VYPR

Vendor CVEs

Eclipse

All CVEs

356 total · sorted by risk
  • CVE-2024-2214HigMar 26, 2024
    risk 0.46cvss 7.0epss 0.00

    In Eclipse ThreadX before version 6.4.0, the _Mtxinit() function in the Xtensa port was missing an array size check causing a memory overwrite. The affected file was ports/xtensa/xcc/src/tx_clib_lock.c

  • CVE-2022-39368HigNov 10, 2022
    risk 0.46cvss 8.2epss 0.01

    Eclipse Californium is a Java implementation of RFC7252 - Constrained Application Protocol for IoT Cloud services. In versions prior to 3.7.0, and 2.7.4, Californium is vulnerable to a Denial of Service. Failing handshakes don't cleanup counters for throttling, causing the…

  • CVE-2020-14368HigDec 14, 2020
    risk 0.46cvss 7.1epss 0.01

    A flaw was found in Eclipse Che in versions prior to 7.14.0 that impacts CodeReady Workspaces. When configured with cookies authentication, Theia IDE doesn't properly set the SameSite value, allowing a Cross-Site Request Forgery (CSRF) and consequently allowing a cross-site…

  • CVE-2020-27216HigOct 23, 2020
    risk 0.46cvss 7.0epss 0.04

    In Eclipse Jetty versions 1.0 thru 9.4.32.v20200930, 10.0.0.alpha1 thru 10.0.0.beta2, and 11.0.0.alpha1 thru 11.0.0.beta2O, on Unix like systems, the system's temporary directory is shared between all users on that system. A collocated user can observe the process of creating a…

  • CVE-2019-17637HigJul 15, 2020
    risk 0.46cvss 7.1epss 0.01

    In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in…

  • CVE-2019-17636HigMar 10, 2020
    risk 0.46cvss 8.1epss 0.01

    In Eclipse Theia versions 0.3.9 through 0.15.0, one of the default pre-packaged Theia extensions is "Mini-Browser", published as "@theia/mini-browser" on npmjs.com. This extension, for its own needs, exposes a HTTP endpoint that allows to read the content of files on the host's…

  • CVE-2019-10249HigMay 6, 2019
    risk 0.46cvss 8.1epss 0.01

    All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artifacts may have been compromised.

  • CVE-2021-34429MedJul 15, 2021
    risk 0.45cvss 5.3epss 0.99

    For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerability reported in…

  • CVE-2023-48698MedDec 5, 2023
    risk 0.44cvss 6.8epss 0.01

    Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause remote code execution due to expired pointer dereference vulnerabilities in Azure RTOS USBX. The affected components include…

  • CVE-2023-48696MedDec 5, 2023
    risk 0.44cvss 6.7epss 0.01

    Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause remote code execution due to expired pointer dereference vulnerabilities in Azure RTOS USBX. The affected components include…

  • CVE-2023-48694MedDec 5, 2023
    risk 0.44cvss 6.8epss 0.01

    Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause remote code execution due to expired pointer dereference and type confusion vulnerabilities in Azure RTOS USBX. The affected…

  • CVE-2023-5763MedNov 3, 2023
    risk 0.44cvss 6.8epss 0.01

    In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 6u211, or < 7u201, or < 8u191), allows remote attackers to load malicious code on the server via access to insecure ORB listeners.

  • CVE-2021-28164MedApr 1, 2021
    risk 0.44cvss 5.3epss 0.82

    In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the…

  • CVE-2021-38443MedMay 5, 2022
    risk 0.43cvss 6.6epss 0.02

    Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write arbitrary values in the XML parser.

  • CVE-2021-38441MedMay 5, 2022
    risk 0.43cvss 6.6epss 0.02

    Eclipse CycloneDDS versions prior to 0.8.0 are vulnerable to a write-what-where condition, which may allow an attacker to write arbitrary values in the XML parser.

