Eclipse
eclipse
260 CVEs • 67 products
Products (67)
Click to collapseToggle
Products (67)
Click to collapse
CVEs (260)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In versions 1.6 to 2.0.11 of Eclipse Mosquitto, an MQTT v5 client connecting with a large number of user-property properties could cause excessive CPU usage, leading to a loss of performance and possible denial of servic...Show more |
In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage(). |
1Eclipse 1Paho Mqtt C/c++ Client Nov 21, 2024 Nov 3, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In versions prior to 1.1 of the Eclipse Paho MQTT C Client, the client does not check rem_len size in readpacket. |
In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods. |
The build of some language stacks of Eclipse Che version 6 includes pulling some binaries from an unsecured HTTP endpoint. As a consequence the builds of such stacks are vulnerable to MITM attacks that allow the replacem...Show more |
In all released versions of Eclipse Equinox, at least until version 4.21 (September 2021), installation can be vulnerable to man-in-the-middle attack if using p2 repos that are HTTP; that can then be exploited to serve i...Show more |
Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a sandbox escape vulnerability may lead to post-authentication Remote Code execution. This vulnerab...Show more |
Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a user able to create Policy Sets can run arbitrary code by sending malicious Groovy scripts which...Show more |
In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. This extension uses lsp4xml (recently renamed to LemMinX) in order to pr...Show more |
In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE. But with the way it is made it is possible for a previewed HTML file to trigger an RCE. This...Show more |
2Eclipse Fedoraproject2Fedora MosquittoNov 21, 2024 Aug 30, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is revoked when a durable client is offline, then existing subscriptions f...Show more |
1Eclipse 1Cyclone Data Distribution Service Nov 21, 2024 Aug 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A heap buffer overflow in /src/dds_stream.c of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash. |
1Eclipse 1Cyclone Data Distribution Service Nov 21, 2024 Aug 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A stack buffer overflow in /ddsi/q_bitset.h of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash. |
In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally succeeds without verifying the server side's signature on the client side, if that...Show more |
In Eclipse Mosquitto versions 2.07 and earlier, the server will crash if the client tries to send a PUBLISH packet with topic length = 0. |
In Eclipse Mosquitto version 1.6 to 2.0.10, if an authenticated client that had connected with MQTT v5 sent a crafted CONNECT message to the broker a memory leak would occur, which could be used to provide a DoS attack a...Show more |
3Eclipse NetappOracle18Autovue For Agile Product Lifecycle Management Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Security Edge Protection Proxy+15 moreNov 21, 2024 Jul 15, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a...Show more |
Eclipse TinyDTLS through 0.9-rc1 relies on the rand function in the C library, which makes it easier for remote attackers to compute the master key and then decrypt DTLS traffic. |
1Eclipse 1Business Intelligence And Reporting Tools Nov 21, 2024 Jun 25, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code into the running instance. |
4Debian EclipseNetapp+1 more16Active Iq Unified Manager Autovue For Agile Product Lifecycle ManagementCommunications Element Manager+13 moreNov 21, 2024 Jun 22, 2021 N/A· v4 3.5 LOW· v3 3.6 LOW· v2 For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments w...Show more |