Vulnerabilities > Eclipse

DATE CVE VULNERABILITY TITLE RISK
2023-02-09 CVE-2023-24815 Unspecified vulnerability in Eclipse Vert.X-Web
Vert.x-Web is a set of building blocks for building web applications in the java programming language.
network
low complexity
eclipse
5.3
2023-01-27 CVE-2022-2712 Path Traversal vulnerability in Eclipse Glassfish 5.1.0/6.0.0/6.2.5
In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'.
network
low complexity
eclipse CWE-22
7.5
2022-11-10 CVE-2022-36022 Use of Insufficiently Random Values vulnerability in Eclipse Deeplearning4J
Deeplearning4J is a suite of tools for deploying and training deep learning models using the JVM.
network
low complexity
eclipse CWE-330
5.3
2022-11-10 CVE-2022-39368 Incomplete Cleanup vulnerability in Eclipse Californium
Eclipse Californium is a Java implementation of RFC7252 - Constrained Application Protocol for IoT Cloud services.
network
low complexity
eclipse CWE-459
8.2
2022-10-24 CVE-2022-3676 Type Confusion vulnerability in Eclipse Openj9
In Eclipse Openj9 before version 0.35.0, interface calls can be inlined without a runtime type check.
network
low complexity
eclipse CWE-843
6.5
2022-09-08 CVE-2022-25897 Allocation of Resources Without Limits or Throttling vulnerability in Eclipse Milo
The package org.eclipse.milo:sdk-server before 0.6.8 are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.
network
low complexity
eclipse CWE-770
7.5
2022-08-16 CVE-2022-2838 XXE vulnerability in Eclipse Sphinx
In Eclipse Sphinx™ before version 0.13.1, Apache Xerces XML Parser was used without disabling processing of referenced external entities allowing the injection of arbitrary definitions which is able to access local files and expose their contents via HTTP requests.
network
low complexity
eclipse CWE-611
5.3
2022-07-29 CVE-2022-2576 Unspecified vulnerability in Eclipse Californium
In Eclipse Californium version 2.0.0 to 2.7.2 and 3.0.0-3.5.0 a DTLS resumption handshake falls back to a DTLS full handshake on a parameter mismatch without using a HelloVerifyRequest.
network
low complexity
eclipse
7.5
2022-07-18 CVE-2015-8031 XXE vulnerability in Eclipse Hudson
Hudson (aka org.jvnet.hudson.main:hudson-core) before 3.3.2 allows XXE attacks.
network
low complexity
eclipse CWE-611
critical
9.8
2022-07-08 CVE-2021-41037 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Eclipse Equinox P2
In Eclipse p2, installable units are able to alter the Eclipse Platform installation and the local machine via touchpoints during installation.
network
low complexity
eclipse CWE-829
8.0