Vulnerabilities > Eclipse > High

DATE CVE VULNERABILITY TITLE RISK
2021-08-23 CVE-2020-18734 Out-of-bounds Write vulnerability in Eclipse Cyclone Data Distribution Service 0.1.0
A stack buffer overflow in /ddsi/q_bitset.h of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.
network
low complexity
eclipse CWE-787
7.5
2021-08-23 CVE-2020-18735 Out-of-bounds Write vulnerability in Eclipse Cyclone Data Distribution Service 0.1.0
A heap buffer overflow in /src/dds_stream.c of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.
network
low complexity
eclipse CWE-787
7.5
2021-08-20 CVE-2021-34433 Improper Verification of Cryptographic Signature vulnerability in Eclipse Californium
In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally succeeds without verifying the server side's signature on the client side, if that signature is not included in the server's ServerKeyExchange.
network
low complexity
eclipse CWE-347
7.5
2021-07-27 CVE-2021-34432 Unspecified vulnerability in Eclipse Mosquitto
In Eclipse Mosquitto versions 2.07 and earlier, the server will crash if the client tries to send a PUBLISH packet with topic length = 0.
network
low complexity
eclipse
7.5
2021-07-08 CVE-2021-34430 Inadequate Encryption Strength vulnerability in Eclipse Tinydtls 0.8.1/0.8.2/0.9
Eclipse TinyDTLS through 0.9-rc1 relies on the rand function in the C library, which makes it easier for remote attackers to compute the master key and then decrypt DTLS traffic.
network
low complexity
eclipse CWE-326
7.5
2021-04-01 CVE-2021-28165 Improper Handling of Exceptional Conditions vulnerability in multiple products
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.
network
low complexity
eclipse oracle jenkins netapp CWE-755
7.5
2021-03-09 CVE-2020-27225 Missing Authentication for Critical Function vulnerability in Eclipse Platform
In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to the local help web server, allowing an unauthenticated local attacker to issue active help commands to the associated Eclipse Platform process or Eclipse Rich Client Platform process.
local
low complexity
eclipse CWE-306
7.8
2021-02-03 CVE-2020-27222 Unspecified vulnerability in Eclipse Californium
In Eclipse Californium version 2.3.0 to 2.6.0, the certificate based (x509 and RPK) DTLS handshakes accidentally fails, because the DTLS server side sticks to a wrong internal state.
network
low complexity
eclipse
7.5
2021-01-20 CVE-2020-35217 Cross-Site Request Forgery (CSRF) vulnerability in Eclipse Vert.X-Web 4.0.0
Vert.x-Web framework v4.0 milestone 1-4 does not perform a correct CSRF verification.
network
low complexity
eclipse CWE-352
8.8
2021-01-14 CVE-2020-27220 Missing Authorization vulnerability in Eclipse Hono
The Eclipse Hono AMQP and MQTT protocol adapters do not check whether an authenticated gateway device is authorized to receive command & control messages when it has subscribed only to commands for a specific device.
network
low complexity
eclipse CWE-862
8.8