  • CVE-2026-82958HigSep 2, 2026
    risk 0.42cvss —epss 0.00

    In Eclipse Ditto versions [1.3.0, 3.9.6], the ImplicitThingCreationMessageMapper of the connectivity service builds a CreateThing command by substituting placeholder values (e.g. {{ header:device_id }}) resolved from inbound message headers into a pre-configured JSON "thing"…

  • CVE-2026-14574MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` recursively merges preference values without rejecting prototype-related keys (`__proto__`, `constructor`, `prototype`). Because this function is invoked by…

  • CVE-2026-63252HigAug 4, 2026
    risk 0.42cvss 7.5epss 0.00

    In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnects, allowing a remote unauthenticated client to exhaust pooled direct memory by repeatedly sending incomplete chunks and…

  • CVE-2026-62927HigAug 4, 2026
    risk 0.42cvss 7.5epss 0.00

    In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or otherwise low-privileged client to execute a denied method by batching it with an allowed method.

  • CVE-2026-61387HigAug 4, 2026
    risk 0.42cvss 7.5epss 0.00

    In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, the server-global reservation is not restored. Deeply nested PubSub ExtensionObjects in a `CreateMonitoredItems` event filter can…

  • CVE-2026-10051HigJul 14, 2026
    risk 0.42cvss 7.5epss 0.00

    In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the same connection. Subsequent request that do not have trailers report the trailers of the first request. Subsequent request that do have…

  • CVE-2024-7708HigJul 14, 2026
    risk 0.42cvss 7.5epss 0.00

    For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case for 100-Continue, but any request where the network is slow can leak.

  • CVE-2026-9563HigJul 2, 2026
    risk 0.42cvss 7.5epss 0.01

    In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default maximum on the number of characters consumed while parsing a single JSON document. Applications that parse attacker- controlled JSON can be forced to consume…

  • CVE-2026-6918HigMay 5, 2026
    risk 0.42cvss 7.5epss 0.01

    In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message.

  • CVE-2026-1605HigMar 5, 2026
    risk 0.42cvss 7.5epss 0.01

    In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed and the corresponding response is not compressed. This happens because the JDK Inflater is allocated…

  • CVE-2025-11966MedOct 22, 2025
    risk 0.42cvss 6.4epss 0.00

    In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], when "directory listing" is enabled, file and directory names are inserted into generated HTML without proper escaping in the href, title, and link attributes. An attacker who can create or rename files or…

  • CVE-2025-55091MedOct 16, 2025
    risk 0.42cvss 6.5epss 0.00

    In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ip_packet_receive() function when received an Ethernet with type set as IP but no IP data.

  • CVE-2025-55090MedOct 16, 2025
    risk 0.42cvss 6.5epss 0.00

    In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_packet_receive() function when received an Ethernet frame with less than 4 bytes of IP packet.

  • CVE-2025-5115HigAug 20, 2025
    risk 0.42cvss 7.5epss 0.03

    In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for example by sending frames that are malformed or that should not be sent in a particular stream state, therefore forcing…

  • CVE-2025-7962HigJul 21, 2025
    risk 0.42cvss 7.5epss 0.01

    In Jakarta Mail versions prior to 2.0.2 it is possible to perform an SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages.

  • CVE-2025-1948HigMay 8, 2025
    risk 0.42cvss 7.5epss 0.01

    In Eclipse Jetty versions 12.0.0 to 12.0.16 included, an HTTP/2 client can specify a very large value for the HTTP/2 settings parameter SETTINGS_MAX_HEADER_LIST_SIZE. The Jetty HTTP/2 server does not perform validation on this setting, and tries to allocate a ByteBuffer of the…

  • CVE-2024-8391HigSep 4, 2024
    risk 0.42cvss 7.5epss 0.01

    In Eclipse Vert.x version 4.3.0 to 4.5.9, the gRPC server does not limit the maximum length of message payload (Maven GAV: io.vertx:vertx-grpc-server and io.vertx:vertx-grpc-client).  This is fixed in the 4.5.10 version.  Note this does not affect the Vert.x gRPC…

  • CVE-2024-22201HigFeb 26, 2024
    risk 0.42cvss 7.5epss 0.01

    Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out. An attacker can cause many connections to end up in this state, and the server may run out of file descriptors, eventually…

  • CVE-2023-48697MedDec 5, 2023
    risk 0.42cvss 6.4epss 0.01

    Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause remote code execution due to memory buffer and pointer vulnerabilities in Azure RTOS USBX. The affected components include…

