Vulnerability index

Browse CVEs

246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Omr HIGH 7.8
CVE-2019-11773

Prior to 0.1, AIX builds of Eclipse OMR contain unused RPATHs which may facilitate code injection and privilege elevation by local users.

Fix: 0.1+
Fix from $1,950 2019-09-12
Omr HIGH 7.4
CVE-2019-11774

Prior to 0.1, all builds of Eclipse OMR contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by versio…

Fix: 0.1+
Fix from $1,950 2019-09-12
Paho Java Client HIGH 7.5
CVE-2019-11777

In the Eclipse Paho Java client library version 1.2.0, when connecting to an MQTT server using TLS and setting a host name verifier, the result of th…

Mitigation only
Fix from $1,950 2019-09-11
Business Intelligence And Reporting Tools MEDIUM 6.1
CVE-2019-11776

In Eclipse BIRT versions 1.0 to 4.7, the Report Viewer allows Reflected XSS in URL parameter. Attacker can execute the payload in victim's browser co…

Fix: after 4.7.0
Fix from $1,600 2019-08-09
Openj9 CRITICAL 9.8
CVE-2019-11772

In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that …

Fix: 0.15.0+
Fix from $2,300 2019-07-17
Openj9 HIGH 7.8
CVE-2019-11771

AIX builds of Eclipse OpenJ9 before 0.15.0 contain unused RPATHs which may facilitate code injection and privilege elevation by local users.

Fix: 0.15.0+
Fix from $1,950 2019-07-17
Buildship HIGH 8.1
CVE-2019-11770

In Eclipse Buildship versions prior to 3.1.1, the build files indicate that this project is resolving dependencies over HTTP instead of HTTPS. Any of…

Fix: 3.1.1+
Fix from $1,950 2019-06-14
Xtend HIGH 8.1
CVE-2019-10249

All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artifacts may have been compromise…

Fix: 2.18.0+
Fix from $1,950 2019-05-06
Vorto HIGH 8.1
CVE-2019-10248

Eclipse Vorto versions prior to 0.11 resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS. Any of these dependent artifact…

Fix: 0.11+
Fix from $1,950 2019-04-22
Jetty MEDIUM 5.3
CVE-2019-10246

In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource dir…

Fix: after 3.1.3
Fix from $1,600 2019-04-22
Kura HIGH 7.5
CVE-2019-10244

In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service …

Fix: after 4.0.0
Fix from $1,950 2019-04-09
Kura MEDIUM 5.3
CVE-2019-10242

In Eclipse Kura versions up to 4.0.0, the SkinServlet did not checked the path passed during servlet call, potentially allowing path traversal in get…

Fix: after 4.0.0
Fix from $1,600 2019-04-09
Kura MEDIUM 5.3
CVE-2019-10243

In Eclipse Kura versions up to 4.0.0, Kura exposes the underlying Ui Web server version in its replies. This can be used as a hint by an attacker to …

Fix: after 4.0.0
Fix from $1,600 2019-04-09
Hawkbit HIGH 8.1
CVE-2019-10240

Eclipse hawkBit versions prior to 0.3.0M2 resolved Maven build artifacts for the Vaadin based UI over HTTP instead of HTTPS. Any of these dependent a…

Fix: after 0.2.5
Fix from $1,950 2019-04-03
Mosquitto HIGH 8.1
CVE-2018-12550

When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use an ACL file, and that ACL file is empty, or contains only comments or bl…

Fix: after 1.5.5
Fix from $1,950 2019-03-27
Mosquitto HIGH 8.1
CVE-2018-12551

When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use a password file for authentication, any malformed data in the password f…

Fix: after 1.5.5
Fix from $1,950 2019-03-27
Mosquitto MEDIUM 6.5
CVE-2018-12546

In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a retained message to a topic, then has its access to that topic revoke…

Fix: after 1.5.5
Fix from $1,600 2019-03-27
Wakaama HIGH 7.5
CVE-2019-9004

In Eclipse Wakaama (formerly liblwm2m) 1.0, core/er-coap-13/er-coap-13.c in lwm2mserver in the LWM2M server mishandles invalid options, leading to a …

Patch available
Fix from $1,950 2019-02-22
Openj9 CRITICAL 9.8
CVE-2018-12548

In OpenJDK + Eclipse OpenJ9 version 0.11.0 builds, the public jdk.crypto.jniprovider.NativeCrypto class contains public static natives which accept p…

Mitigation only
Fix from $2,300 2019-01-31
Rdf4j HIGH 7.5
CVE-2018-20227

RDF4J 2.4.2 allows Directory Traversal via ../ in an entry in a ZIP archive.

Fix: 2.5.0+
Fix from $1,950 2018-12-19
Mosquitto HIGH 7.5
CVE-2018-20145

Eclipse Mosquitto 1.5.x before 1.5.5 allows ACL bypass: if the option per_listener_settings was set to true, and the default listener was in use, and…

Fix: 1.5.5+
Fix from $1,950 2018-12-13
Mosquitto HIGH 7.5
CVE-2018-12543EPSS 36%

In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is not $SYS, …

Fix: after 1.5.2
Fix from $1,950 2018-11-15
Vert.x CRITICAL 9.8
CVE-2018-12542

In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that should be within a restricted di…

Fix: after 3.5.3
Fix from $2,300 2018-10-10
Vert.x CRITICAL 9.8
CVE-2018-12544

In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense against X…

Patch available
Fix from $2,300 2018-10-10
Vert.x MEDIUM 6.5
CVE-2018-12541

In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the WebSocket HTTP upgrade implementation buffers the full http request before doing the handshake,…

Fix: 3.5.4+
Fix from $1,600 2018-10-10
Rdf4j CRITICAL 10.0
CVE-2018-1000644

Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External Entity (XXE) vulnerability in RDF4j XML parser parsing RDF files that can result in…

Fix: 2.4.0+
Fix from $2,300 2018-08-20
Openj9 HIGH 7.8
CVE-2018-12539

In Eclipse OpenJ9 version 0.8, users other than the process owner may be able to use Java Attach API to connect to an Eclipse OpenJ9 or IBM JVM on th…

Patch available
Fix from $1,950 2018-08-14
Vert.x MEDIUM 5.3
CVE-2018-12537

In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed ch…

Fix: after 3.5.1
Fix from $1,600 2018-08-14
Mojarra HIGH 7.5
CVE-2018-14371

The getLocalePrefix function in ResourceManager.java in Eclipse Mojarra before 2.3.7 is affected by Directory Traversal via the loc parameter. A remo…

Fix: 2.3.7+
Fix from $1,950 2018-07-18
Vert.x HIGH 8.8
CVE-2018-12540

In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returned XSRF header/form parameter.…

Fix: after 3.5.2
Fix from $1,950 2018-07-12