← Back

Cyclone Data Distribution Service

cyclone_data_distribution_service

Vendor: Eclipse • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Eclipse
1Cyclone Data Distribution Service
Jul 5, 2026
Dec 23, 2025
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certificate checks and execute commands with System privileges.
1Eclipse
1Cyclone Data Distribution Service
Jun 17, 2026
Mar 12, 2025
8.8 HIGH· v4
9.1 CRITICAL· v3
N/A· v2
An integer underflow during deserialization may allow any unauthenticated user to read out of bounds heap memory. This may result into secret data or pointers revealing the layout of the address space to be included into...Show more
An integer underflow during deserialization may allow any unauthenticated user to read out of bounds heap memory. This may result into secret data or pointers revealing the layout of the address space to be included into a deserialized data structure, which may potentially lead to thread crashes or cause denial of service conditions.Show less
1Eclipse
1Cyclone Data Distribution Service
Jun 17, 2026
Aug 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A heap buffer overflow in /src/dds_stream.c of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.
1Eclipse
1Cyclone Data Distribution Service
Jun 17, 2026
Aug 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A stack buffer overflow in /ddsi/q_bitset.h of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.