Vulnerability index

Browse CVEs

246 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2019-11773 Prior to 0.1, AIX builds of Eclipse OMR contain unused RPATHs which may facilitate code injection and privilege elevation by local users. Omr 0.1+ Fix from $1,9502019-09-12 HIGH 7.4 CVE-2019-11774 Prior to 0.1, all builds of Eclipse OMR contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by versio… Omr 0.1+ Fix from $1,9502019-09-12 HIGH 7.5 CVE-2019-11777 In the Eclipse Paho Java client library version 1.2.0, when connecting to an MQTT server using TLS and setting a host name verifier, the result of th… Paho Java Client Mitigation only Fix from $1,9502019-09-11 MEDIUM 6.1 CVE-2019-11776 In Eclipse BIRT versions 1.0 to 4.7, the Report Viewer allows Reflected XSS in URL parameter. Attacker can execute the payload in victim's browser co… Business Intelligence And Reporting Tools after 4.7.0 Fix from $1,6002019-08-09 CRITICAL 9.8 CVE-2019-11772 In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that … Openj9 0.15.0+ Fix from $2,3002019-07-17 HIGH 7.8 CVE-2019-11771 AIX builds of Eclipse OpenJ9 before 0.15.0 contain unused RPATHs which may facilitate code injection and privilege elevation by local users. Openj9 0.15.0+ Fix from $1,9502019-07-17 HIGH 8.1 CVE-2019-11770 In Eclipse Buildship versions prior to 3.1.1, the build files indicate that this project is resolving dependencies over HTTP instead of HTTPS. Any of… Buildship 3.1.1+ Fix from $1,9502019-06-14 HIGH 8.1 CVE-2019-10249 All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artifacts may have been compromise… Xtend 2.18.0+ Fix from $1,9502019-05-06 HIGH 8.1 CVE-2019-10248 Eclipse Vorto versions prior to 0.11 resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS. Any of these dependent artifact… Vorto 0.11+ Fix from $1,9502019-04-22 MEDIUM 5.3 CVE-2019-10246 In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource dir… Jetty after 3.1.3 Fix from $1,6002019-04-22 HIGH 7.5 CVE-2019-10244 In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service … Kura after 4.0.0 Fix from $1,9502019-04-09 MEDIUM 5.3 CVE-2019-10242 In Eclipse Kura versions up to 4.0.0, the SkinServlet did not checked the path passed during servlet call, potentially allowing path traversal in get… Kura after 4.0.0 Fix from $1,6002019-04-09 MEDIUM 5.3 CVE-2019-10243 In Eclipse Kura versions up to 4.0.0, Kura exposes the underlying Ui Web server version in its replies. This can be used as a hint by an attacker to … Kura after 4.0.0 Fix from $1,6002019-04-09 HIGH 8.1 CVE-2019-10240 Eclipse hawkBit versions prior to 0.3.0M2 resolved Maven build artifacts for the Vaadin based UI over HTTP instead of HTTPS. Any of these dependent a… Hawkbit after 0.2.5 Fix from $1,9502019-04-03 HIGH 8.1 CVE-2018-12550 When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use an ACL file, and that ACL file is empty, or contains only comments or bl… Mosquitto after 1.5.5 Fix from $1,9502019-03-27 HIGH 8.1 CVE-2018-12551 When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use a password file for authentication, any malformed data in the password f… Mosquitto after 1.5.5 Fix from $1,9502019-03-27 MEDIUM 6.5 CVE-2018-12546 In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a retained message to a topic, then has its access to that topic revoke… Mosquitto after 1.5.5 Fix from $1,6002019-03-27 HIGH 7.5 CVE-2019-9004 In Eclipse Wakaama (formerly liblwm2m) 1.0, core/er-coap-13/er-coap-13.c in lwm2mserver in the LWM2M server mishandles invalid options, leading to a … Wakaama Patch available Fix from $1,9502019-02-22 CRITICAL 9.8 CVE-2018-12548 In OpenJDK + Eclipse OpenJ9 version 0.11.0 builds, the public jdk.crypto.jniprovider.NativeCrypto class contains public static natives which accept p… Openj9 Mitigation only Fix from $2,3002019-01-31 HIGH 7.5 CVE-2018-20227 RDF4J 2.4.2 allows Directory Traversal via ../ in an entry in a ZIP archive. Rdf4j 2.5.0+ Fix from $1,9502018-12-19 HIGH 7.5 CVE-2018-20145 Eclipse Mosquitto 1.5.x before 1.5.5 allows ACL bypass: if the option per_listener_settings was set to true, and the default listener was in use, and… Mosquitto 1.5.5+ Fix from $1,9502018-12-13 HIGH 7.5 CVE-2018-12543EPSS 36% In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is not $SYS, … Mosquitto after 1.5.2 Fix from $1,9502018-11-15 CRITICAL 9.8 CVE-2018-12542 In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that should be within a restricted di… Vert.x after 3.5.3 Fix from $2,3002018-10-10 CRITICAL 9.8 CVE-2018-12544 In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense against X… Vert.x Patch available Fix from $2,3002018-10-10 MEDIUM 6.5 CVE-2018-12541 In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the WebSocket HTTP upgrade implementation buffers the full http request before doing the handshake,… Vert.x 3.5.4+ Fix from $1,6002018-10-10 CRITICAL 10.0 CVE-2018-1000644 Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External Entity (XXE) vulnerability in RDF4j XML parser parsing RDF files that can result in… Rdf4j 2.4.0+ Fix from $2,3002018-08-20 HIGH 7.8 CVE-2018-12539 In Eclipse OpenJ9 version 0.8, users other than the process owner may be able to use Java Attach API to connect to an Eclipse OpenJ9 or IBM JVM on th… Openj9 Patch available Fix from $1,9502018-08-14 MEDIUM 5.3 CVE-2018-12537 In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed ch… Vert.x after 3.5.1 Fix from $1,6002018-08-14 HIGH 7.5 CVE-2018-14371 The getLocalePrefix function in ResourceManager.java in Eclipse Mojarra before 2.3.7 is affected by Directory Traversal via the loc parameter. A remo… Mojarra 2.3.7+ Fix from $1,9502018-07-18 HIGH 8.8 CVE-2018-12540 In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returned XSRF header/form parameter.… Vert.x after 3.5.2 Fix from $1,9502018-07-12