Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
eclipse vulnerabilities and exploits
(subscribe to this query)
8.5
CVSSv2
CVE-2019-17634
Eclipse Memory Analyzer version 1.9.1 and previous versions is subject to a cross site scripting (XSS) vulnerability when generating an HTML report from a malicious heap dump. The user must chose todownload, open the malicious heap dump and generate an HTML report for the problem...
Eclipse Memory Analyzer
6.4
CVSSv2
CVE-2018-20227
RDF4J 2.4.2 allows Directory Traversal via ../ in an entry in a ZIP archive.
Eclipse Rdf4j 2.4.2
6.8
CVSSv2
CVE-2019-17635
Eclipse Memory Analyzer version 1.9.1 and previous versions is subject to a deserialization vulnerability if an index file of a parsed heap dump is replaced by a malicious version and the heap dump is reopened in Memory Analyzer. The user must chose to reopen an already parsed he...
Eclipse Memory Analyzer
7.5
CVSSv2
CVE-2018-12548
In OpenJDK + Eclipse OpenJ9 version 0.11.0 builds, the public jdk.crypto.jniprovider.NativeCrypto class contains public static natives which accept pointer values that are dereferenced in the native code.
Eclipse Openj9 0.11.0
NA
CVE-2023-6194
In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit document type definition (DTD) references to external entities. This means that if a user chooses to use a malicious report definition XML file containing an external entit...
Eclipse Memory Analyzer
5
CVSSv2
CVE-2019-9004
In Eclipse Wakaama (formerly liblwm2m) 1.0, core/er-coap-13/er-coap-13.c in lwm2mserver in the LWM2M server mishandles invalid options, leading to a memory leak. Processing of a single crafted packet leads to leaking (wasting) 24 bytes of memory. This can lead to termination of t...
Eclipse Wakaama 1.0
5 Github repositories
7.8
CVSSv2
CVE-2017-8315
Eclipse XML parser for the Eclipse IDE versions 2017.2.5 and previous versions was found vulnerable to an XML External Entity attack. An attacker can exploit the vulnerability by implementing malicious code on Androidmanifest.xml.
Eclipse Ide 2017.2.5
6.8
CVSSv2
CVE-2021-41037
In Eclipse p2, installable units are able to alter the Eclipse Platform installation and the local machine via touchpoints during installation. Those touchpoints can, for example, alter the command-line used to start the application, injecting things like agent or other settings ...
Eclipse Equinox P2
5
CVSSv2
CVE-2021-41040
In Eclipse Wakaama, ever since its inception until 2021-01-14, the CoAP parsing code does not properly sanitize network-received data.
Eclipse Wakaama 1.0
4 Github repositories
5
CVSSv2
CVE-2017-7243
Eclipse tinydtls 0.8.2 for Eclipse IoT allows remote malicious users to cause a denial of service (DTLS peer crash) by sending a "Change cipher spec" packet without pre-handshake.
Eclipse Tinydtls 0.8.2
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-6267
XML injection
CVE-2024-37673
CVE-2024-6266
CVE-2024-30078
arbitrary
CVE-2024-36886
CVE-2024-5346
template injection
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
5
6
7
8
9
10
NEXT »