VYPR

Vendor CVEs

Eclipse

All CVEs

356 total · sorted by risk
  • CVE-2010-4647Jan 13, 2011
    risk 0.03cvss —epss 0.06

    Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE before 3.6.2 allow remote attackers to inject arbitrary web script or HTML via the query string to (1) help/index.jsp or (2) help/advanced/content.jsp.

  • CVE-2008-7271Jan 13, 2011
    risk 0.03cvss —epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in the Help Contents web application (aka the Help Server) in Eclipse IDE, possibly 3.3.2, allow remote attackers to inject arbitrary web script or HTML via (1) the searchWord parameter to help/advanced/searchView.jsp or (2)…

  • CVE-2009-4612Jan 13, 2010
    risk 0.03cvss —epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in the WebApp JSP Snoop page in Mort Bay Jetty 6.1.x through 6.1.21 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI under (1) jspsnoop/, (2) jspsnoop/ERROR/, and (3)…

  • CVE-2009-4610Jan 13, 2010
    risk 0.03cvss —epss 0.03

    Multiple cross-site scripting (XSS) vulnerabilities in Mort Bay Jetty 6.x and 7.0.0 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to jsp/dump.jsp in the JSP Dump feature, or the (2) Name or (3) Value parameter to the default URI for the…

  • CVE-2009-4521Dec 31, 2009
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in birt-viewer/run in Eclipse Business Intelligence and Reporting Tools (BIRT) before 2.5.0, as used in KonaKart and other products, allows remote attackers to inject arbitrary web script or HTML via the __report parameter.

  • CVE-2006-2758Jun 2, 2006
    risk 0.03cvss —epss 0.04

    Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a %2e%2e%5c (encoded ../) in the URL. NOTE: this might be the same issue as CVE-2005-3747.

  • CVE-2005-3747Nov 22, 2005
    risk 0.03cvss —epss 0.04

    Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly involving requests for .jsp files with URL-encoded backslash ("%5C") characters. NOTE: this might be the same issue as CVE-2006-2758.

  • CVE-2002-1533Mar 31, 2003
    risk 0.03cvss —epss 0.02

    Cross-site scripting (XSS) vulnerability in Jetty JSP servlet engine allows remote attackers to insert arbitrary HTML or script via an HTTP request to a .jsp file whose name contains the malicious script and some encoded linefeed characters (%0a).

  • CVE-2026-15704CriJul 24, 2026
    risk 0.00cvss 9.8epss 0.00

    In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by inconsistent trailing-slash handling between the ABAC middleware and the HTTP router. The shared router configuration used Chi's…

  • CVE-2026-57898CriJul 14, 2026
    risk 0.00cvss 9.0epss 0.01

    In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauthenticated arbitrary file write through the AAS thumbnail API. The AAS thumbnail upload path accepted a client-controlled…

  • CVE-2026-13699MedJul 14, 2026
    risk 0.00cvss 4.3epss 0.00

    In Eclipse KUKSA Databroker version 0.6.1, the kuksa.val.v2.VAL/PublishValue gRPC handler fails to validate the existence of the optional data_point field in PublishValueRequest. When a request contains a valid signal_id but omits data_point, the server directly…

  • CVE-2026-58465HigJul 2, 2026
    risk 0.00cvss 7.5epss 0.01

    Eclipse Wakaama before snapshot/2026-05-26 contains an unbounded memory allocation vulnerability in the CoAP Block1 handler within coap/block.c that allows unauthenticated remote attackers to exhaust server memory by sending a sequence of Block1 PUT requests with incrementing…

  • CVE-2026-9267MedJun 29, 2026
    risk 0.00cvss —epss 0.00

    Eclipse tinydtls before commit b3efd41ad111a4920f599f51ffa4f5e9f1e72221 contains an out-of-bounds read vulnerability in the check_server_certificate() function that allows unauthenticated attackers to trigger reads beyond valid buffer boundaries by crafting a Certificate…

  • CVE-2026-1188CriJan 29, 2026
    risk 0.00cvss 9.8epss 0.01

    In the Eclipse OMR port library component since release 0.2.0, an API function to return the textual names of all supported processor features was not accounting for the separator inserted between processor features. If the output buffer supplied to this function was incorrectly…

  • CVE-2025-14549HigDec 15, 2025
    risk 0.00cvss 8.1epss 0.00

    In the Eclipse OMR compiler component, since release 0.7.0, an optimization enabled for Eclipse OpenJ9 consumers of OMR on Z processors incorrectly handles NUL (0x00) characters during the Latin-compatible charset (UTF-8, ISO8859-1, ASCII, etc) to IBM-1047/037 translation…

  • CVE-2025-6705MedJun 27, 2025
    risk 0.00cvss 5.3epss 0.00

    A vulnerability in the Eclipse Open VSX Registry’s automated publishing system could have allowed unauthorized uploads of extensions. Specifically, the system’s build scripts were executed without proper isolation, potentially exposing a privileged token. This token enabled…

  • CVE-2025-4447HigMay 9, 2025
    risk 0.00cvss 7.8epss 0.00

    In Eclipse OpenJ9 versions up to 0.51, when used with OpenJDK version 8 a stack based buffer overflow can be caused by modifying a file on disk that is read when the JVM starts.

