00

    In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiring the user to trust the folder first. This affects applications built on Theia that include the git integration, such as the Theia IDE. Both Theia's own…

  • CVE-2026-10055HigJul 3, 2026
    risk 0.48cvss 8.5epss 0.00

    In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the standard /services messaging endpoint, performs the HTTP request server-side, and returns the full response body to the caller. …

  • CVE-2026-5795HigApr 8, 2026
    risk 0.48cvss 7.4epss 0.01

    In Eclipse Jetty, the class JASPIAuthenticator initiates the authentication checks, which set two ThreadLocal variable. Upon returning from the initial checks, there are conditions that cause an early return from the JASPIAuthenticator code without clearing those ThreadLocals.…

  • CVE-2023-48695HigDec 5, 2023
    risk 0.48cvss 7.3epss 0.01

    Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause remote code execution due to out of bounds write vulnerabilities in Azure RTOS USBX. The affected components include…

  • CVE-2019-11774HigSep 12, 2019
    risk 0.48cvss 7.4epss 0.01

    Prior to 0.1, all builds of Eclipse OMR contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by versioning - for example if there is a condition that is moved out of the loop that reads a field we may not privatize the value of that…

  • CVE-2019-11775HigJul 30, 2019
    risk 0.48cvss 7.4epss 0.01

    All builds of Eclipse OpenJ9 prior to 0.15 contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by versioning - for example if there is a condition that is moved out of the loop that reads a field we may not privatize the value of…

  • CVE-2026-84173HigSep 7, 2026
    risk 0.47cvss —epss 0.00

    In Eclipse Ankaios versions v0.5.1 through v1.0.1, the agent-side Control Interface authorizer incorrectly evaluates multi-segment allow rules whose first path segment is a wildcard. An authenticated workload with access restricted by such a rule can submit a…

  • CVE-2026-84736HigSep 3, 2026
    risk 0.47cvss —epss 0.00

    In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Federator component disables TLS certificate validation for outbound HTTPS connections by default. When the TLS_CERTIFICATE_VALIDATION environment variable is unset or…

  • CVE-2024-13009HigMay 8, 2025
    risk 0.47cvss 7.2epss 0.01

    In Eclipse Jetty versions 9.4.0 to 9.4.56 a buffer can be incorrectly released when confronted with a gzip error when inflating a request body. This can result in corrupted and/or inadvertent sharing of data between requests.

  • CVE-2024-2212HigMar 26, 2024
    risk 0.47cvss 7.3epss 0.01

    In Eclipse ThreadX before 6.4.0, xQueueCreate() and xQueueCreateSet() functions from the FreeRTOS compatibility API (utility/rtos_compatibility_layers/FreeRTOS/tx_freertos.c) were missing parameter checks. This could lead to integer wraparound, under-allocations and heap…

  • CVE-2026-58080HigAug 4, 2026
    risk 0.46cvss 8.2epss 0.00

    In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role permissions and construct the running configuration through `copy()`, sessions receive no role IDs and the default access controller…

  • CVE-2025-55080HigOct 15, 2025
    risk 0.46cvss 7.1epss 0.00

    In Eclipse ThreadX before 6.4.3, when memory protection is enabled, syscall parameters verification wasn't enough, allowing an attacker to obtain an arbitrary memory read/write.

  • CVE-2024-8642HigSep 11, 2024
    risk 0.46cvss 8.1epss 0.00

    In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for token validity (expiry, not-before, issuance date), which can allow an attacker to bypass the check for token expiration. The…

  • CVE-2024-2452HigMar 26, 2024
    risk 0.46cvss 7.0epss 0.01

    In Eclipse ThreadX NetX Duo before 6.4.0, if an attacker can control parameters of __portable_aligned_alloc() could cause an integer wrap-around and an allocation smaller than expected. This could cause subsequent heap buffer overflows.

Page 3 of 8