İçeriğe atla
Noroxi

eclipse kayıtları

eclipse üreticisine ait 295 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
1 · %0,3
Silahlaştırılmış
4 · %1,4
Pre-auth RCE
16
Düzeltme kaydı olan
%72,9
Yayından KEV’e ortanca
0 gün

Tüm kayıtlar

295 kayıt
  • The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100

    siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 Eki 2023

  • CVE-2014-9390
    62Bu hafta

    Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before

    KritikCVSS 9,8SilahlaştırılmışEPSS %76

    mercurial · mercurial11 Şub 2020

  • CVE-2021-34427
    56Planlayın

    In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (curre

    KritikCVSS 9,8Kavram kanıtıEPSS %58

    eclipse · business intelligence and reporting tools25 Haz 2021

  • CVE-2015-2080
    53Planlayın

    The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process mem

    YüksekCVSS 7,5Kavram kanıtıEPSS %75

    eclipse · jetty7 Eki 2016

  • CVE-2021-34429
    51Planlayın

    For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the con

    OrtaCVSS 5,3SilahlaştırılmışEPSS %99

    eclipse · jetty15 Tem 2021

  • CVE-2021-28164
    46Planlayın

    In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segm

    OrtaCVSS 5,3SilahlaştırılmışEPSS %82

    eclipse · jetty1 Nis 2021

  • CVE-2024-10525
    46Planlayın

    Eclipse Mosquito: Heap Buffer Overflow in my_subscribe_callback

    YüksekCVSS 7,2İstismar yokEPSS %59

    eclipse · mosquitto30 Eki 2024

  • CVE-2021-28165
    46Planlayın

    In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large inva

    YüksekCVSS 7,5Kavram kanıtıEPSS %54

    eclipse · jetty1 Nis 2021

  • CVE-2021-28169
    45Planlayın

    For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to a

    OrtaCVSS 5,3Kavram kanıtıEPSS %78

    eclipse · jetty8 Haz 2021

  • CVE-2017-7658
    45Planlayın

    In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when pr

    KritikCVSS 9,8İstismar yokEPSS %19

    eclipse · jetty26 Haz 2018

  • CVE-2020-27223
    44Planlayın

    In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept

    OrtaCVSS 5,3Kavram kanıtıEPSS %78

    eclipse · jetty26 Şub 2021

  • CVE-2017-7657
    43Planlayın

    In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled

    KritikCVSS 9,8İstismar yokEPSS %15

    eclipse · jetty26 Haz 2018

  • CVE-2018-12543
    41Planlayın

    In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is n

    YüksekCVSS 7,5İstismar yokEPSS %36

    eclipse · mosquitto15 Kas 2018

  • CVE-2016-4800
    41Planlayın

    The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass prot

    KritikCVSS 9,8İstismar yokEPSS %6

    eclipse · jetty13 Nis 2017

  • CVE-2018-1000644
    41Planlayın

    Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External Entity (XXE) vulnerability in RDF4j XML parser parsing RDF files that can

    KritikCVSS 10,0İstismar yokEPSS %2

    eclipse · rdf4j20 Ağu 2018

  • CVE-2019-17638
    40Planlayın

    In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce

    KritikCVSS 9,4Kavram kanıtıEPSS %11

    eclipse · jetty9 Tem 2020

  • CVE-2021-32835
    40Planlayın

    Groovy Sandbox escape in Eclipse Keti

    KritikCVSS 9,9İstismar yokEPSS %5

    eclipse · keti8 Eyl 2021

  • CVE-2018-12547
    40Planlayın

    In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter.

    KritikCVSS 9,8İstismar yokEPSS %3

    eclipse · openj911 Şub 2019

  • CVE-2018-12549
    40Planlayın

    In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when ac

    KritikCVSS 9,8İstismar yokEPSS %2

    eclipse · openj911 Şub 2019

  • CVE-2022-29246
    40Planlayın

    Potential buffer overflow in function DFU upload in Azure RTOS USBX

    KritikCVSS 9,8İstismar yokEPSS %2

    eclipse · threadx usbx24 May 2022

  • CVE-2018-12542
    40Planlayın

    In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that should be within a rest

    KritikCVSS 9,8Kavram kanıtıEPSS %2

    eclipse · vert.x10 Eki 2018

  • CVE-2021-34436
    40Planlayın

    In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-ext

    KritikCVSS 9,8İstismar yokEPSS %2

    eclipse · theia2 Eyl 2021

  • CVE-2018-12544
    40Planlayın

    In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense

    KritikCVSS 9,8İstismar yokEPSS %2

    eclipse · vert.x10 Eki 2018

  • CVE-2021-38441
    40Planlayın

    Eclipse CycloneDDS Write-what-where Condition

    KritikCVSS 9,8İstismar yokEPSS %2

    eclipse · cyclonedds5 May 2022

  • CVE-2021-38443
    40Planlayın

    Eclipse CycloneDDS Improper Handling of Syntactically Invalid Structure

    KritikCVSS 9,8İstismar yokEPSS %2

    eclipse · cyclonedds5 May 2022