Vulnerabilities > Eclipse > Mosquitto > High

DATE CVE VULNERABILITY TITLE RISK
2018-11-15 CVE-2018-12543 Improper Input Validation vulnerability in Eclipse Mosquitto 1.5.1/1.5.2
In Eclipse Mosquitto versions 1.5 to 1.5.2 inclusive, if a message is published to Mosquitto that has a topic starting with $, but that is not $SYS, e.g.
network
low complexity
eclipse CWE-20
7.5
2018-06-05 CVE-2017-7654 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
In Eclipse Mosquitto 1.4.15 and earlier, a Memory Leak vulnerability was found within the Mosquitto Broker.
network
low complexity
eclipse debian CWE-772
7.5
2018-04-25 CVE-2017-7652 In Eclipse Mosquitto 1.4.14, if a Mosquitto instance is set running with a configuration file, then sending a HUP signal to server triggers the configuration to be reloaded from disk.
network
high complexity
eclipse debian
7.5
2018-04-24 CVE-2017-7651 Resource Exhaustion vulnerability in multiple products
In Eclipse Mosquitto 1.4.14, a user can shutdown the Mosquitto server simply by filling the RAM memory with a lot of connections with large payload.
network
low complexity
eclipse debian CWE-400
7.5