VUMETRIC
CYBER PORTAL
Dashboard
Security News
Latest Vulnerabilities
Browse Vulnerabilities
by Vendors
by Products
by Categories
Weekly Reports
Vulnerabilities
>
Eclipse
> Medium
Exclude new CVEs:
DATE
CVE
VULNERABILITY TITLE
RISK
2018-06-27
CVE-2018-12536
In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't match a dynamic url-pattern, and is eventually handled by the DefaultServlet's static file serving, the bad characters can trigger a java.nio.file.InvalidPathException which includes the full path to the base resource directory that the DefaultServlet and/or webapp is using.
network
low complexity
eclipse
oracle
5.3
5.3
2018-06-05
CVE-2017-7653
Improper Input Validation vulnerability in multiple products
The Eclipse Mosquitto broker up to version 1.4.15 does not reject strings that are not valid UTF-8.
network
high complexity
eclipse
debian
CWE-20
5.3
5.3
2017-09-11
CVE-2017-7650
Improper Authentication vulnerability in multiple products
In Mosquitto before 1.4.12, pattern based ACLs can be bypassed by clients that set their username/client id to '#' or '+'.
network
low complexity
eclipse
debian
CWE-287
6.5
6.5
2017-06-25
CVE-2017-9868
Information Exposure vulnerability in multiple products
In Mosquitto through 1.4.12, mosquitto.db (aka the persistence file) is world readable, which allows local users to obtain sensitive MQTT topic information.
local
low complexity
eclipse
debian
CWE-200
5.5
5.5
«
Previous
1
2
...
3
4
5
6
7
(current)
»