eclipse records
295 published records for vendor eclipse.
Researcher profile
- Entered KEV
- 1 · 0.3%
- Weaponized
- 4 · 1.4%
- Pre-auth RCE
- 16
- With a fix record
- 72.9%
- Median publish → KEV
- 0 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')20
- CWE-125 Out-of-bounds Read17
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')16
- CWE-20 Improper Input Validation15
- CWE-400 Uncontrolled Resource Consumption14
- CWE-611 Improper Restriction of XML External Entity Reference14
The weakness classes this vendor ships most often: where to look.
CWEAll records
295 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
90Now | CVE-2023-44487Weaponized | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | High7.5 | KEV | 100.0% | Oct 10, 2023 |
62This week | CVE-2014-9390Weaponized | Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial beforemercurial · mercurial · CWE-20 | Critical9.8 | — | 75.6% | Feb 11, 2020 |
56Plan | CVE-2021-34427Proof of concept | In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (curreeclipse · business intelligence and reporting tools · CWE-20 | Critical9.8 | — | 58.0% | Jun 25, 2021 |
53Plan | CVE-2015-2080Proof of concept | The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memeclipse · jetty · CWE-200 | High7.5 | — | 75.4% | Oct 7, 2016 |
51Plan | CVE-2021-34429Weaponized | For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the coneclipse · jetty · CWE-200 | Medium5.3 | — | 99.3% | Jul 15, 2021 |
46Plan | CVE-2021-28164Weaponized | In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segmeclipse · jetty · CWE-200 | Medium5.3 | — | 82.4% | Apr 1, 2021 |
46Plan | CVE-2024-10525No exploit | Eclipse Mosquito: Heap Buffer Overflow in my_subscribe_callbackeclipse · mosquitto · CWE-122 | High7.2 | — | 59.5% | Oct 30, 2024 |
46Plan | CVE-2021-28165Proof of concept | In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invaeclipse · jetty · CWE-400 | High7.5 | — | 53.9% | Apr 1, 2021 |
45Plan | CVE-2021-28169Proof of concept | For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to aeclipse · jetty · CWE-200 | Medium5.3 | — | 78.5% | Jun 8, 2021 |
45Plan | CVE-2017-7658No exploit | In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when preclipse · jetty · CWE-444 | Critical9.8 | — | 19.4% | Jun 26, 2018 |
44Plan | CVE-2020-27223Proof of concept | In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accepteclipse · jetty · CWE-407 | Medium5.3 | — | 78.0% | Feb 26, 2021 |
43Plan | CVE-2017-7657No exploit | In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabledeclipse · jetty · CWE-444 | Critical9.8 | — | 14.9% | Jun 26, 2018 |
41Plan | CVE-2018-12543No exploit | In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is neclipse · mosquitto · CWE-617 | High7.5 | — | 36.0% | Nov 15, 2018 |
41Plan | CVE-2016-4800No exploit | The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass proteclipse · jetty · CWE-284 | Critical9.8 | — | 6.4% | Apr 13, 2017 |
41Plan | CVE-2018-1000644No exploit | Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External Entity (XXE) vulnerability in RDF4j XML parser parsing RDF files that can eclipse · rdf4j · CWE-611 | Critical10.0 | — | 1.7% | Aug 20, 2018 |
40Plan | CVE-2019-17638Proof of concept | In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produceeclipse · jetty · CWE-672 | Critical9.4 | — | 11.1% | Jul 9, 2020 |
40Plan | CVE-2021-32835No exploit | Groovy Sandbox escape in Eclipse Ketieclipse · keti · CWE-693 | Critical9.9 | — | 4.6% | Sep 8, 2021 |
40Plan | CVE-2018-12547No exploit | In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter.eclipse · openj9 · CWE-20 | Critical9.8 | — | 2.7% | Feb 11, 2019 |
40Plan | CVE-2018-12549No exploit | In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when aceclipse · openj9 · CWE-111 | Critical9.8 | — | 2.3% | Feb 11, 2019 |
40Plan | CVE-2022-29246No exploit | Potential buffer overflow in function DFU upload in Azure RTOS USBXeclipse · threadx usbx · CWE-120 | Critical9.8 | — | 2.3% | May 24, 2022 |
40Plan | CVE-2018-12542Proof of concept | In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that should be within a resteclipse · vert.x · CWE-22 | Critical9.8 | — | 2.2% | Oct 10, 2018 |
40Plan | CVE-2021-34436No exploit | In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-exteclipse · theia · CWE-22 | Critical9.8 | — | 2.2% | Sep 2, 2021 |
