← Back

Eclipse

eclipse

276 CVEs • 70 products

Products (70)

Click to collapse
Toggle
Jetty
jetty
Mosquitto
mosquitto
Openj9
openj9
Threadx Usbx
threadx_usbx
Vert.x
vert.x
Glassfish
glassfish
Theia
theia
Omr
omr
Threadx
threadx
Kura
kura
Che
che
Californium
californium
Open Vsx
open_vsx
Eclipse Ide
eclipse_ide
Mojarra
mojarra
Jgit
jgit
Vert.x Web
vert.x-web
Tinydtls
tinydtls
Rdf4j
rdf4j
Wakaama
wakaama
Hawkbit
hawkbit
Hono
hono
Jersey
jersey
Keti
keti
Lemminx
lemminx
Cyclonedds
cyclonedds
Parsson
parsson
Openmq
openmq
Birt
birt
Ide
ide
Vorto
vorto
Xtend
xtend
Xtext
xtext
Buildship
buildship
Egit
egit
Platform
platform
Equinox
equinox
Lyo
lyo
Equinox P2
equinox_p2
Hudson
hudson
Sphinx
sphinx
Milo
milo
Deeplearning4j
deeplearning4j
Vert.x Stomp
vert.x_stomp
Leshan
leshan
Pde
pde
Edc Connector
edc_connector
Ditto
ditto
Jakarta Mail
jakarta_mail
Angus Mail
angus_mail
Threadx Filex
threadx_filex
Paho Mqtt
paho_mqtt
Theia Website
theia_website
4diac Forte
4diac_forte
Grizzly
grizzly
Kuksa
kuksa

