Записи eclipse
295 опубликованных записей вендора eclipse.
Профиль для исследователя
- Попали в KEV
- 1 · 0,3 %
- С эксплойтом
- 4 · 1,4 %
- Pre-auth RCE
- 16
- С записью об исправлении
- 72,9 %
- Медиана: публикация → KEV
- 0 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')20
- CWE-125 Out-of-bounds Read17
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')16
- CWE-20 Improper Input Validation15
- CWE-400 Uncontrolled Resource Consumption14
- CWE-611 Improper Restriction of XML External Entity Reference14
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
295 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
90Срочно | CVE-2023-44487Готовый эксплойт | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Высокая7,5 | KEV | 100,0 % | 10 окт. 2023 г. |
62На этой неделе | CVE-2014-9390Готовый эксплойт | Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial beforemercurial · mercurial · CWE-20 | Критическая9,8 | — | 75,6 % | 11 февр. 2020 г. |
56В плане | CVE-2021-34427Proof of concept | In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (curreeclipse · business intelligence and reporting tools · CWE-20 | Критическая9,8 | — | 58,0 % | 25 июн. 2021 г. |
53В плане | CVE-2015-2080Proof of concept | The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memeclipse · jetty · CWE-200 | Высокая7,5 | — | 75,4 % | 7 окт. 2016 г. |
51В плане | CVE-2021-34429Готовый эксплойт | For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the coneclipse · jetty · CWE-200 | Средняя5,3 | — | 99,3 % | 15 июл. 2021 г. |
46В плане | CVE-2021-28164Готовый эксплойт | In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segmeclipse · jetty · CWE-200 | Средняя5,3 | — | 82,4 % | 1 апр. 2021 г. |
46В плане | CVE-2024-10525Эксплойта нет | Eclipse Mosquito: Heap Buffer Overflow in my_subscribe_callbackeclipse · mosquitto · CWE-122 | Высокая7,2 | — | 59,5 % | 30 окт. 2024 г. |
46В плане | CVE-2021-28165Proof of concept | In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invaeclipse · jetty · CWE-400 | Высокая7,5 | — | 53,9 % | 1 апр. 2021 г. |
45В плане | CVE-2021-28169Proof of concept | For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to aeclipse · jetty · CWE-200 | Средняя5,3 | — | 78,5 % | 8 июн. 2021 г. |
45В плане | CVE-2017-7658Эксплойта нет | In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when preclipse · jetty · CWE-444 | Критическая9,8 | — | 19,4 % | 26 июн. 2018 г. |
44В плане | CVE-2020-27223Proof of concept | In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accepteclipse · jetty · CWE-407 | Средняя5,3 | — | 78,0 % | 26 февр. 2021 г. |
43В плане | CVE-2017-7657Эксплойта нет | In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabledeclipse · jetty · CWE-444 | Критическая9,8 | — | 14,9 % | 26 июн. 2018 г. |
41В плане | CVE-2018-12543Эксплойта нет | In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is neclipse · mosquitto · CWE-617 | Высокая7,5 | — | 36,0 % | 15 нояб. 2018 г. |
41В плане | CVE-2016-4800Эксплойта нет | The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass proteclipse · jetty · CWE-284 | Критическая9,8 | — | 6,4 % | 13 апр. 2017 г. |
41В плане | CVE-2018-1000644Эксплойта нет | Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External Entity (XXE) vulnerability in RDF4j XML parser parsing RDF files that can eclipse · rdf4j · CWE-611 | Критическая10,0 | — | 1,7 % | 20 авг. 2018 г. |
40В плане | CVE-2019-17638Proof of concept | In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produceeclipse · jetty · CWE-672 | Критическая9,4 | — | 11,1 % | 9 июл. 2020 г. |
40В плане | CVE-2021-32835Эксплойта нет | Groovy Sandbox escape in Eclipse Ketieclipse · keti · CWE-693 | Критическая9,9 | — | 4,6 % | 8 сент. 2021 г. |
40В плане | CVE-2018-12547Эксплойта нет | In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter.eclipse · openj9 · CWE-20 | Критическая9,8 | — | 2,7 % | 11 февр. 2019 г. |
40В плане | CVE-2018-12549Эксплойта нет | In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when aceclipse · openj9 · CWE-111 | Критическая9,8 | — | 2,3 % | 11 февр. 2019 г. |
40В плане | CVE-2022-29246Эксплойта нет | Potential buffer overflow in function DFU upload in Azure RTOS USBXeclipse · threadx usbx · CWE-120 | Критическая9,8 | — | 2,3 % | 24 мая 2022 г. |
40В плане | CVE-2018-12542Proof of concept | In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that should be within a resteclipse · vert.x · CWE-22 | Критическая9,8 | — | 2,2 % | 10 окт. 2018 г. |
40В плане | CVE-2021-34436Эксплойта нет | In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-exteclipse · theia · CWE-22 | Критическая9,8 | — | 2,2 % | 2 сент. 2021 г. |
40В плане | CVE-2018-12544Эксплойта нет | In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense eclipse · vert.x · CWE-611 | Критическая9,8 | — | 2,2 % | 10 окт. 2018 г. |
40В плане | CVE-2021-38441Эксплойта нет | Eclipse CycloneDDS Write-what-where Conditioneclipse · cyclonedds · CWE-123 | Критическая9,8 | — | 2,1 % | 5 мая 2022 г. |
40В плане | CVE-2021-38443Эксплойта нет | Eclipse CycloneDDS Improper Handling of Syntactically Invalid Structureeclipse · cyclonedds · CWE-228 | Критическая9,8 | — | 2,1 % | 5 мая 2022 г. |
- CVE-2023-4448790Срочно
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 окт. 2023 г.
