Vulnerabilities > Eclipse > Mosquitto

DATE CVE VULNERABILITY TITLE RISK
2018-04-25 CVE-2017-7652 In Eclipse Mosquitto 1.4.14, if a Mosquitto instance is set running with a configuration file, then sending a HUP signal to server triggers the configuration to be reloaded from disk.
network
high complexity
eclipse debian
7.5
2018-04-24 CVE-2017-7651 Resource Exhaustion vulnerability in multiple products
In Eclipse Mosquitto 1.4.14, a user can shutdown the Mosquitto server simply by filling the RAM memory with a lot of connections with large payload.
network
low complexity
eclipse debian CWE-400
7.5
2017-09-11 CVE-2017-7650 Improper Authentication vulnerability in multiple products
In Mosquitto before 1.4.12, pattern based ACLs can be bypassed by clients that set their username/client id to '#' or '+'.
network
low complexity
eclipse debian CWE-287
6.5
2017-06-25 CVE-2017-9868 Information Exposure vulnerability in multiple products
In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information.
local
low complexity
eclipse debian CWE-200
5.5