Vulnerability index

Browse CVEs

246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Tinydtls HIGH 7.5
CVE-2021-34430

Eclipse TinyDTLS through 0.9-rc1 relies on the rand function in the C library, which makes it easier for remote attackers to compute the master key a…

Fix: after 0.8.2
Fix from $1,950 2021-07-08
Business Intelligence And Reporting Tools CRITICAL 9.8
CVE-2021-34427EPSS 58%

In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT v…

Fix: after 4.8.0
Fix from $2,300 2021-06-25
Mojarra MEDIUM 6.5
CVE-2020-6950EPSS 10%

Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter.

Fix: 2.3.14 / 11.2.8.0+
Fix from $1,600 2021-06-02
Jakarta Expression Language MEDIUM 5.3
CVE-2021-28170

In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated…

Fix: 2.3.0+
Fix from $1,600 2021-05-26
Jersey MEDIUM 5.5
CVE-2021-28168

Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the Fi…

Fix: 2.34 / 3.0.2+
Fix from $1,600 2021-04-22
Openj9 MEDIUM 6.5
CVE-2021-28167

In Eclipse Openj9 to version 0.25.0, usage of the jdk.internal.reflect.ConstantPool API causes the JVM in some cases to pre-resolve certain constant …

Fix: after 0.25.0
Fix from $1,600 2021-04-21
Mosquitto MEDIUM 6.5
CVE-2021-28166

In Eclipse Mosquitto version 2.0.0 to 2.0.9, if an authenticated client that had connected with MQTT v5 sent a crafted CONNACK message to the broker,…

Fix: after 2.0.9
Fix from $1,600 2021-04-07
Jetty MEDIUM 5.3
CVE-2021-28164EPSS 82%

In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to a…

Fix: after 11.70.1
Fix from $1,600 2021-04-01
Theia MEDIUM 6.1
CVE-2021-28161

In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javascript code can be injected.

Fix: after 1.8.0
Fix from $1,600 2021-03-12
Theia MEDIUM 6.1
CVE-2021-28162

In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run.

Fix: after 0.16.0
Fix from $1,600 2021-03-12
Platform HIGH 7.8
CVE-2020-27225

In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to the local help web server, all…

Fix: after 4.18
Fix from $1,950 2021-03-09
Theia CRITICAL 9.6
CVE-2020-27224

In Eclipse Theia versions up to and including 1.2.0, the Markdown Preview (@theia/preview), can be exploited to execute arbitrary code.

Fix: after 1.2.0
Fix from $2,300 2021-02-24
Californium HIGH 7.5
CVE-2020-27222

In Eclipse Californium version 2.3.0 to 2.6.0, the certificate based (x509 and RPK) DTLS handshakes accidentally fails, because the DTLS server side …

Fix: after 2.6.0
Fix from $1,950 2021-02-03
Openj9 CRITICAL 9.8
CVE-2020-27221

In Eclipse OpenJ9 up to and including version 0.23, there is potential for a stack-based buffer overflow when the virtual machine or JNI natives are …

Fix: after 0.23.0
Fix from $2,300 2021-01-21
Vert.x Web HIGH 8.8
CVE-2020-35217

Vert.x-Web framework v4.0 milestone 1-4 does not perform a correct CSRF verification. Instead of comparing the CSRF token in the request with the CSR…

Patch available
Fix from $1,950 2021-01-20
Hono HIGH 8.8
CVE-2020-27220

The Eclipse Hono AMQP and MQTT protocol adapters do not check whether an authenticated gateway device is authorized to receive command & control mess…

Fix: after 1.4.4
Fix from $1,950 2021-01-14
Hawkbit MEDIUM 6.1
CVE-2020-27219

In all version of Eclipse Hawkbit prior to 0.3.0M7, the HTTP 404 (Not Found) JSON response body returned by the REST API may contain unsafe character…

Fix: after 0.2.5
Fix from $1,600 2021-01-14
Che HIGH 7.1
CVE-2020-14368

A flaw was found in Eclipse Che in versions prior to 7.14.0 that impacts CodeReady Workspaces. When configured with cookies authentication, Theia IDE…

Fix: 7.14.0+
Fix from $1,950 2020-12-14
Hono HIGH 7.5
CVE-2020-27217

In Eclipse Hono version 1.3.0 and 1.4.0 the AMQP protocol adapter does not verify the size of AMQP messages received from devices. In particular, a d…

Mitigation only
Fix from $1,950 2020-11-13
Vert.x CRITICAL 9.8
CVE-2019-17640

In Eclipse Vert.x 3.4.x up to 3.9.4, 4.0.0.milestone1, 4.0.0.milestone2, 4.0.0.milestone3, 4.0.0.milestone4, 4.0.0.milestone5, 4.0.0.Beta1, 4.0.0.Bet…

Fix: after 3.9.4
Fix from $2,300 2020-10-15
Openj9 MEDIUM 5.3
CVE-2019-17639

In Eclipse OpenJ9 prior to version 0.21 on Power platforms, calling the System.arraycopy method with a length longer than the length of the source or…

Fix: after 0.20.0
Fix from $1,600 2020-07-15
Jetty CRITICAL 9.4
CVE-2019-17638EPSS 11%

In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce an HTTP …

Mitigation only
Fix from $2,300 2020-07-09
Che MEDIUM 6.8
CVE-2020-10689

A flaw was found in the Eclipse Che up to version 7.8.x, where it did not properly restrict access to workspace pods. An authenticated user can explo…

Fix: 7.9.0+
Fix from $1,600 2020-04-03
Theia HIGH 8.1
CVE-2019-17636

In Eclipse Theia versions 0.3.9 through 0.15.0, one of the default pre-packaged Theia extensions is "Mini-Browser", published as "@theia/mini-browser…

Fix: after 0.15.0
Fix from $1,950 2020-03-10
Memory Analyzer HIGH 7.8
CVE-2019-17635

Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a deserialization vulnerability if an index file of a parsed heap dump is replaced by…

Fix: after 1.9.1
Fix from $1,950 2020-01-17
Memory Analyzer CRITICAL 9.0
CVE-2019-17634

Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a cross site scripting (XSS) vulnerability when generating an HTML report from a mali…

Fix: after 1.9.1
Fix from $2,300 2020-01-17
Che HIGH 8.8
CVE-2019-17633

For Eclipse Che versions 6.16 to 7.3.0, with both authentication and TLS disabled, visiting a malicious web site could trigger the start of an arbitr…

Fix: after 7.3.0
Fix from $1,950 2019-12-19
Jetty MEDIUM 6.1
CVE-2019-17632

In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in te…

Mitigation only
Fix from $1,600 2019-11-25
Mojarra MEDIUM 6.1
CVE-2019-17091

faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2…

Fix: 2.2.20 / 2.3.10+
Fix from $1,600 2019-10-02
Mosquitto MEDIUM 5.4
CVE-2019-11778

If an MQTT v5 client connects to Eclipse Mosquitto versions 1.6.0 to 1.6.4 inclusive, sets a last will and testament, sets a will delay interval, set…

Fix: 1.6.5+
Fix from $1,600 2019-09-18