Vulnerability index

Browse CVEs

246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sphinx MEDIUM 5.3
CVE-2022-2838

In Eclipse Sphinx™ before version 0.13.1, Apache Xerces XML Parser was used without disabling processing of referenced external entities allowing the…

Fix: 0.13.1+
Fix from $1,600 2022-08-16
Californium HIGH 7.5
CVE-2022-2576

In Eclipse Californium version 2.0.0 to 2.7.2 and 3.0.0-3.5.0 a DTLS resumption handshake falls back to a DTLS full handshake on a parameter mismatch…

Fix: after 3.5.0
Fix from $1,950 2022-07-29
Hudson CRITICAL 9.8
CVE-2015-8031

Hudson (aka org.jvnet.hudson.main:hudson-core) before 3.3.2 allows XXE attacks.

Fix: 3.2.2+
Fix from $2,300 2022-07-18
Equinox P2 HIGH 8.0
CVE-2021-41037

In Eclipse p2, installable units are able to alter the Eclipse Platform installation and the local machine via touchpoints during installation. Those…

Mitigation only
Fix from $1,950 2022-07-08
Jetty HIGH 7.5
CVE-2022-2191

In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffers from configured ByteBufferP…

Fix: after 11.0.9
Fix from $1,950 2022-07-07
Lyo MEDIUM 5.3
CVE-2021-41042

In Eclipse Lyo versions 1.0.0 to 4.1.0, a TransformerFactory is initialized with the defaults that do not restrict DTD loading when working with RDF/…

Fix: after 4.1.0
Fix from $1,600 2022-07-07
Threadx Usbx CRITICAL 9.8
CVE-2022-29246

Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack. Prior to version 6.1.11, he USBX DFU UPLOAD functionality may be utilized …

Fix: 6.1.11+
Fix from $2,300 2022-05-24
Threadx Usbx CRITICAL 9.8
CVE-2022-29223

Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack. In versions prior to 6.1.10, an attacker can cause a buffer overflow by pr…

Fix: 6.1.10+
Fix from $2,300 2022-05-24
Cyclonedds CRITICAL 9.8
CVE-2021-38441

Eclipse CycloneDDS versions prior to 0.8.0 are vulnerable to a write-what-where condition, which may allow an attacker to write arbitrary values in t…

Fix: 0.8.0+
Fix from $2,300 2022-05-05
Cyclonedds CRITICAL 9.8
CVE-2021-38443

Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write arbitrary values in the XML par…

Fix: 0.8.0+
Fix from $2,300 2022-05-05
Openj9 MEDIUM 5.3
CVE-2021-41041

In Eclipse Openj9 before version 0.32.0, Java 8 & 11 fail to throw the exception captured during bytecode verification when verification is triggered…

Fix: 0.32.0+
Fix from $1,600 2022-04-27
Lemminx MEDIUM 6.5
CVE-2022-0673

A flaw was found in LemMinX in versions prior to 0.19.0. Cache poisoning of external schema files due to directory traversal.

Fix: 0.19.0+
Fix from $1,600 2022-02-18
Lemminx MEDIUM 5.5
CVE-2022-0672

A flaw was found in LemMinX in versions prior to 0.19.0. Insecure redirect could allow unauthorized access to sensitive information locally if LemMin…

Fix: 0.19.0+
Fix from $1,600 2022-02-18
Wakaama HIGH 7.5
CVE-2021-41040

In Eclipse Wakaama, ever since its inception until 2021-01-14, the CoAP parsing code does not properly sanitize network-received data.

Patch available
Fix from $1,950 2022-02-01
Mosquitto HIGH 7.5
CVE-2021-41039

In versions 1.6 to 2.0.11 of Eclipse Mosquitto, an MQTT v5 client connecting with a large number of user-property properties could cause excessive CP…

Fix: after 2.0.11
Fix from $1,950 2021-12-01
Theia MEDIUM 6.1
CVE-2021-41038

In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage().

Fix: 1.18.0+
Fix from $1,600 2021-11-10
Paho Mqtt C\/c\+\+ Client CRITICAL 9.8
CVE-2021-41036

In versions prior to 1.1 of the Eclipse Paho MQTT C Client, the client does not check rem_len size in readpacket.

Fix: 1.1.0+
Fix from $2,300 2021-11-03
Openj9 CRITICAL 9.8
CVE-2021-41035

In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.

Fix: 0.29.0+
Fix from $2,300 2021-10-25
Che HIGH 8.1
CVE-2021-41034

The build of some language stacks of Eclipse Che version 6 includes pulling some binaries from an unsecured HTTP endpoint. As a consequence the build…

Fix: 7.0.0+
Fix from $1,950 2021-09-29
Equinox HIGH 8.1
CVE-2021-41033

In all released versions of Eclipse Equinox, at least until version 4.21 (September 2021), installation can be vulnerable to man-in-the-middle attack…

Fix: 4.21+
Fix from $1,950 2021-09-13
Keti CRITICAL 9.9
CVE-2021-32835

Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a sandbox escape vulnerabili…

No fix yet
Fix from $2,300 2021-09-09
Keti CRITICAL 9.9
CVE-2021-32834

Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a user able to create Policy…

No fix yet
Fix from $2,300 2021-09-09
Theia CRITICAL 9.8
CVE-2021-34436

In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. T…

Fix: after 0.2.0
Fix from $2,300 2021-09-02
Theia HIGH 8.8
CVE-2021-34435

In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE. But with the way it is…

Fix: after 1.8.1
Fix from $1,950 2021-09-01
Cyclone Data Distribution Service HIGH 7.5
CVE-2020-18734

A stack buffer overflow in /ddsi/q_bitset.h of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.

No fix yet
Fix from $1,950 2021-08-23
Cyclone Data Distribution Service HIGH 7.5
CVE-2020-18735

A heap buffer overflow in /src/dds_stream.c of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.

No fix yet
Fix from $1,950 2021-08-23
Californium HIGH 7.5
CVE-2021-34433

In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally succeeds wi…

Fix: 2.6.5+
Fix from $1,950 2021-08-20
Mosquitto HIGH 7.5
CVE-2021-34432

In Eclipse Mosquitto versions 2.0.7 and earlier, the server will crash if the client tries to send a PUBLISH packet with topic length = 0.

Fix: after 2.0.7
Fix from $1,950 2021-07-27
Mosquitto MEDIUM 6.5
CVE-2021-34431

In Eclipse Mosquitto version 1.6 to 2.0.10, if an authenticated client that had connected with MQTT v5 sent a crafted CONNECT message to the broker a…

Fix: after 2.0.10
Fix from $1,600 2021-07-22
Jetty MEDIUM 5.3
CVE-2021-34429EPSS 99%

For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of t…

Fix: 9.4.43 / 10.0.6+
Fix from $1,600 2021-07-15