Vulnerabilities > Eclipse > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-04-09 CVE-2019-10243 Information Exposure vulnerability in Eclipse Kura
In Eclipse Kura versions up to 4.0.0, Kura exposes the underlying Ui Web server version in its replies.
network
low complexity
eclipse CWE-200
5.3
2019-04-09 CVE-2019-10242 Path Traversal vulnerability in Eclipse Kura
In Eclipse Kura versions up to 4.0.0, the SkinServlet did not checked the path passed during servlet call, potentially allowing path traversal in get requests for a limited number of file types.
network
low complexity
eclipse CWE-22
5.3
2019-03-27 CVE-2018-12546 Incorrect Permission Assignment for Critical Resource vulnerability in Eclipse Mosquitto
In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a retained message to a topic, then has its access to that topic revoked, the retained message will still be published to clients that subscribe to that topic in the future.
network
low complexity
eclipse CWE-732
6.5
2018-10-10 CVE-2018-12541 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Eclipse Vert.X
In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the WebSocket HTTP upgrade implementation buffers the full http request before doing the handshake, holding the entire request body in memory.
network
low complexity
eclipse CWE-119
6.5
2018-08-14 CVE-2018-12537 Improper Input Validation vulnerability in Eclipse Vert.X
In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value.
network
low complexity
eclipse CWE-20
5.3
2018-06-27 CVE-2018-12536 In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't match a dynamic url-pattern, and is eventually handled by the DefaultServlet's static file serving, the bad characters can trigger a java.nio.file.InvalidPathException which includes the full path to the base resource directory that the DefaultServlet and/or webapp is using.
network
low complexity
eclipse oracle
5.3
2018-06-05 CVE-2017-7653 Improper Input Validation vulnerability in multiple products
The Eclipse Mosquitto broker up to version 1.4.15 does not reject strings that are not valid UTF-8.
network
high complexity
eclipse debian CWE-20
5.3
2017-09-11 CVE-2017-7650 Improper Authentication vulnerability in multiple products
In Mosquitto before 1.4.12, pattern based ACLs can be bypassed by clients that set their username/client id to '#' or '+'.
network
low complexity
eclipse debian CWE-287
6.5
2017-06-25 CVE-2017-9868 Information Exposure vulnerability in multiple products
In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information.
local
low complexity
eclipse debian CWE-200
5.5