eclipse kayıtları
eclipse üreticisine ait 295 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %0,3
- Silahlaştırılmış
- 4 · %1,4
- Pre-auth RCE
- 16
- Düzeltme kaydı olan
- %72,9
- Yayından KEV’e ortanca
- 0 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')20
- CWE-125 Out-of-bounds Read17
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')16
- CWE-20 Improper Input Validation15
- CWE-400 Uncontrolled Resource Consumption14
- CWE-611 Improper Restriction of XML External Entity Reference14
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
295 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
90Hemen | CVE-2023-44487Silahlaştırılmış | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, assiemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware · CWE-400 | Yüksek7,5 | KEV | %100,0 | 10 Eki 2023 |
62Bu hafta | CVE-2014-9390Silahlaştırılmış | Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial beforemercurial · mercurial · CWE-20 | Kritik9,8 | — | %75,6 | 11 Şub 2020 |
56Planlayın | CVE-2021-34427Kavram kanıtı | In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (curreeclipse · business intelligence and reporting tools · CWE-20 | Kritik9,8 | — | %58,0 | 25 Haz 2021 |
53Planlayın | CVE-2015-2080Kavram kanıtı | The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memeclipse · jetty · CWE-200 | Yüksek7,5 | — | %75,4 | 7 Eki 2016 |
51Planlayın | CVE-2021-34429Silahlaştırılmış | For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the coneclipse · jetty · CWE-200 | Orta5,3 | — | %99,3 | 15 Tem 2021 |
46Planlayın | CVE-2021-28164Silahlaştırılmış | In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segmeclipse · jetty · CWE-200 | Orta5,3 | — | %82,4 | 1 Nis 2021 |
46Planlayın | CVE-2024-10525İstismar yok | Eclipse Mosquito: Heap Buffer Overflow in my_subscribe_callbackeclipse · mosquitto · CWE-122 | Yüksek7,2 | — | %59,5 | 30 Eki 2024 |
46Planlayın | CVE-2021-28165Kavram kanıtı | In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invaeclipse · jetty · CWE-400 | Yüksek7,5 | — | %53,9 | 1 Nis 2021 |
45Planlayın | CVE-2021-28169Kavram kanıtı | For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to aeclipse · jetty · CWE-200 | Orta5,3 | — | %78,5 | 8 Haz 2021 |
45Planlayın | CVE-2017-7658İstismar yok | In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when preclipse · jetty · CWE-444 | Kritik9,8 | — | %19,4 | 26 Haz 2018 |
44Planlayın | CVE-2020-27223Kavram kanıtı | In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accepteclipse · jetty · CWE-407 | Orta5,3 | — | %78,0 | 26 Şub 2021 |
43Planlayın | CVE-2017-7657İstismar yok | In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabledeclipse · jetty · CWE-444 | Kritik9,8 | — | %14,9 | 26 Haz 2018 |
41Planlayın | CVE-2018-12543İstismar yok | In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is neclipse · mosquitto · CWE-617 | Yüksek7,5 | — | %36,0 | 15 Kas 2018 |
41Planlayın | CVE-2016-4800İstismar yok | The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass proteclipse · jetty · CWE-284 | Kritik9,8 | — | %6,4 | 13 Nis 2017 |
41Planlayın | CVE-2018-1000644İstismar yok | Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External Entity (XXE) vulnerability in RDF4j XML parser parsing RDF files that can eclipse · rdf4j · CWE-611 | Kritik10,0 | — | %1,7 | 20 Ağu 2018 |
40Planlayın | CVE-2019-17638Kavram kanıtı | In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produceeclipse · jetty · CWE-672 | Kritik9,4 | — | %11,1 | 9 Tem 2020 |
40Planlayın | CVE-2021-32835İstismar yok | Groovy Sandbox escape in Eclipse Ketieclipse · keti · CWE-693 | Kritik9,9 | — | %4,6 | 8 Eyl 2021 |
40Planlayın | CVE-2018-12547İstismar yok | In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter.eclipse · openj9 · CWE-20 | Kritik9,8 | — | %2,7 | 11 Şub 2019 |
40Planlayın | CVE-2018-12549İstismar yok | In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when aceclipse · openj9 · CWE-111 | Kritik9,8 | — | %2,3 | 11 Şub 2019 |
40Planlayın | CVE-2022-29246İstismar yok | Potential buffer overflow in function DFU upload in Azure RTOS USBXeclipse · threadx usbx · CWE-120 | Kritik9,8 | — | %2,3 | 24 May 2022 |
40Planlayın | CVE-2018-12542Kavram kanıtı | In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that should be within a resteclipse · vert.x · CWE-22 | Kritik9,8 | — | %2,2 | 10 Eki 2018 |
40Planlayın | CVE-2021-34436İstismar yok | In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-exteclipse · theia · CWE-22 | Kritik9,8 | — | %2,2 | 2 Eyl 2021 |
