VYPR

Vendor CVEs

Eclipse

All CVEs

334 total · sorted by risk
  • CVE-2026-14574MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` recursively merges preference values without rejecting prototype-related keys (`__proto__`, `constructor`, `prototype`). Because this function is invoked by…

  • CVE-2026-63252HigAug 4, 2026
    risk 0.42cvss 7.5epss 0.00

    In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnects, allowing a remote unauthenticated client to exhaust pooled direct memory by repeatedly sending incomplete chunks and…

  • CVE-2026-62927HigAug 4, 2026
    risk 0.42cvss 7.5epss 0.00

    In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating authorization, allowing an anonymous or otherwise low-privileged client to execute a denied method by batching it with an allowed method.

  • CVE-2026-61387HigAug 4, 2026
    risk 0.42cvss 7.5epss 0.00

    In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, the server-global reservation is not restored. Deeply nested PubSub ExtensionObjects in a `CreateMonitoredItems` event filter can…

  • CVE-2026-10051HigJul 14, 2026
    risk 0.42cvss 7.5epss 0.00

    In Eclipse Jetty, a first HTTP/1.1 request with trailers causes the server to retain the trailers in subsequent requests performed over the same connection. Subsequent request that do not have trailers report the trailers of the first request. Subsequent request that do have…

  • CVE-2024-7708HigJul 14, 2026
    risk 0.42cvss 7.5epss 0.00

    For requests that have a body, but reading the body may end up in reading 0 bytes, there is a buffer leak. This is particularly the case for 100-Continue, but any request where the network is slow can leak.

  • CVE-2026-9563HigJul 2, 2026
    risk 0.42cvss 7.5epss 0.00

    In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default maximum on the number of characters consumed while parsing a single JSON document. Applications that parse attacker- controlled JSON can be forced to consume…

  • CVE-2026-6918HigMay 5, 2026
    risk 0.42cvss 7.5epss 0.01

    In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message.

  • CVE-2026-1605HigMar 5, 2026
    risk 0.42cvss 7.5epss 0.01

    In Eclipse Jetty, versions 12.0.0-12.0.31 and 12.1.0-12.0.5, class GzipHandler exposes a vulnerability when a compressed HTTP request, with Content-Encoding: gzip, is processed and the corresponding response is not compressed. This happens because the JDK Inflater is allocated…

  • CVE-2025-11966MedOct 22, 2025
    risk 0.42cvss 6.4epss 0.00

    In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], when "directory listing" is enabled, file and directory names are inserted into generated HTML without proper escaping in the href, title, and link attributes. An attacker who can create or rename files or…

  • CVE-2025-55091MedOct 16, 2025
    risk 0.42cvss 6.5epss 0.00

    In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ip_packet_receive() function when received an Ethernet with type set as IP but no IP data.

  • CVE-2025-55090MedOct 16, 2025
    risk 0.42cvss 6.5epss 0.00

    In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_packet_receive() function when received an Ethernet frame with less than 4 bytes of IP packet.

  • CVE-2025-5115HigAug 20, 2025
    risk 0.42cvss 7.5epss 0.02

    In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for example by sending frames that are malformed or that should not be sent in a particular stream state, therefore forcing…

  • CVE-2025-7962HigJul 21, 2025
    risk 0.42cvss 7.5epss 0.01

    In Jakarta Mail versions prior to 2.0.2 it is possible to perform an SMTP Injection by utilizing the \r and \n UTF-8 characters to separate different messages.

  • CVE-2025-1948HigMay 8, 2025
    risk 0.42cvss 7.5epss 0.01

    In Eclipse Jetty versions 12.0.0 to 12.0.16 included, an HTTP/2 client can specify a very large value for the HTTP/2 settings parameter SETTINGS_MAX_HEADER_LIST_SIZE. The Jetty HTTP/2 server does not perform validation on this setting, and tries to allocate a ByteBuffer of the…

  • CVE-2024-8391HigSep 4, 2024
    risk 0.42cvss 7.5epss 0.01

    In Eclipse Vert.x version 4.3.0 to 4.5.9, the gRPC server does not limit the maximum length of message payload (Maven GAV: io.vertx:vertx-grpc-server and io.vertx:vertx-grpc-client).  This is fixed in the 4.5.10 version.  Note this does not affect the Vert.x gRPC…

