Skip to content
Noroxi

eclipse records

295 published records for vendor eclipse.

All records

295 records
  • The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023

  • CVE-2014-9390
    62This week

    Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before

    CriticalCVSS 9.8WeaponizedEPSS 76%

    mercurial · mercurialFeb 11, 2020

  • In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (curre

    CriticalCVSS 9.8Proof of conceptEPSS 58%

    eclipse · business intelligence and reporting toolsJun 25, 2021

  • The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process mem

    HighCVSS 7.5Proof of conceptEPSS 75%

    eclipse · jettyOct 7, 2016

  • For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the con

    MediumCVSS 5.3WeaponizedEPSS 99%

    eclipse · jettyJul 15, 2021

  • In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segm

    MediumCVSS 5.3WeaponizedEPSS 82%

    eclipse · jettyApr 1, 2021

  • Eclipse Mosquito: Heap Buffer Overflow in my_subscribe_callback

    HighCVSS 7.2No exploitEPSS 59%

    eclipse · mosquittoOct 30, 2024

  • In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large inva

    HighCVSS 7.5Proof of conceptEPSS 54%

    eclipse · jettyApr 1, 2021

  • For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to a

    MediumCVSS 5.3Proof of conceptEPSS 78%

    eclipse · jettyJun 8, 2021

  • In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when pr

    CriticalCVSS 9.8No exploitEPSS 19%

    eclipse · jettyJun 26, 2018

  • In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept

    MediumCVSS 5.3Proof of conceptEPSS 78%

    eclipse · jettyFeb 26, 2021

  • In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled

    CriticalCVSS 9.8No exploitEPSS 15%

    eclipse · jettyJun 26, 2018

  • In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is n

    HighCVSS 7.5No exploitEPSS 36%

    eclipse · mosquittoNov 15, 2018

  • The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass prot

    CriticalCVSS 9.8No exploitEPSS 6%

    eclipse · jettyApr 13, 2017

  • Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External Entity (XXE) vulnerability in RDF4j XML parser parsing RDF files that can

    CriticalCVSS 10.0No exploitEPSS 2%

    eclipse · rdf4jAug 20, 2018

  • In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce

    CriticalCVSS 9.4Proof of conceptEPSS 11%

    eclipse · jettyJul 9, 2020

  • Groovy Sandbox escape in Eclipse Keti

    CriticalCVSS 9.9No exploitEPSS 5%

    eclipse · ketiSep 8, 2021

  • In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter.

    CriticalCVSS 9.8No exploitEPSS 3%

    eclipse · openj9Feb 11, 2019

  • In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when ac

    CriticalCVSS 9.8No exploitEPSS 2%

    eclipse · openj9Feb 11, 2019

  • Potential buffer overflow in function DFU upload in Azure RTOS USBX

    CriticalCVSS 9.8No exploitEPSS 2%

    eclipse · threadx usbxMay 24, 2022

  • In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that should be within a rest

    CriticalCVSS 9.8Proof of conceptEPSS 2%

    eclipse · vert.xOct 10, 2018

  • In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-ext

    CriticalCVSS 9.8No exploitEPSS 2%

    eclipse · theiaSep 2, 2021

  • In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense

    CriticalCVSS 9.8No exploitEPSS 2%

    eclipse · vert.xOct 10, 2018

  • Eclipse CycloneDDS Write-what-where Condition

    CriticalCVSS 9.8No exploitEPSS 2%

    eclipse · cycloneddsMay 5, 2022

  • Eclipse CycloneDDS Improper Handling of Syntactically Invalid Structure

    CriticalCVSS 9.8No exploitEPSS 2%

    eclipse · cycloneddsMay 5, 2022