- CVE-2014-939062На этой неделе
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before
КритическаяCVSS 9,8Готовый эксплойтEPSS 76 %mercurial · mercurial11 февр. 2020 г.
- CVE-2021-3442756В плане
In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (curre
КритическаяCVSS 9,8Proof of conceptEPSS 58 %eclipse · business intelligence and reporting tools25 июн. 2021 г.
- CVE-2015-208053В плане
The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process mem
ВысокаяCVSS 7,5Proof of conceptEPSS 75 %eclipse · jetty7 окт. 2016 г.
- CVE-2021-3442951В плане
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the con
СредняяCVSS 5,3Готовый эксплойтEPSS 99 %eclipse · jetty15 июл. 2021 г.
- CVE-2021-2816446В плане
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segm
СредняяCVSS 5,3Готовый эксплойтEPSS 82 %eclipse · jetty1 апр. 2021 г.
- CVE-2024-1052546В плане
Eclipse Mosquito: Heap Buffer Overflow in my_subscribe_callback
ВысокаяCVSS 7,2Эксплойта нетEPSS 59 %eclipse · mosquitto30 окт. 2024 г.
- CVE-2021-2816546В плане
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large inva
ВысокаяCVSS 7,5Proof of conceptEPSS 54 %eclipse · jetty1 апр. 2021 г.
- CVE-2021-2816945В плане
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to a
СредняяCVSS 5,3Proof of conceptEPSS 78 %eclipse · jetty8 июн. 2021 г.
- CVE-2017-765845В плане
In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when pr
КритическаяCVSS 9,8Эксплойта нетEPSS 19 %eclipse · jetty26 июн. 2018 г.
- CVE-2020-2722344В плане
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept
СредняяCVSS 5,3Proof of conceptEPSS 78 %eclipse · jetty26 февр. 2021 г.
- CVE-2017-765743В плане
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled
КритическаяCVSS 9,8Эксплойта нетEPSS 15 %eclipse · jetty26 июн. 2018 г.
- CVE-2018-1254341В плане
In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is n
ВысокаяCVSS 7,5Эксплойта нетEPSS 36 %eclipse · mosquitto15 нояб. 2018 г.
- CVE-2016-480041В плане
The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass prot
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %eclipse · jetty13 апр. 2017 г.
- CVE-2018-100064441В плане
Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External Entity (XXE) vulnerability in RDF4j XML parser parsing RDF files that can
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %eclipse · rdf4j20 авг. 2018 г.
- CVE-2019-1763840В плане
In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce
КритическаяCVSS 9,4Proof of conceptEPSS 11 %eclipse · jetty9 июл. 2020 г.
- CVE-2021-3283540В плане
Groovy Sandbox escape in Eclipse Keti
КритическаяCVSS 9,9Эксплойта нетEPSS 5 %eclipse · keti8 сент. 2021 г.
- CVE-2018-1254740В плане
In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %eclipse · openj911 февр. 2019 г.
- CVE-2018-1254940В плане
In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when ac
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %eclipse · openj911 февр. 2019 г.
- CVE-2022-2924640В плане
Potential buffer overflow in function DFU upload in Azure RTOS USBX
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %eclipse · threadx usbx24 мая 2022 г.
- CVE-2018-1254240В плане
In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that should be within a rest
КритическаяCVSS 9,8Proof of conceptEPSS 2 %eclipse · vert.x10 окт. 2018 г.
- CVE-2021-3443640В плане
In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-ext
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %eclipse · theia2 сент. 2021 г.
- CVE-2018-1254440В плане
In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %eclipse · vert.x10 окт. 2018 г.
- CVE-2021-3844140В плане
Eclipse CycloneDDS Write-what-where Condition
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %eclipse · cyclonedds5 мая 2022 г.
- CVE-2021-3844340В плане
Eclipse CycloneDDS Improper Handling of Syntactically Invalid Structure
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %eclipse · cyclonedds5 мая 2022 г.