Vulnerabilities > Eclipse > High

DATE CVE VULNERABILITY TITLE RISK
2019-09-12 CVE-2019-11773 Uncontrolled Search Path Element vulnerability in Eclipse OMR
Prior to 0.1, AIX builds of Eclipse OMR contain unused RPATHs which may facilitate code injection and privilege elevation by local users.
local
low complexity
eclipse CWE-427
7.8
2019-09-11 CVE-2019-11777 Improper Handling of Exceptional Conditions vulnerability in Eclipse Paho Java Client 1.2.0
In the Eclipse Paho Java client library version 1.2.0, when connecting to an MQTT server using TLS and setting a host name verifier, the result of that verification is not checked.
network
low complexity
eclipse CWE-755
7.5
2019-07-30 CVE-2019-11775 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in multiple products
All builds of Eclipse OpenJ9 prior to 0.15 contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by versioning - for example if there is a condition that is moved out of the loop that reads a field we may not privatize the value of that field in the modified copy of the loop allowing the test to see one value of the field and subsequently the loop to see a modified field value without retesting the condition moved out of the loop.
network
high complexity
eclipse redhat CWE-367
7.4
2019-07-17 CVE-2019-11771 Permissions, Privileges, and Access Controls vulnerability in Eclipse Openj9
AIX builds of Eclipse OpenJ9 before 0.15.0 contain unused RPATHs which may facilitate code injection and privilege elevation by local users.
local
low complexity
eclipse CWE-264
7.8
2019-06-14 CVE-2019-11770 Incorrect Resource Transfer Between Spheres vulnerability in Eclipse Buildship
In Eclipse Buildship versions prior to 3.1.1, the build files indicate that this project is resolving dependencies over HTTP instead of HTTPS.
network
high complexity
eclipse CWE-669
8.1
2019-05-06 CVE-2019-10249 Improper Encoding or Escaping of Output vulnerability in Eclipse Xtend and Xtext
All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artifacts may have been compromised.
network
high complexity
eclipse CWE-116
8.1
2019-04-22 CVE-2019-10248 Incorrect Resource Transfer Between Spheres vulnerability in Eclipse Vorto
Eclipse Vorto versions prior to 0.11 resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS.
network
high complexity
eclipse CWE-669
8.1
2019-04-19 CVE-2019-10245 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causing crashes.
network
low complexity
eclipse redhat CWE-119
7.5
2019-04-09 CVE-2019-10244 XXE vulnerability in Eclipse Kura
In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service (not part of the device distribution) could potentially be target of XXE attack due to an improper factory and parser initialisation.
network
low complexity
eclipse CWE-611
7.5
2019-04-03 CVE-2019-10240 Cleartext Transmission of Sensitive Information vulnerability in Eclipse Hawkbit
Eclipse hawkBit versions prior to 0.3.0M2 resolved Maven build artifacts for the Vaadin based UI over HTTP instead of HTTPS.
network
high complexity
eclipse CWE-319
8.1