Vulnerability index

Browse CVEs

246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Threadx Netx Duo HIGH 7.5
CVE-2025-2259

In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause an integer underflow and a subsequent den…

Fix: 6.4.3+
Fix from $1,950 2025-04-06
Threadx Netx Duo HIGH 7.5
CVE-2025-2260

In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause a denial of service by specially crafted …

Fix: 6.4.3+
Fix from $1,950 2025-04-06
Threadx Netx Duo HIGH 7.5
CVE-2025-2258

In NetX Duo component HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause an integer underflow and a …

Fix: 6.4.3+
Fix from $1,950 2025-04-06
Cyclone Data Distribution Service CRITICAL 9.1
CVE-2024-10838

An integer underflow during deserialization may allow any unauthenticated user to read out of bounds heap memory. This may result into secret data or…

Fix: 0.10.5+
Fix from $2,300 2025-03-12
Omr HIGH 7.8
CVE-2025-1471

In Eclipse OMR versions 0.2.0 to 0.4.0, some of the z/OS atoe print functions use a constant length buffer for string conversion. If the input format…

Fix: after 0.4.0
Fix from $1,950 2025-02-21
Omr MEDIUM 5.5
CVE-2025-1470

In Eclipse OMR, from the initial contribution to version 0.4.0, some OMR internal port library and utilities consumers of z/OS atoe functions do not …

Fix: after 0.4.0
Fix from $1,600 2025-02-21
Threadx Netx Duo HIGH 7.5
CVE-2025-0728

In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause an integer underflow and a subsequent den…

Fix: 6.4.2+
Fix from $1,950 2025-02-21
Threadx Netx Duo HIGH 7.5
CVE-2025-0727

In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause an integer underflow and a subsequent den…

Fix: 6.4.2+
Fix from $1,950 2025-02-21
Threadx Netx Duo HIGH 7.5
CVE-2025-0726

In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause a denial of service by specially crafted …

Fix: 6.4.2+
Fix from $1,950 2025-02-21
Open Vsx MEDIUM 5.3
CVE-2025-1007

In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the user is …

Fix: 0.19.1+
Fix from $1,600 2025-02-19
Openj9 MEDIUM 5.3
CVE-2024-10917

In Eclipse OpenJ9 versions up to 0.47, the JNI function GetStringUTFLength may return an incorrect value which has wrapped around. From 0.48 the valu…

Fix: 0.48.0+
Fix from $1,600 2024-11-11
Mosquitto MEDIUM 6.5
CVE-2024-3935

In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing bridge connection, and that bridge…

Fix: 2.0.19+
Fix from $1,600 2024-10-30
Mosquitto CRITICAL 9.8
CVE-2024-10525EPSS 59%

In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using lib…

Fix: 2.0.19+
Fix from $2,300 2024-10-30
Jetty MEDIUM 6.5
CVE-2024-8184

There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized users to cause remote denial-o…

Fix: 9.4.56 / 10.0.24+
Fix from $1,600 2024-10-14
Jetty MEDIUM 5.3
CVE-2024-6763

Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing…

Fix: 9.4.57+
Fix from $1,600 2024-10-14
Jetty MEDIUM 6.5
CVE-2024-6762

Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the server’s memory.

Fix: 10.0.18 / 11.0.18+
Fix from $1,600 2024-10-14
Mosquitto HIGH 7.5
CVE-2024-8376

In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific seq…

Fix: 2.0.19+
Fix from $1,950 2024-10-11
Glassfish MEDIUM 6.1
CVE-2024-9329

In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the reque…

Fix: 7.0.17+
Fix from $1,600 2024-09-30
Eclipse Dataspace Components MEDIUM 5.3
CVE-2024-9202

In Eclipse Dataspace Components versions 0.1.3 to 0.9.0, the Connector component filters which datasets (= data offers) another party can see in a re…

Fix: 0.9.1+
Fix from $1,600 2024-09-27
Eclipse Dataspace Components HIGH 8.1
CVE-2024-8642

In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for…

Fix: 0.9.0+
Fix from $1,950 2024-09-11
Glassfish MEDIUM 6.1
CVE-2024-8646

In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed. This vulnerability is caused by the vulner…

Fix: 7.0.10+
Fix from $1,600 2024-09-11
Vert.x HIGH 7.5
CVE-2024-8391

In Eclipse Vert.x version 4.3.0 to 4.5.9, the gRPC server does not limit the maximum length of message payload (Maven GAV: io.vertx:vertx-grpc-server…

Fix: 4.5.10+
Fix from $1,950 2024-09-04
Parsson HIGH 7.5
CVE-2023-7272

In Eclipse Parsson before 1.0.4 and 1.1.3, a document with a large depth of nested objects can allow an attacker to cause a Java stack overflow excep…

Fix: 1.0.4 / 1.1.3+
Fix from $1,950 2024-07-17
Openj9 HIGH 7.3
CVE-2024-3933

In Eclipse OpenJ9 release versions prior to 0.44.0 and after 0.13.0, when running with JVM option -Xgc:concurrentScavenge, the sequence generated for…

Fix: 0.44.0+
Fix from $1,950 2024-05-27
Ditto MEDIUM 5.4
CVE-2024-5165

In Eclipse Ditto versions 3.0.0 to 3.5.5, the user input of several input fields of the Eclipse Ditto Explorer User Interface https://eclipse.dev/di…

Fix: 3.5.6+
Fix from $1,600 2024-05-23
Edc Connector MEDIUM 5.3
CVE-2024-4536

In Eclipse Dataspace Components from version 0.2.1 to 0.6.2, in the EDC Connector component ( https://github.com/eclipse-edc/Connector ), an attacker…

Fix: 0.6.3+
Fix from $1,600 2024-05-07
Target Management CRITICAL 9.8
CVE-2024-0740

Eclipse Target Management: Terminal and Remote System Explorer (RSE) version <= 4.5.400 has a remote code execution vulnerability that does not requi…

Fix: after 4.5.400
Fix from $2,300 2024-04-26
Kura HIGH 7.5
CVE-2024-3046

In Eclipse Kura LogServlet component included in versions 5.0.0 to 5.4.1, a specifically crafted request to the servlet can allow an unauthenticated …

Fix: after 5.4.1
Fix from $1,950 2024-04-09
Threadx Netx Duo CRITICAL 9.8
CVE-2024-2452

In Eclipse ThreadX NetX Duo before 6.4.0, if an attacker can control parameters of __portable_aligned_alloc() could cause an integer wrap-around an…

Fix: 6.4.0+
Fix from $2,300 2024-03-26
Threadx HIGH 7.8
CVE-2024-2212

In Eclipse ThreadX before 6.4.0, xQueueCreate() and xQueueCreateSet() functions from the FreeRTOS compatibility API (utility/rtos_compatibility_la…

Fix: 6.4.0+
Fix from $1,950 2024-03-26