  • CVE-2023-36478HigOct 10, 2023
    risk 0.42cvss 7.5epss 0.04

    Eclipse Jetty provides a web server and servlet container. In versions 11.0.0 through 11.0.15, 10.0.0 through 10.0.15, and 9.0.0 through 9.4.52, an integer overflow in `MetaDataBuilder.checkSize` allows for HTTP/2 HPACK header values to exceed their size limit.…

  • CVE-2022-2576HigJul 29, 2022
    risk 0.42cvss 7.5epss 0.01

    In Eclipse Californium version 2.0.0 to 2.7.2 and 3.0.0-3.5.0 a DTLS resumption handshake falls back to a DTLS full handshake on a parameter mismatch without using a HelloVerifyRequest. Especially, if used with certificate based cipher suites, that results in message…

  • CVE-2021-34431MedJul 22, 2021
    risk 0.42cvss 6.5epss 0.01

    In Eclipse Mosquitto version 1.6 to 2.0.10, if an authenticated client that had connected with MQTT v5 sent a crafted CONNECT message to the broker a memory leak would occur, which could be used to provide a DoS attack against the broker.

  • CVE-2021-28167MedApr 21, 2021
    risk 0.42cvss 6.5epss 0.01

    In Eclipse Openj9 to version 0.25.0, usage of the jdk.internal.reflect.ConstantPool API causes the JVM in some cases to pre-resolve certain constant pool entries. This allows a user to call static methods or access static members without running the class initialization method,…

  • CVE-2021-28166MedApr 7, 2021
    risk 0.42cvss 6.5epss 0.01

    In Eclipse Mosquitto version 2.0.0 to 2.0.9, if an authenticated client that had connected with MQTT v5 sent a crafted CONNACK message to the broker, a NULL pointer dereference would occur.

  • CVE-2021-22553MedFeb 17, 2021
    risk 0.42cvss 6.5epss 0.00

    Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not automatically dispose of the session. Over multiple git actions, this can lead to a heap memory exhaustion for Gerrit servers. We recommend upgrading Gerrit to…

  • CVE-2020-10689MedApr 3, 2020
    risk 0.42cvss 6.4epss 0.01

    A flaw was found in the Eclipse Che up to version 7.8.x, where it did not properly restrict access to workspace pods. An authenticated user can exploit this flaw to bypass JWT proxy and gain access to the workspace pods of another user. Successful exploitation requires knowledge…

  • CVE-2018-12546MedMar 27, 2019
    risk 0.42cvss 6.5epss 0.01

    In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a retained message to a topic, then has its access to that topic revoked, the retained message will still be published to clients that subscribe to that topic in the future. In some applications this…

  • CVE-2018-20227HigDec 19, 2018
    risk 0.42cvss 7.5epss 0.02

    RDF4J 2.4.2 allows Directory Traversal via ../ in an entry in a ZIP archive.

  • CVE-2018-14371HigJul 18, 2018
    risk 0.42cvss 7.5epss 0.04

    The getLocalePrefix function in ResourceManager.java in Eclipse Mojarra before 2.3.7 is affected by Directory Traversal via the loc parameter. A remote attacker can download configuration files or Java bytecodes from applications.

  • CVE-2017-7650MedSep 11, 2017
    risk 0.42cvss 6.5epss 0.02

    In Mosquitto before 1.4.12, pattern based ACLs can be bypassed by clients that set their username/client id to '#' or '+'. This allows locally or remotely connected clients to access MQTT topics that they do have the rights to. The same issue may be present in third party…

  • CVE-2017-9735HigJun 16, 2017
    risk 0.42cvss 7.5epss 0.06

    Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.

  • CVE-2026-88819MedSep 14, 2026
    risk 0.41cvss —epss 0.00

    In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.

  • CVE-2026-60007HigAug 4, 2026
    risk 0.41cvss 7.4epss 0.00

    In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's `Basic128Rsa15`-encrypted username token to use…

  • CVE-2026-2332HigApr 14, 2026
    risk 0.41cvss 7.4epss 0.01

    In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/2025/10/29/funky-chunks-2.html Jetty…

  • CVE-2025-12383HigNov 18, 2025
    risk 0.41cvss 7.4epss 0.00

    In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such as mutual authentication, custom key/trust stores, and other security settings. This issue may result in SSLHandshakeException under normal circumstances, but…

Page 4 of 8