Vulnerability index

Browse CVEs

246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2021-34430 Eclipse TinyDTLS through 0.9-rc1 relies on the rand function in the C library, which makes it easier for remote attackers to compute the master key a… Tinydtls after 0.8.2 Fix from $1,9502021-07-08 CRITICAL 9.8 CVE-2021-34427EPSS 58% In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT v… Business Intelligence And Reporting Tools after 4.8.0 Fix from $2,3002021-06-25 MEDIUM 6.5 CVE-2020-6950EPSS 10% Directory traversal in Eclipse Mojarra before 2.3.14 allows attackers to read arbitrary files via the loc parameter or con parameter. Mojarra 2.3.14 / 11.2.8.0+ Fix from $1,6002021-06-02 MEDIUM 5.3 CVE-2021-28170 In the Jakarta Expression Language implementation 3.0.3 and earlier, a bug in the ELParserTokenManager enables invalid EL expressions to be evaluated… Jakarta Expression Language 2.3.0+ Fix from $1,6002021-05-26 MEDIUM 5.5 CVE-2021-28168 Eclipse Jersey 2.28 to 2.33 and Eclipse Jersey 3.0.0 to 3.0.1 contains a local information disclosure vulnerability. This is due to the use of the Fi… Jersey 2.34 / 3.0.2+ Fix from $1,6002021-04-22 MEDIUM 6.5 CVE-2021-28167 In Eclipse Openj9 to version 0.25.0, usage of the jdk.internal.reflect.ConstantPool API causes the JVM in some cases to pre-resolve certain constant … Openj9 after 0.25.0 Fix from $1,6002021-04-21 MEDIUM 6.5 CVE-2021-28166 In Eclipse Mosquitto version 2.0.0 to 2.0.9, if an authenticated client that had connected with MQTT v5 sent a crafted CONNACK message to the broker,… Mosquitto after 2.0.9 Fix from $1,6002021-04-07 MEDIUM 5.3 CVE-2021-28164EPSS 82% In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to a… Jetty after 11.70.1 Fix from $1,6002021-04-01 MEDIUM 6.1 CVE-2021-28161 In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javascript code can be injected. Theia after 1.8.0 Fix from $1,6002021-03-12 MEDIUM 6.1 CVE-2021-28162 In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run. Theia after 0.16.0 Fix from $1,6002021-03-12 HIGH 7.8 CVE-2020-27225 In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to the local help web server, all… Platform after 4.18 Fix from $1,9502021-03-09 CRITICAL 9.6 CVE-2020-27224 In Eclipse Theia versions up to and including 1.2.0, the Markdown Preview (@theia/preview), can be exploited to execute arbitrary code. Theia after 1.2.0 Fix from $2,3002021-02-24 HIGH 7.5 CVE-2020-27222 In Eclipse Californium version 2.3.0 to 2.6.0, the certificate based (x509 and RPK) DTLS handshakes accidentally fails, because the DTLS server side … Californium after 2.6.0 Fix from $1,9502021-02-03 CRITICAL 9.8 CVE-2020-27221 In Eclipse OpenJ9 up to and including version 0.23, there is potential for a stack-based buffer overflow when the virtual machine or JNI natives are … Openj9 after 0.23.0 Fix from $2,3002021-01-21 HIGH 8.8 CVE-2020-35217 Vert.x-Web framework v4.0 milestone 1-4 does not perform a correct CSRF verification. Instead of comparing the CSRF token in the request with the CSR… Vert.x Web Patch available Fix from $1,9502021-01-20 HIGH 8.8 CVE-2020-27220 The Eclipse Hono AMQP and MQTT protocol adapters do not check whether an authenticated gateway device is authorized to receive command & control mess… Hono after 1.4.4 Fix from $1,9502021-01-14 MEDIUM 6.1 CVE-2020-27219 In all version of Eclipse Hawkbit prior to 0.3.0M7, the HTTP 404 (Not Found) JSON response body returned by the REST API may contain unsafe character… Hawkbit after 0.2.5 Fix from $1,6002021-01-14 HIGH 7.1 CVE-2020-14368 A flaw was found in Eclipse Che in versions prior to 7.14.0 that impacts CodeReady Workspaces. When configured with cookies authentication, Theia IDE… Che 7.14.0+ Fix from $1,9502020-12-14 HIGH 7.5 CVE-2020-27217 In Eclipse Hono version 1.3.0 and 1.4.0 the AMQP protocol adapter does not verify the size of AMQP messages received from devices. In particular, a d… Hono Mitigation only Fix from $1,9502020-11-13 CRITICAL 9.8 CVE-2019-17640 In Eclipse Vert.x 3.4.x up to 3.9.4, 4.0.0.milestone1, 4.0.0.milestone2, 4.0.0.milestone3, 4.0.0.milestone4, 4.0.0.milestone5, 4.0.0.Beta1, 4.0.0.Bet… Vert.x after 3.9.4 Fix from $2,3002020-10-15 MEDIUM 5.3 CVE-2019-17639 In Eclipse OpenJ9 prior to version 0.21 on Power platforms, calling the System.arraycopy method with a length longer than the length of the source or… Openj9 after 0.20.0 Fix from $1,6002020-07-15 CRITICAL 9.4 CVE-2019-17638EPSS 11% In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce an HTTP … Jetty Mitigation only Fix from $2,3002020-07-09 MEDIUM 6.8 CVE-2020-10689 A flaw was found in the Eclipse Che up to version 7.8.x, where it did not properly restrict access to workspace pods. An authenticated user can explo… Che 7.9.0+ Fix from $1,6002020-04-03 HIGH 8.1 CVE-2019-17636 In Eclipse Theia versions 0.3.9 through 0.15.0, one of the default pre-packaged Theia extensions is "Mini-Browser", published as "@theia/mini-browser… Theia after 0.15.0 Fix from $1,9502020-03-10 HIGH 7.8 CVE-2019-17635 Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a deserialization vulnerability if an index file of a parsed heap dump is replaced by… Memory Analyzer after 1.9.1 Fix from $1,9502020-01-17 CRITICAL 9.0 CVE-2019-17634 Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a cross site scripting (XSS) vulnerability when generating an HTML report from a mali… Memory Analyzer after 1.9.1 Fix from $2,3002020-01-17 HIGH 8.8 CVE-2019-17633 For Eclipse Che versions 6.16 to 7.3.0, with both authentication and TLS disabled, visiting a malicious web site could trigger the start of an arbitr… Che after 7.3.0 Fix from $1,9502019-12-19 MEDIUM 6.1 CVE-2019-17632 In Eclipse Jetty versions 9.4.21.v20190926, 9.4.22.v20191022, and 9.4.23.v20191118, the generation of default unhandled Error response content (in te… Jetty Mitigation only Fix from $1,6002019-11-25 MEDIUM 6.1 CVE-2019-17091 faces/context/PartialViewContextImpl.java in Eclipse Mojarra, as used in Mojarra for Eclipse EE4J before 2.3.10 and Mojarra JavaServer Faces before 2… Mojarra 2.2.20 / 2.3.10+ Fix from $1,6002019-10-02 MEDIUM 5.4 CVE-2019-11778 If an MQTT v5 client connects to Eclipse Mosquitto versions 1.6.0 to 1.6.4 inclusive, sets a last will and testament, sets a will delay interval, set… Mosquitto 1.6.5+ Fix from $1,6002019-09-18