CVEs (276)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Eclipse
1Threadx Usbx
Jun 17, 2026
Oct 17, 2025
2.4 LOW· v4
9.1 CRITICAL· v3
N/A· v2
In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio10_sam_parse_func() when parsing a list of sampling frequencies.
1Eclipse
1Threadx Usbx
Jun 17, 2026
Oct 17, 2025
2.4 LOW· v4
6.1 MEDIUM· v3
N/A· v2
In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio_alternate_setting_locate() when parsing a descriptor with attacker-contro...Show more
In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio_alternate_setting_locate() when parsing a descriptor with attacker-controlled frequency fields.Show less
1Eclipse
1Threadx Usbx
Jun 17, 2026
Oct 17, 2025
1.0 LOW· v4
6.1 MEDIUM· v3
N/A· v2
In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio_device_type_get() when parsing a descriptor of an USB audio device.
1Eclipse
1Threadx Usbx
Jun 17, 2026
Oct 17, 2025
2.4 LOW· v4
6.1 MEDIUM· v3
N/A· v2
In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio_streaming_sampling_get() when parsing a descriptor of an USB streaming de...Show more
In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio_streaming_sampling_get() when parsing a descriptor of an USB streaming device.Show less
1Eclipse
1Threadx Usbx
Jun 17, 2026
Oct 17, 2025
2.1 LOW· v4
6.1 MEDIUM· v3
N/A· v2
In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_hid_report_descriptor_get()  when parsing a descriptor of an USB HID device.
1Eclipse
1Threadx Netx Duo
Jun 17, 2026
Oct 17, 2025
6.9 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_icmpv6_validate_options() when handling a packet with ICMP6 options.
1Eclipse
1Threadx Netx Duo
Jun 17, 2026
Oct 17, 2025
6.3 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
In NextX Duo's snmp addon versions before 6.4.4, a part of the Eclipse Foundation ThreadX, an attacker could cause an out-of-bound read by a crafted SNMPv3 security parameters.
1Eclipse
1Threadx Netx Duo
Jun 17, 2026
Oct 17, 2025
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_packet_receive() when handling unicast DHCP messages that could cause corr...Show more
In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_packet_receive() when handling unicast DHCP messages that could cause corruption of 4 bytes of memory.Show less
1Eclipse
1Threadx Netx Duo
Jun 17, 2026
Oct 17, 2025
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
In Eclipse Foundation NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_option_process() when processing an IPv4 packet with th...Show more
In Eclipse Foundation NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_option_process() when processing an IPv4 packet with the timestamp option.Show less
1Eclipse
1Threadx Netx Duo
Jun 17, 2026
Oct 16, 2025
6.9 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ip_packet_receive() function when received an Ethernet with type set as IP but...Show more
In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ip_packet_receive() function when received an Ethernet with type set as IP but no IP data.Show less
1Eclipse
1Threadx Netx Duo
Jun 17, 2026
Oct 16, 2025
6.9 MEDIUM· v4
6.5 MEDIUM· v3
N/A· v2
In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_packet_receive() function when received an Ethernet frame with less than 4...Show more
In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_packet_receive() function when received an Ethernet frame with less than 4 bytes of IP packet.Show less
1Eclipse
1Threadx Filex
Jun 17, 2026
Oct 16, 2025
9.2 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
In FileX before 6.4.2, the file support module for Eclipse Foundation ThreadX, there was a possible buffer overflow in the FileX RAM disk driver. It could cause a remote execurtion after receiving a crafted sequence of p...Show more
In FileX before 6.4.2, the file support module for Eclipse Foundation ThreadX, there was a possible buffer overflow in the FileX RAM disk driver. It could cause a remote execurtion after receiving a crafted sequence of packetsShow less
1Eclipse
1Threadx Netx Duo
Jun 17, 2026
Oct 16, 2025
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check in_nx_secure_tls_proc_clienthello_supported_versions_extension() in the extension version field.
1Eclipse
1Threadx Netx Duo
Jun 17, 2026
Oct 15, 2025
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check resulting it out by two out of bound read.
1Eclipse
1Threadx Netx Duo
Jun 17, 2026
Oct 15, 2025
6.9 MEDIUM· v4
5.3 MEDIUM· v3
N/A· v2
In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was a potential out of bound read in _nx_secure_tls_process_clienthello() because of a missing validation of PSK length provided in the...Show more
In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was a potential out of bound read in _nx_secure_tls_process_clienthello() because of a missing validation of PSK length provided in the user message.Show less
1Eclipse
1Threadx Netx Duo
Jun 17, 2026
Oct 15, 2025
6.9 MEDIUM· v4
9.1 CRITICAL· v3
N/A· v2
In Eclipse Foundation NextX Duo before 6.4.4, a module of ThreadX, the _nx_secure_tls_process_clienthello() function was missing length verification of certain SSL/TLS client hello message: the ciphersuite length and c...Show more
In Eclipse Foundation NextX Duo before 6.4.4, a module of ThreadX, the _nx_secure_tls_process_clienthello() function was missing length verification of certain SSL/TLS client hello message: the ciphersuite length and compression method length. In case of an attacker-crafted message with values outside of the expected range, it could cause an out-of-bound read.Show less
1Eclipse
1Threadx
Jun 17, 2026
Oct 15, 2025
7.2 HIGH· v4
7.1 HIGH· v3
N/A· v2
In Eclipse ThreadX before 6.4.3, when memory protection is enabled, syscall parameters verification wasn't enough, allowing an attacker to obtain an arbitrary memory read/write.
1Eclipse
1Threadx
Jun 17, 2026
Oct 15, 2025
5.7 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
In Eclipse ThreadX before version 6.4.3, the thread module has a setting of maximum priority. In some cases the check of that maximum priority wasn't performed, allowing, as a result, to obtain a thread with higher prior...Show more
In Eclipse ThreadX before version 6.4.3, the thread module has a setting of maximum priority. In some cases the check of that maximum priority wasn't performed, allowing, as a result, to obtain a thread with higher priority than expected and causing a possible denial of service.Show less
1Eclipse
1Threadx
Jun 17, 2026
Oct 14, 2025
5.7 MEDIUM· v4
5.5 MEDIUM· v3
N/A· v2
In Eclipse ThreadX before version 6.4.3, an attacker can cause a denial of service (crash) by providing a pointer to a reserved or unmapped memory region. Vulnerable system calls had a check of pointers, but that check w...Show more
In Eclipse ThreadX before version 6.4.3, an attacker can cause a denial of service (crash) by providing a pointer to a reserved or unmapped memory region. Vulnerable system calls had a check of pointers, but that check wasn't verifying whether the pointer is outside the module memory region.Show less
1Eclipse
1Jetty
Jun 17, 2026
Aug 20, 2025
7.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for example by sending frames that are malformed or that should no...Show more
In Eclipse Jetty, versions <=9.4.57, <=10.0.25, <=11.0.25, <=12.0.21, <=12.1.0.alpha2, an HTTP/2 client may trigger the server to send RST_STREAM frames, for example by sending frames that are malformed or that should not be sent in a particular stream state, therefore forcing the server to consume resources such as CPU and memory. For example, a client can open a stream and then send WINDOW_UPDATE frames with window size increment of 0, which is illegal. Per specification https://www.rfc-editor.org/rfc/rfc9113.html#name-window_update , the server should send a RST_STREAM frame. The client can now open another stream and send another bad WINDOW_UPDATE, therefore causing the server to consume more resources than necessary, as this case does not exceed the max number of concurrent streams, yet the client is able to create an enormous amount of streams in a short period of time. The attack can be performed with other conditions (for example, a DATA frame for a closed stream) that cause the server to send a RST_STREAM frame. Links: * https://github.com/jetty/jetty.project/security/advisories/GHSA-mmxm-8w33-wc4hShow less