  • CVE-2024-22201HigFeb 26, 2024
    risk 0.42cvss 7.5epss 0.01

    Jetty is a Java based web server and servlet engine. An HTTP/2 SSL connection that is established and TCP congested will be leaked when it times out. An attacker can cause many connections to end up in this state, and the server may run out of file descriptors, eventually…

  • CVE-2023-48697MedDec 5, 2023
    risk 0.42cvss 6.4epss 0.01

    Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. An attacker can cause remote code execution due to memory buffer and pointer vulnerabilities in Azure RTOS USBX. The affected components include…

  • CVE-2023-36478HigOct 10, 2023
    risk 0.42cvss 7.5epss 0.04

    Eclipse Jetty provides a web server and servlet container. In versions 11.0.0 through 11.0.15, 10.0.0 through 10.0.15, and 9.0.0 through 9.4.52, an integer overflow in `MetaDataBuilder.checkSize` allows for HTTP/2 HPACK header values to exceed their size limit.…

  • CVE-2022-2576HigJul 29, 2022
    risk 0.42cvss 7.5epss 0.01

    In Eclipse Californium version 2.0.0 to 2.7.2 and 3.0.0-3.5.0 a DTLS resumption handshake falls back to a DTLS full handshake on a parameter mismatch without using a HelloVerifyRequest. Especially, if used with certificate based cipher suites, that results in message…

  • CVE-2021-34431MedJul 22, 2021
    risk 0.42cvss 6.5epss 0.01

    In Eclipse Mosquitto version 1.6 to 2.0.10, if an authenticated client that had connected with MQTT v5 sent a crafted CONNECT message to the broker a memory leak would occur, which could be used to provide a DoS attack against the broker.

  • CVE-2021-28167MedApr 21, 2021
    risk 0.42cvss 6.5epss 0.01

    In Eclipse Openj9 to version 0.25.0, usage of the jdk.internal.reflect.ConstantPool API causes the JVM in some cases to pre-resolve certain constant pool entries. This allows a user to call static methods or access static members without running the class initialization method,…

  • CVE-2021-28166MedApr 7, 2021
    risk 0.42cvss 6.5epss 0.01

    In Eclipse Mosquitto version 2.0.0 to 2.0.9, if an authenticated client that had connected with MQTT v5 sent a crafted CONNACK message to the broker, a NULL pointer dereference would occur.

  • CVE-2021-22553MedFeb 17, 2021
    risk 0.42cvss 6.5epss 0.00

    Any git operation is passed through Jetty and a session is created. No expiry is set for the session and Jetty does not automatically dispose of the session. Over multiple git actions, this can lead to a heap memory exhaustion for Gerrit servers. We recommend upgrading Gerrit to…

  • CVE-2020-10689MedApr 3, 2020
    risk 0.42cvss 6.4epss 0.01

    A flaw was found in the Eclipse Che up to version 7.8.x, where it did not properly restrict access to workspace pods. An authenticated user can exploit this flaw to bypass JWT proxy and gain access to the workspace pods of another user. Successful exploitation requires knowledge…

  • CVE-2018-12546MedMar 27, 2019
    risk 0.42cvss 6.5epss 0.01

    In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a retained message to a topic, then has its access to that topic revoked, the retained message will still be published to clients that subscribe to that topic in the future. In some applications this…

  • CVE-2018-20227HigDec 19, 2018
    risk 0.42cvss 7.5epss 0.02

    RDF4J 2.4.2 allows Directory Traversal via ../ in an entry in a ZIP archive.

  • CVE-2018-14371HigJul 18, 2018
    risk 0.42cvss 7.5epss 0.04

    The getLocalePrefix function in ResourceManager.java in Eclipse Mojarra before 2.3.7 is affected by Directory Traversal via the loc parameter. A remote attacker can download configuration files or Java bytecodes from applications.

  • CVE-2017-7650MedSep 11, 2017
    risk 0.42cvss 6.5epss 0.02

    In Mosquitto before 1.4.12, pattern based ACLs can be bypassed by clients that set their username/client id to '#' or '+'. This allows locally or remotely connected clients to access MQTT topics that they do have the rights to. The same issue may be present in third party…

  • CVE-2017-9735HigJun 16, 2017
    risk 0.42cvss 7.5epss 0.06

    Jetty through 9.4.x is prone to a timing channel in util/security/Password.java, which makes it easier for remote attackers to obtain access by observing elapsed times before rejection of incorrect passwords.