40Plan | CVE-2018-12544No exploit | In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense eclipse · vert.x · CWE-611 | Critical9.8 | — | 2.2% | Oct 10, 2018 |
40Plan | CVE-2021-38441No exploit | Eclipse CycloneDDS Write-what-where Conditioneclipse · cyclonedds · CWE-123 | Critical9.8 | — | 2.1% | May 5, 2022 |
40Plan | CVE-2021-38443No exploit | Eclipse CycloneDDS Improper Handling of Syntactically Invalid Structureeclipse · cyclonedds · CWE-228 | Critical9.8 | — | 2.1% | May 5, 2022 |
- CVE-2023-4448790Now
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
HighCVSS 7.5KEVWeaponizedEPSS 100%siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023
- CVE-2014-939062This week
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before
CriticalCVSS 9.8WeaponizedEPSS 76%mercurial · mercurialFeb 11, 2020
- CVE-2021-3442756Plan
In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (curre
CriticalCVSS 9.8Proof of conceptEPSS 58%eclipse · business intelligence and reporting toolsJun 25, 2021
- CVE-2015-208053Plan
The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process mem
HighCVSS 7.5Proof of conceptEPSS 75%eclipse · jettyOct 7, 2016
- CVE-2021-3442951Plan
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the con
MediumCVSS 5.3WeaponizedEPSS 99%eclipse · jettyJul 15, 2021
- CVE-2021-2816446Plan
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segm
MediumCVSS 5.3WeaponizedEPSS 82%eclipse · jettyApr 1, 2021
- CVE-2024-1052546Plan
Eclipse Mosquito: Heap Buffer Overflow in my_subscribe_callback
HighCVSS 7.2No exploitEPSS 59%eclipse · mosquittoOct 30, 2024
- CVE-2021-2816546Plan
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large inva
HighCVSS 7.5Proof of conceptEPSS 54%eclipse · jettyApr 1, 2021
- CVE-2021-2816945Plan
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to a
MediumCVSS 5.3Proof of conceptEPSS 78%eclipse · jettyJun 8, 2021
- CVE-2017-765845Plan
In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when pr
CriticalCVSS 9.8No exploitEPSS 19%eclipse · jettyJun 26, 2018
- CVE-2020-2722344Plan
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept
MediumCVSS 5.3Proof of conceptEPSS 78%eclipse · jettyFeb 26, 2021
- CVE-2017-765743Plan
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled
CriticalCVSS 9.8No exploitEPSS 15%eclipse · jettyJun 26, 2018
- CVE-2018-1254341Plan
In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is n
HighCVSS 7.5No exploitEPSS 36%eclipse · mosquittoNov 15, 2018
- CVE-2016-480041Plan
The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass prot
CriticalCVSS 9.8No exploitEPSS 6%eclipse · jettyApr 13, 2017
- CVE-2018-100064441Plan
Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External Entity (XXE) vulnerability in RDF4j XML parser parsing RDF files that can
CriticalCVSS 10.0No exploitEPSS 2%eclipse · rdf4jAug 20, 2018
- CVE-2019-1763840Plan
In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce
CriticalCVSS 9.4Proof of conceptEPSS 11%eclipse · jettyJul 9, 2020
- CVE-2021-3283540Plan
Groovy Sandbox escape in Eclipse Keti
CriticalCVSS 9.9No exploitEPSS 5%eclipse · ketiSep 8, 2021
- CVE-2018-1254740Plan
In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter.
CriticalCVSS 9.8No exploitEPSS 3%eclipse · openj9Feb 11, 2019
- CVE-2018-1254940Plan
In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when ac
CriticalCVSS 9.8No exploitEPSS 2%eclipse · openj9Feb 11, 2019
- CVE-2022-2924640Plan
Potential buffer overflow in function DFU upload in Azure RTOS USBX
CriticalCVSS 9.8No exploitEPSS 2%eclipse · threadx usbxMay 24, 2022
- CVE-2018-1254240Plan
In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that should be within a rest
CriticalCVSS 9.8Proof of conceptEPSS 2%eclipse · vert.xOct 10, 2018
- CVE-2021-3443640Plan
In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-ext
CriticalCVSS 9.8No exploitEPSS 2%eclipse · theiaSep 2, 2021
- CVE-2018-1254440Plan
In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense
CriticalCVSS 9.8No exploitEPSS 2%eclipse · vert.xOct 10, 2018
- CVE-2021-3844140Plan
Eclipse CycloneDDS Write-what-where Condition
CriticalCVSS 9.8No exploitEPSS 2%eclipse · cycloneddsMay 5, 2022
- CVE-2021-3844340Plan
Eclipse CycloneDDS Improper Handling of Syntactically Invalid Structure
CriticalCVSS 9.8No exploitEPSS 2%eclipse · cycloneddsMay 5, 2022