Vulnerability index

Browse CVEs

246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2025-2259 In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause an integer underflow and a subsequent den… Threadx Netx Duo 6.4.3+ Fix from $1,9502025-04-06 HIGH 7.5 CVE-2025-2260 In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause a denial of service by specially crafted … Threadx Netx Duo 6.4.3+ Fix from $1,9502025-04-06 HIGH 7.5 CVE-2025-2258 In NetX Duo component HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause an integer underflow and a … Threadx Netx Duo 6.4.3+ Fix from $1,9502025-04-06 CRITICAL 9.1 CVE-2024-10838 An integer underflow during deserialization may allow any unauthenticated user to read out of bounds heap memory. This may result into secret data or… Cyclone Data Distribution Service 0.10.5+ Fix from $2,3002025-03-12 HIGH 7.8 CVE-2025-1471 In Eclipse OMR versions 0.2.0 to 0.4.0, some of the z/OS atoe print functions use a constant length buffer for string conversion. If the input format… Omr after 0.4.0 Fix from $1,9502025-02-21 MEDIUM 5.5 CVE-2025-1470 In Eclipse OMR, from the initial contribution to version 0.4.0, some OMR internal port library and utilities consumers of z/OS atoe functions do not … Omr after 0.4.0 Fix from $1,6002025-02-21 HIGH 7.5 CVE-2025-0728 In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause an integer underflow and a subsequent den… Threadx Netx Duo 6.4.2+ Fix from $1,9502025-02-21 HIGH 7.5 CVE-2025-0727 In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause an integer underflow and a subsequent den… Threadx Netx Duo 6.4.2+ Fix from $1,9502025-02-21 HIGH 7.5 CVE-2025-0726 In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause a denial of service by specially crafted … Threadx Netx Duo 6.4.2+ Fix from $1,9502025-02-21 MEDIUM 5.3 CVE-2025-1007 In OpenVSX version v0.9.0 to v0.20.0, the /user/namespace/{namespace}/details API allows a user to edit all namespace details, even if the user is … Open Vsx 0.19.1+ Fix from $1,6002025-02-19 MEDIUM 5.3 CVE-2024-10917 In Eclipse OpenJ9 versions up to 0.47, the JNI function GetStringUTFLength may return an incorrect value which has wrapped around. From 0.48 the valu… Openj9 0.48.0+ Fix from $1,6002024-11-11 MEDIUM 6.5 CVE-2024-3935 In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing bridge connection, and that bridge… Mosquitto 2.0.19+ Fix from $1,6002024-10-30 CRITICAL 9.8 CVE-2024-10525EPSS 59% In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using lib… Mosquitto 2.0.19+ Fix from $2,3002024-10-30 MEDIUM 6.5 CVE-2024-8184 There exists a security vulnerability in Jetty's ThreadLimitHandler.getRemote() which can be exploited by unauthorized users to cause remote denial-o… Jetty 9.4.56 / 10.0.24+ Fix from $1,6002024-10-14 MEDIUM 5.3 CVE-2024-6763 Eclipse Jetty is a lightweight, highly scalable, Java-based web server and Servlet engine . It includes a utility class, HttpURI, for URI/URL parsing… Jetty 9.4.57+ Fix from $1,6002024-10-14 MEDIUM 6.5 CVE-2024-6762 Jetty PushSessionCacheFilter can be exploited by unauthenticated users to launch remote DoS attacks by exhausting the server’s memory. Jetty 10.0.18 / 11.0.18+ Fix from $1,6002024-10-14 HIGH 7.5 CVE-2024-8376 In Eclipse Mosquitto up to version 2.0.18a, an attacker can achieve memory leaking, segmentation fault or heap-use-after-free by sending specific seq… Mosquitto 2.0.19+ Fix from $1,9502024-10-11 MEDIUM 6.1 CVE-2024-9329 In Eclipse Glassfish versions before 7.0.17, The Host HTTP parameter could cause the web application to redirect to the specified URL, when the reque… Glassfish 7.0.17+ Fix from $1,6002024-09-30 MEDIUM 5.3 CVE-2024-9202 In Eclipse Dataspace Components versions 0.1.3 to 0.9.0, the Connector component filters which datasets (= data offers) another party can see in a re… Eclipse Dataspace Components 0.9.1+ Fix from $1,6002024-09-27 HIGH 8.1 CVE-2024-8642 In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for… Eclipse Dataspace Components 0.9.0+ Fix from $1,9502024-09-11 MEDIUM 6.1 CVE-2024-8646 In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed. This vulnerability is caused by the vulner… Glassfish 7.0.10+ Fix from $1,6002024-09-11 HIGH 7.5 CVE-2024-8391 In Eclipse Vert.x version 4.3.0 to 4.5.9, the gRPC server does not limit the maximum length of message payload (Maven GAV: io.vertx:vertx-grpc-server… Vert.x 4.5.10+ Fix from $1,9502024-09-04 HIGH 7.5 CVE-2023-7272 In Eclipse Parsson before 1.0.4 and 1.1.3, a document with a large depth of nested objects can allow an attacker to cause a Java stack overflow excep… Parsson 1.0.4 / 1.1.3+ Fix from $1,9502024-07-17 HIGH 7.3 CVE-2024-3933 In Eclipse OpenJ9 release versions prior to 0.44.0 and after 0.13.0, when running with JVM option -Xgc:concurrentScavenge, the sequence generated for… Openj9 0.44.0+ Fix from $1,9502024-05-27 MEDIUM 5.4 CVE-2024-5165 In Eclipse Ditto versions 3.0.0 to 3.5.5, the user input of several input fields of the Eclipse Ditto Explorer User Interface https://eclipse.dev/di… Ditto 3.5.6+ Fix from $1,6002024-05-23 MEDIUM 5.3 CVE-2024-4536 In Eclipse Dataspace Components from version 0.2.1 to 0.6.2, in the EDC Connector component ( https://github.com/eclipse-edc/Connector ), an attacker… Edc Connector 0.6.3+ Fix from $1,6002024-05-07 CRITICAL 9.8 CVE-2024-0740 Eclipse Target Management: Terminal and Remote System Explorer (RSE) version <= 4.5.400 has a remote code execution vulnerability that does not requi… Target Management after 4.5.400 Fix from $2,3002024-04-26 HIGH 7.5 CVE-2024-3046 In Eclipse Kura LogServlet component included in versions 5.0.0 to 5.4.1, a specifically crafted request to the servlet can allow an unauthenticated … Kura after 5.4.1 Fix from $1,9502024-04-09 CRITICAL 9.8 CVE-2024-2452 In Eclipse ThreadX NetX Duo before 6.4.0, if an attacker can control parameters of __portable_aligned_alloc() could cause an integer wrap-around an… Threadx Netx Duo 6.4.0+ Fix from $2,3002024-03-26 HIGH 7.8 CVE-2024-2212 In Eclipse ThreadX before 6.4.0, xQueueCreate() and xQueueCreateSet() functions from the FreeRTOS compatibility API (utility/rtos_compatibility_la… Threadx 6.4.0+ Fix from $1,9502024-03-26