  • CVE-2026-60007HigAug 4, 2026
    risk 0.41cvss 7.4epss 0.00

    In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other authentication failures, allowing an on-path attacker who captures a victim's `Basic128Rsa15`-encrypted username token to use…

  • CVE-2025-12383HigNov 18, 2025
    risk 0.41cvss 7.4epss 0.00

    In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such as mutual authentication, custom key/trust stores, and other security settings. This issue may result in SSLHandshakeException under normal circumstances, but…

  • CVE-2021-28169MedJun 9, 2021
    risk 0.41cvss 5.3epss 0.78

    For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to access protected resources within the WEB-INF directory. For example a request to `/concat?/%2557EB-INF/web.xml` can retrieve the web.xml…

  • CVE-2025-55099MedOct 17, 2025
    risk 0.40cvss 6.1epss 0.00

    In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio_alternate_setting_locate() when parsing a descriptor with attacker-controlled frequency fields.

  • CVE-2025-55098MedOct 17, 2025
    risk 0.40cvss 6.1epss 0.00

    In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio_device_type_get() when parsing a descriptor of an USB audio device.

  • CVE-2025-55097MedOct 17, 2025
    risk 0.40cvss 6.1epss 0.00

    In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio_streaming_sampling_get() when parsing a descriptor of an USB streaming device.

  • CVE-2025-55096MedOct 17, 2025
    risk 0.40cvss 6.1epss 0.00

    In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_hid_report_descriptor_get()  when parsing a descriptor of an USB HID device.

  • CVE-2024-9343MedJul 16, 2025
    risk 0.40cvss 6.1epss 0.00

    In Eclipse GlassFish version 7.0.15 is possible to perform Stored Cross-site scripting attacks in the Administration Console.

  • CVE-2024-10029MedJul 16, 2025
    risk 0.40cvss 6.1epss 0.00

    In Eclipse GlassFish version 7.0.15 is possible to perform Reflected Cross-site scripting attacks in the Administration Console.

  • CVE-2021-28161MedMar 12, 2021
    risk 0.40cvss 6.1epss 0.01

    In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javascript code can be injected.

  • CVE-2019-17632MedNov 25, 2019
    risk 0.40cvss 6.1epss 0.02

    In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in text/html and text/json Content-Type) does not escape Exception messages in stacktraces included in error output.

  • CVE-2009-5046MedNov 6, 2019
    risk 0.40cvss 6.1epss 0.02

    JSP Dump and Session Dump Servlet XSS in jetty before 6.1.22.

  • CVE-2009-5049MedNov 6, 2019
    risk 0.40cvss 6.1epss 0.02

    WebApp JSP Snoop page XSS in jetty though 6.1.21.

  • CVE-2009-5048MedNov 6, 2019
    risk 0.40cvss 6.1epss 0.02

    Cookie Dump Servlet stored XSS vulnerability in jetty though 6.1.20.

  • CVE-2019-11776MedAug 9, 2019
    risk 0.40cvss 6.1epss 0.01

    In Eclipse BIRT versions 1.0 to 4.7, the Report Viewer allows Reflected XSS in URL parameter. Attacker can execute the payload in victim's browser context.

  • CVE-2019-10241MedApr 22, 2019
    risk 0.40cvss 6.1epss 0.10

    In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory…

  • CVE-2023-3592MedOct 2, 2023
    risk 0.38cvss 5.8epss 0.01

    In Mosquitto before 2.0.16, a memory leak occurs when clients send v5 CONNECT packets with a will message that contains invalid property types.

  • CVE-2023-0809MedOct 2, 2023
    risk 0.38cvss 5.8epss 0.01

    In Mosquitto before 2.0.16, excessive memory is allocated based on malicious initial packets that are not CONNECT packets.

  • CVE-2024-4536MedMay 7, 2024
    risk 0.37cvss 6.8epss 0.00

    In Eclipse Dataspace Components from version 0.2.1 to 0.6.2, in the EDC Connector component ( https://github.com/eclipse-edc/Connector ), an attacker might obtain OAuth2 client secrets from the vault. In Eclipse Dataspace Components from version 0.2.1 to 0.6.2, we have…

  • CVE-2026-14304MedAug 5, 2026
    risk 0.36cvss 5.5epss 0.00

    In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. If this…

Page 4 of 7