Vulnerability index

Browse CVEs

246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2022-2838 In Eclipse Sphinx™ before version 0.13.1, Apache Xerces XML Parser was used without disabling processing of referenced external entities allowing the… Sphinx 0.13.1+ Fix from $1,6002022-08-16 HIGH 7.5 CVE-2022-2576 In Eclipse Californium version 2.0.0 to 2.7.2 and 3.0.0-3.5.0 a DTLS resumption handshake falls back to a DTLS full handshake on a parameter mismatch… Californium after 3.5.0 Fix from $1,9502022-07-29 CRITICAL 9.8 CVE-2015-8031 Hudson (aka org.jvnet.hudson.main:hudson-core) before 3.3.2 allows XXE attacks. Hudson 3.2.2+ Fix from $2,3002022-07-18 HIGH 8.0 CVE-2021-41037 In Eclipse p2, installable units are able to alter the Eclipse Platform installation and the local machine via touchpoints during installation. Those… Equinox P2 Mitigation only Fix from $1,9502022-07-08 HIGH 7.5 CVE-2022-2191 In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffers from configured ByteBufferP… Jetty after 11.0.9 Fix from $1,9502022-07-07 MEDIUM 5.3 CVE-2021-41042 In Eclipse Lyo versions 1.0.0 to 4.1.0, a TransformerFactory is initialized with the defaults that do not restrict DTD loading when working with RDF/… Lyo after 4.1.0 Fix from $1,6002022-07-07 CRITICAL 9.8 CVE-2022-29246 Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack. Prior to version 6.1.11, he USBX DFU UPLOAD functionality may be utilized … Threadx Usbx 6.1.11+ Fix from $2,3002022-05-24 CRITICAL 9.8 CVE-2022-29223 Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack. In versions prior to 6.1.10, an attacker can cause a buffer overflow by pr… Threadx Usbx 6.1.10+ Fix from $2,3002022-05-24 CRITICAL 9.8 CVE-2021-38441 Eclipse CycloneDDS versions prior to 0.8.0 are vulnerable to a write-what-where condition, which may allow an attacker to write arbitrary values in t… Cyclonedds 0.8.0+ Fix from $2,3002022-05-05 CRITICAL 9.8 CVE-2021-38443 Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write arbitrary values in the XML par… Cyclonedds 0.8.0+ Fix from $2,3002022-05-05 MEDIUM 5.3 CVE-2021-41041 In Eclipse Openj9 before version 0.32.0, Java 8 & 11 fail to throw the exception captured during bytecode verification when verification is triggered… Openj9 0.32.0+ Fix from $1,6002022-04-27 MEDIUM 6.5 CVE-2022-0673 A flaw was found in LemMinX in versions prior to 0.19.0. Cache poisoning of external schema files due to directory traversal. Lemminx 0.19.0+ Fix from $1,6002022-02-18 MEDIUM 5.5 CVE-2022-0672 A flaw was found in LemMinX in versions prior to 0.19.0. Insecure redirect could allow unauthorized access to sensitive information locally if LemMin… Lemminx 0.19.0+ Fix from $1,6002022-02-18 HIGH 7.5 CVE-2021-41040 In Eclipse Wakaama, ever since its inception until 2021-01-14, the CoAP parsing code does not properly sanitize network-received data. Wakaama Patch available Fix from $1,9502022-02-01 HIGH 7.5 CVE-2021-41039 In versions 1.6 to 2.0.11 of Eclipse Mosquitto, an MQTT v5 client connecting with a large number of user-property properties could cause excessive CP… Mosquitto after 2.0.11 Fix from $1,9502021-12-01 MEDIUM 6.1 CVE-2021-41038 In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage(). Theia 1.18.0+ Fix from $1,6002021-11-10 CRITICAL 9.8 CVE-2021-41036 In versions prior to 1.1 of the Eclipse Paho MQTT C Client, the client does not check rem_len size in readpacket. Paho Mqtt C\/c\+\+ Client 1.1.0+ Fix from $2,3002021-11-03 CRITICAL 9.8 CVE-2021-41035 In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods. Openj9 0.29.0+ Fix from $2,3002021-10-25 HIGH 8.1 CVE-2021-41034 The build of some language stacks of Eclipse Che version 6 includes pulling some binaries from an unsecured HTTP endpoint. As a consequence the build… Che 7.0.0+ Fix from $1,9502021-09-29 HIGH 8.1 CVE-2021-41033 In all released versions of Eclipse Equinox, at least until version 4.21 (September 2021), installation can be vulnerable to man-in-the-middle attack… Equinox 4.21+ Fix from $1,9502021-09-13 CRITICAL 9.9 CVE-2021-32835 Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a sandbox escape vulnerabili… Keti No fix yet Fix from $2,3002021-09-09 CRITICAL 9.9 CVE-2021-32834 Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a user able to create Policy… Keti No fix yet Fix from $2,3002021-09-09 CRITICAL 9.8 CVE-2021-34436 In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. T… Theia after 0.2.0 Fix from $2,3002021-09-02 HIGH 8.8 CVE-2021-34435 In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE. But with the way it is… Theia after 1.8.1 Fix from $1,9502021-09-01 HIGH 7.5 CVE-2020-18734 A stack buffer overflow in /ddsi/q_bitset.h of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash. Cyclone Data Distribution Service No fix yet Fix from $1,9502021-08-23 HIGH 7.5 CVE-2020-18735 A heap buffer overflow in /src/dds_stream.c of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash. Cyclone Data Distribution Service No fix yet Fix from $1,9502021-08-23 HIGH 7.5 CVE-2021-34433 In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally succeeds wi… Californium 2.6.5+ Fix from $1,9502021-08-20 HIGH 7.5 CVE-2021-34432 In Eclipse Mosquitto versions 2.0.7 and earlier, the server will crash if the client tries to send a PUBLISH packet with topic length = 0. Mosquitto after 2.0.7 Fix from $1,9502021-07-27 MEDIUM 6.5 CVE-2021-34431 In Eclipse Mosquitto version 1.6 to 2.0.10, if an authenticated client that had connected with MQTT v5 sent a crafted CONNECT message to the broker a… Mosquitto after 2.0.10 Fix from $1,6002021-07-22 MEDIUM 5.3 CVE-2021-34429EPSS 99% For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of t… Jetty 9.4.43 / 10.0.6+ Fix from $1,6002021-07-15