  • CVE-2025-2260HigApr 6, 2025
    risk 0.00cvss 7.5epss 0.01

    In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause a denial of service by specially crafted packets. The core issue is missing closing of a file in case of an error condition, resulting in the 404 error for each further…

  • CVE-2025-2259HigApr 6, 2025
    risk 0.00cvss 7.5epss 0.01

    In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause an integer underflow and a subsequent denial of service by writing a very large file, by specially crafted packets with Content-Length in one packet smaller than the data…

  • CVE-2025-2258HigApr 6, 2025
    risk 0.00cvss 7.5epss 0.01

    In NetX Duo component HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause an integer underflow and a subsequent denial of service by writing a very large file, by specially crafted packets with Content-Length smaller than the data…

  • CVE-2025-1471HigFeb 21, 2025
    risk 0.00cvss 7.8epss 0.00

    In Eclipse OMR versions 0.2.0 to 0.4.0, some of the z/OS atoe print functions use a constant length buffer for string conversion. If the input format string and arguments are larger than the buffer size then buffer overflow occurs. Beginning in version 0.5.0, the conversion…

  • CVE-2025-1470MedFeb 21, 2025
    risk 0.00cvss 5.5epss 0.00

    In Eclipse OMR, from the initial contribution to version 0.4.0, some OMR internal port library and utilities consumers of z/OS atoe functions do not check their return values for NULL memory pointers or for memory allocation failures. This can lead to NULL pointer dereference…

  • CVE-2025-0728HigFeb 21, 2025
    risk 0.00cvss 7.5epss 0.01

    In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause an integer underflow and a subsequent denial of service by writing a very large file, by specially crafted packets with Content-Length smaller than the data request size.…

  • CVE-2025-0727HigFeb 21, 2025
    risk 0.00cvss 7.5epss 0.01

    In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause an integer underflow and a subsequent denial of service by writing a very large file, by specially crafted packets with Content-Length in one packet smaller than the data…

  • CVE-2025-0726HigFeb 21, 2025
    risk 0.00cvss 7.5epss 0.01

    In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause a denial of service by specially crafted packets. The core issue is missing closing of a file in case of an error condition, resulting in the 404 error for each further…

  • CVE-2024-10917LowNov 11, 2024
    risk 0.00cvss 3.7epss 0.00

    In Eclipse OpenJ9 versions up to 0.47, the JNI function GetStringUTFLength may return an incorrect value which has wrapped around. From 0.48 the value is correct but may be truncated to include a smaller number of characters.

  • CVE-2024-8376HigOct 11, 2024
    risk 0.00cvss 7.5epss 0.01

    In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE" and "PUBLISH" packets.

  • CVE-2024-9202MedSep 27, 2024
    risk 0.00cvss 5.3epss 0.00

    In Eclipse Dataspace Components versions 0.1.3 to 0.9.0, the Connector component filters which datasets (= data offers) another party can see in a requested catalog, to ensure that only authorized parties are able to view restricted offers. However, there is the possibility to…

  • CVE-2023-5676MedNov 15, 2023
    risk 0.00cvss 4.1epss 0.00

    In Eclipse OpenJ9 before version 0.41.0, the JVM can be forced into an infinite busy hang on a spinlock or a segmentation fault if a shutdown signal (SIGTERM, SIGINT or SIGHUP) is received before the JVM has finished initializing.

  • CVE-2023-5632HigOct 18, 2023
    risk 0.00cvss 7.5epss 0.01

    In Eclipse Mosquito before and including 2.0.5, establishing a connection to the mosquitto server without sending data causes the EPOLLOUT event to be added, which results excessive CPU consumption. This could be used by a malicious actor to perform denial of service type…

  • CVE-2023-4760HigSep 21, 2023
    risk 0.00cvss 7.6epss 0.01

    In Eclipse RAP versions from 3.0.0 up to and including 3.25.0, Remote Code Execution is possible on Windows when using the FileUpload component. The reason for this is a not completely secure extraction of the file name in the FileUploadProcessor.stripFileName(String name)…

  • CVE-2023-28366HigSep 1, 2023
    risk 0.00cvss 7.5epss 0.01

    The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc…

  • CVE-2023-2597HigMay 22, 2023
    risk 0.00cvss 7.0epss 0.00

    In Eclipse Openj9 before version 0.38.0, in the implementation of the shared cache (which is enabled by default in OpenJ9 builds) the size of a string is not properly checked against the size of the buffer.

