VYPR

Vendor CVEs

Eclipse

All CVEs

334 total · sorted by risk
  • CVE-2025-0728HigFeb 21, 2025
    risk 0.00cvss 7.5epss 0.01

    In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause an integer underflow and a subsequent denial of service by writing a very large file, by specially crafted packets with Content-Length smaller than the data request size.…

  • CVE-2025-0727HigFeb 21, 2025
    risk 0.00cvss 7.5epss 0.01

    In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause an integer underflow and a subsequent denial of service by writing a very large file, by specially crafted packets with Content-Length in one packet smaller than the data…

  • CVE-2025-0726HigFeb 21, 2025
    risk 0.00cvss 7.5epss 0.01

    In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause a denial of service by specially crafted packets. The core issue is missing closing of a file in case of an error condition, resulting in the 404 error for each further…

  • CVE-2024-10917LowNov 11, 2024
    risk 0.00cvss 3.7epss 0.00

    In Eclipse OpenJ9 versions up to 0.47, the JNI function GetStringUTFLength may return an incorrect value which has wrapped around. From 0.48 the value is correct but may be truncated to include a smaller number of characters.

  • CVE-2024-8376HigOct 11, 2024
    risk 0.00cvss 7.5epss 0.01

    In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific sequences of "CONNECT", "DISCONNECT", "SUBSCRIBE", "UNSUBSCRIBE" and "PUBLISH" packets.

  • CVE-2024-9202MedSep 27, 2024
    risk 0.00cvss 5.3epss 0.00

    In Eclipse Dataspace Components versions 0.1.3 to 0.9.0, the Connector component filters which datasets (= data offers) another party can see in a requested catalog, to ensure that only authorized parties are able to view restricted offers. However, there is the possibility to…

  • CVE-2023-5676MedNov 15, 2023
    risk 0.00cvss 4.1epss 0.00

    In Eclipse OpenJ9 before version 0.41.0, the JVM can be forced into an infinite busy hang on a spinlock or a segmentation fault if a shutdown signal (SIGTERM, SIGINT or SIGHUP) is received before the JVM has finished initializing.

  • CVE-2023-5632HigOct 18, 2023
    risk 0.00cvss 7.5epss 0.01

    In Eclipse Mosquito before and including 2.0.5, establishing a connection to the mosquitto server without sending data causes the EPOLLOUT event to be added, which results excessive CPU consumption. This could be used by a malicious actor to perform denial of service type…

  • CVE-2023-4760HigSep 21, 2023
    risk 0.00cvss 7.6epss 0.01

    In Eclipse RAP versions from 3.0.0 up to and including 3.25.0, Remote Code Execution is possible on Windows when using the FileUpload component. The reason for this is a not completely secure extraction of the file name in the FileUploadProcessor.stripFileName(String name)…

  • CVE-2023-28366HigSep 1, 2023
    risk 0.00cvss 7.5epss 0.01

    The broker in Eclipse Mosquitto 1.3.2 through 2.x before 2.0.16 has a memory leak that can be abused remotely when a client sends many QoS 2 messages with duplicate message IDs, and fails to respond to PUBREC commands. This occurs because of mishandling of EAGAIN from the libc…

  • CVE-2023-2597HigMay 22, 2023
    risk 0.00cvss 7.0epss 0.00

    In Eclipse Openj9 before version 0.38.0, in the implementation of the shared cache (which is enabled by default in OpenJ9 builds) the size of a string is not properly checked against the size of the buffer.

  • CVE-2022-3676MedOct 24, 2022
    risk 0.00cvss 6.5epss 0.01

    In Eclipse Openj9 before version 0.35.0, interface calls can be inlined without a runtime type check. Malicious bytecode could make use of this inlining to access or modify memory via an incompatible type.

  • CVE-2021-41041MedApr 27, 2022
    risk 0.00cvss 5.3epss 0.01

    In Eclipse Openj9 before version 0.32.0, Java 8 & 11 fail to throw the exception captured during bytecode verification when verification is triggered by a MethodHandle invocation, allowing unverified methods to be invoked using MethodHandles.

  • CVE-2022-0673MedFeb 18, 2022
    risk 0.00cvss 6.5epss 0.01

    A flaw was found in LemMinX in versions prior to 0.19.0. Cache poisoning of external schema files due to directory traversal.

  • CVE-2021-41040HigFeb 1, 2022
    risk 0.00cvss 7.5epss 0.01

    In Eclipse Wakaama, ever since its inception until 2021-01-14, the CoAP parsing code does not properly sanitize network-received data.