40Planlayın | CVE-2018-12544İstismar yok | In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense eclipse · vert.x · CWE-611 | Kritik9,8 | — | %2,2 | 10 Eki 2018 |
40Planlayın | CVE-2021-38441İstismar yok | Eclipse CycloneDDS Write-what-where Conditioneclipse · cyclonedds · CWE-123 | Kritik9,8 | — | %2,1 | 5 May 2022 |
40Planlayın | CVE-2021-38443İstismar yok | Eclipse CycloneDDS Improper Handling of Syntactically Invalid Structureeclipse · cyclonedds · CWE-228 | Kritik9,8 | — | %2,1 | 5 May 2022 |
- CVE-2023-4448790Hemen
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware10 Eki 2023
- CVE-2014-939062Bu hafta
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before
KritikCVSS 9,8SilahlaştırılmışEPSS %76mercurial · mercurial11 Şub 2020
- CVE-2021-3442756Planlayın
In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (curre
KritikCVSS 9,8Kavram kanıtıEPSS %58eclipse · business intelligence and reporting tools25 Haz 2021
- CVE-2015-208053Planlayın
The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process mem
YüksekCVSS 7,5Kavram kanıtıEPSS %75eclipse · jetty7 Eki 2016
- CVE-2021-3442951Planlayın
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the con
OrtaCVSS 5,3SilahlaştırılmışEPSS %99eclipse · jetty15 Tem 2021
- CVE-2021-2816446Planlayın
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segm
OrtaCVSS 5,3SilahlaştırılmışEPSS %82eclipse · jetty1 Nis 2021
- CVE-2024-1052546Planlayın
Eclipse Mosquito: Heap Buffer Overflow in my_subscribe_callback
YüksekCVSS 7,2İstismar yokEPSS %59eclipse · mosquitto30 Eki 2024
- CVE-2021-2816546Planlayın
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large inva
YüksekCVSS 7,5Kavram kanıtıEPSS %54eclipse · jetty1 Nis 2021
- CVE-2021-2816945Planlayın
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, it is possible for requests to the ConcatServlet with a doubly encoded path to a
OrtaCVSS 5,3Kavram kanıtıEPSS %78eclipse · jetty8 Haz 2021
- CVE-2017-765845Planlayın
In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when pr
KritikCVSS 9,8İstismar yokEPSS %19eclipse · jetty26 Haz 2018
- CVE-2020-2722344Planlayın
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept
OrtaCVSS 5,3Kavram kanıtıEPSS %78eclipse · jetty26 Şub 2021
- CVE-2017-765743Planlayın
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled
KritikCVSS 9,8İstismar yokEPSS %15eclipse · jetty26 Haz 2018
- CVE-2018-1254341Planlayın
In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is n
YüksekCVSS 7,5İstismar yokEPSS %36eclipse · mosquitto15 Kas 2018
- CVE-2016-480041Planlayın
The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass prot
KritikCVSS 9,8İstismar yokEPSS %6eclipse · jetty13 Nis 2017
- CVE-2018-100064441Planlayın
Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External Entity (XXE) vulnerability in RDF4j XML parser parsing RDF files that can
KritikCVSS 10,0İstismar yokEPSS %2eclipse · rdf4j20 Ağu 2018
- CVE-2019-1763840Planlayın
In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce
KritikCVSS 9,4Kavram kanıtıEPSS %11eclipse · jetty9 Tem 2020
- CVE-2021-3283540Planlayın
Groovy Sandbox escape in Eclipse Keti
KritikCVSS 9,9İstismar yokEPSS %5eclipse · keti8 Eyl 2021
- CVE-2018-1254740Planlayın
In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter.
KritikCVSS 9,8İstismar yokEPSS %3eclipse · openj911 Şub 2019
- CVE-2018-1254940Planlayın
In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when ac
KritikCVSS 9,8İstismar yokEPSS %2eclipse · openj911 Şub 2019
- CVE-2022-2924640Planlayın
Potential buffer overflow in function DFU upload in Azure RTOS USBX
KritikCVSS 9,8İstismar yokEPSS %2eclipse · threadx usbx24 May 2022
- CVE-2018-1254240Planlayın
In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that should be within a rest
KritikCVSS 9,8Kavram kanıtıEPSS %2eclipse · vert.x10 Eki 2018
- CVE-2021-3443640Planlayın
In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-ext
KritikCVSS 9,8İstismar yokEPSS %2eclipse · theia2 Eyl 2021
- CVE-2018-1254440Planlayın
In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense
KritikCVSS 9,8İstismar yokEPSS %2eclipse · vert.x10 Eki 2018
- CVE-2021-3844140Planlayın
Eclipse CycloneDDS Write-what-where Condition
KritikCVSS 9,8İstismar yokEPSS %2eclipse · cyclonedds5 May 2022
- CVE-2021-3844340Planlayın
Eclipse CycloneDDS Improper Handling of Syntactically Invalid Structure
KritikCVSS 9,8İstismar yokEPSS %2eclipse · cyclonedds5 May 2022