  • CVE-2022-3676MedOct 24, 2022
    risk 0.00cvss 6.5epss 0.01

    In Eclipse Openj9 before version 0.35.0, interface calls can be inlined without a runtime type check. Malicious bytecode could make use of this inlining to access or modify memory via an incompatible type.

  • CVE-2021-41041MedApr 27, 2022
    risk 0.00cvss 5.3epss 0.01

    In Eclipse Openj9 before version 0.32.0, Java 8 & 11 fail to throw the exception captured during bytecode verification when verification is triggered by a MethodHandle invocation, allowing unverified methods to be invoked using MethodHandles.

  • CVE-2022-0673MedFeb 18, 2022
    risk 0.00cvss 6.5epss 0.01

    A flaw was found in LemMinX in versions prior to 0.19.0. Cache poisoning of external schema files due to directory traversal.

  • CVE-2021-41040HigFeb 1, 2022
    risk 0.00cvss 7.5epss 0.01

    In Eclipse Wakaama, ever since its inception until 2021-01-14, the CoAP parsing code does not properly sanitize network-received data.

  • CVE-2021-41038MedNov 10, 2021
    risk 0.00cvss 6.1epss 0.01

    In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage().

  • CVE-2021-41035CriOct 25, 2021
    risk 0.00cvss 9.8epss 0.02

    In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.

  • CVE-2021-28170MedMay 26, 2021
    risk 0.00cvss 5.3epss 0.02

    In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid.

  • CVE-2021-28168MedApr 22, 2021
    risk 0.00cvss 6.2epss 0.01

    Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. Thus the…

  • CVE-2021-28162MedMar 12, 2021
    risk 0.00cvss 6.1epss 0.01

    In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run.

  • CVE-2020-27224CriFeb 24, 2021
    risk 0.00cvss 9.6epss 0.03

    In Eclipse Theia versions up to and including 1.2.0, the Markdown Preview (@theia/preview), can be exploited to execute arbitrary code.

  • CVE-2020-35217HigJan 20, 2021
    risk 0.00cvss 8.8epss 0.01

    Vert.x-Web framework v4.0 milestone 1-4 does not perform a correct CSRF verification. Instead of comparing the CSRF token in the request with the CSRF token in the cookie, it compares the CSRF token in the cookie against a CSRF token that is stored in the session. An attacker…

  • CVE-2018-20145HigDec 13, 2018
    risk 0.00cvss 7.5epss 0.02

    Eclipse Mosquitto 1.5.x before 1.5.5 allows ACL bypass: if the option per_listener_settings was set to true, and the default listener was in use, and the default listener specified an acl_file, then the acl file was being ignored.

  • CVE-2009-4609Jan 13, 2010
    risk 0.00cvss —epss 0.02

    The Dump Servlet in Mort Bay Jetty 6.x and 7.0.0 allows remote attackers to obtain sensitive information about internal variables and other data via a request to a URI ending in /dump/, as demonstrated by discovering the value of the getPathTranslated variable.

  • CVE-2009-3579Oct 7, 2009
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the CookieDump.java sample application in Mort Bay Jetty 6.1.19 and 6.1.20 allows remote attackers to inject arbitrary web script or HTML via the Value parameter in a GET request to cookie/.

  • CVE-2009-1524May 5, 2009
    risk 0.00cvss —epss 0.03

    Cross-site scripting (XSS) vulnerability in Mort Bay Jetty before 6.1.17 allows remote attackers to inject arbitrary web script or HTML via a directory listing request containing a ; (semicolon) character.

  • CVE-2007-6672Jan 8, 2008
    risk 0.00cvss —epss 0.04

    Mortbay Jetty 6.1.5 and 6.1.6 allows remote attackers to bypass protection mechanisms and read the source of files via multiple '/' (slash) characters in the URI.

  • CVE-2007-5614Dec 5, 2007
    risk 0.00cvss —epss 0.04

    Mortbay Jetty before 6.1.6rc1 does not properly handle "certain quote sequences" in HTML cookie parameters, which allows remote attackers to hijack browser sessions via unspecified vectors.

Page 7 of 8