  • CVE-2021-41038MedNov 10, 2021
    risk 0.00cvss 6.1epss 0.01

    In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage().

  • CVE-2021-41035CriOct 25, 2021
    risk 0.00cvss 9.8epss 0.02

    In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.

  • CVE-2021-28170MedMay 26, 2021
    risk 0.00cvss 5.3epss 0.02

    In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated as if they were valid.

  • CVE-2021-28168MedApr 22, 2021
    risk 0.00cvss 6.2epss 0.01

    Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the File.createTempFile which creates a file inside of the system temporary directory with the permissions: -rw-r--r--. Thus the…

  • CVE-2021-28162MedMar 12, 2021
    risk 0.00cvss 6.1epss 0.01

    In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run.

  • CVE-2020-27224CriFeb 24, 2021
    risk 0.00cvss 9.6epss 0.02

    In Eclipse Theia versions up to and including 1.2.0, the Markdown Preview (@theia/preview), can be exploited to execute arbitrary code.

  • CVE-2020-35217HigJan 20, 2021
    risk 0.00cvss 8.8epss 0.01

    Vert.x-Web framework v4.0 milestone 1-4 does not perform a correct CSRF verification. Instead of comparing the CSRF token in the request with the CSRF token in the cookie, it compares the CSRF token in the cookie against a CSRF token that is stored in the session. An attacker…

  • CVE-2018-20145HigDec 13, 2018
    risk 0.00cvss 7.5epss 0.02

    Eclipse Mosquitto 1.5.x before 1.5.5 allows ACL bypass: if the option per_listener_settings was set to true, and the default listener was in use, and the default listener specified an acl_file, then the acl file was being ignored.

  • CVE-2009-4609Jan 13, 2010
    risk 0.00cvss epss 0.02

    The Dump Servlet in Mort Bay Jetty 6.x and 7.0.0 allows remote attackers to obtain sensitive information about internal variables and other data via a request to a URI ending in /dump/, as demonstrated by discovering the value of the getPathTranslated variable.

  • CVE-2009-3579Oct 7, 2009
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in the CookieDump.java sample application in Mort Bay Jetty 6.1.19 and 6.1.20 allows remote attackers to inject arbitrary web script or HTML via the Value parameter in a GET request to cookie/.

  • CVE-2009-1524May 5, 2009
    risk 0.00cvss epss 0.03

    Cross-site scripting (XSS) vulnerability in Mort Bay Jetty before 6.1.17 allows remote attackers to inject arbitrary web script or HTML via a directory listing request containing a ; (semicolon) character.

  • CVE-2007-6672Jan 8, 2008
    risk 0.00cvss epss 0.04

    Mortbay Jetty 6.1.5 and 6.1.6 allows remote attackers to bypass protection mechanisms and read the source of files via multiple '/' (slash) characters in the URI.

  • CVE-2007-5615Dec 5, 2007
    risk 0.00cvss epss 0.04

    CRLF injection vulnerability in Mortbay Jetty before 6.1.6rc0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

  • CVE-2007-5614Dec 5, 2007
    risk 0.00cvss epss 0.04

    Mortbay Jetty before 6.1.6rc1 does not properly handle "certain quote sequences" in HTML cookie parameters, which allows remote attackers to hijack browser sessions via unspecified vectors.

  • CVE-2007-5613Dec 5, 2007
    risk 0.00cvss epss 0.03

    Cross-site scripting (XSS) vulnerability in Dump Servlet in Mortbay Jetty before 6.1.6rc1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters and cookies.

  • CVE-2006-6969Feb 7, 2007
    risk 0.00cvss epss 0.02

    Jetty before 4.2.27, 5.1 before 5.1.12, 6.0 before 6.0.2, and 6.1 before 6.1.0pre3 generates predictable session identifiers using java.util.random, which makes it easier for remote attackers to guess a session identifier through brute force attacks, bypass authentication…

  • CVE-2006-2759Jun 2, 2006
    risk 0.00cvss epss 0.01

    jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary script source code via a capital P in the .jsp extension, and probably other mixed case manipulations.

  • CVE-2004-2381Dec 31, 2004
    risk 0.00cvss epss 0.02

    HttpRequest.java in Jetty HTTP Server before 4.2.19 allows remote attackers to cause denial of service (memory usage and application crash) via HTTP requests with a large Content-Length.

  • CVE-2004-2478Dec 31, 2004
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in Jetty HTTP Server, as used in (1) IBM Trading Partner Interchange before 4.2.4, (2) CA Unicenter Web Services Distributed Management (WSDM) before 3.11, and possibly other products, allows remote attackers to read arbitrary files via a .. (dot dot)…

Page 7 of 7