Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
359 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 0.72% | — | Diffplug Eclipse-cdtDiffplug Eclipse-groovyDiffplug Eclipse-wtp | 5/9/2019 | 17/6/2026 | In all versions prior to version 3.9.6 for eclipse-wtp, all versions prior to version 9.4.4 for eclipse-cdt, and all versions prior to version 3.0.1 for eclipse-groovy, Spotless was resolving dependencies over an insecure channel (http). If the build occurred over an insecure connection, a malicious user could have… | |
| Modificada | Media (6.1) | 0.90% | — | Eclipse Business Intelligence AND Reporting Tools | 9/8/2019 | 17/6/2026 | In Eclipse BIRT versions 1.0 to 4.7, the Report Viewer allows Reflected XSS in URL parameter. Attacker can execute the payload in victim's browser context. | |
| Modificada | Alta (7.4) | 1.5% | — | Eclipse Openj9Redhat SatelliteRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 30/7/2019 | 17/6/2026 | All builds of Eclipse OpenJ9 prior to 0.15 contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by versioning - for example if there is a condition that is moved out of the loop that reads a field we may not privatize the value of that field in the modified copy of the… | |
| Modificada | Crítica (9.8) | 2.1% | — | Eclipse Openj9 | 17/7/2019 | 17/6/2026 | In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that the provided index is in bounds when compiled by the JIT. This allows arbitrary writes to any 32-bit address or beyond the end of a byte array within Java code run under… | |
| Modificada | Alta (7.8) | 0.39% | — | Eclipse Openj9 | 17/7/2019 | 17/6/2026 | AIX builds of Eclipse OpenJ9 before 0.15.0 contain unused RPATHs which may facilitate code injection and privilege elevation by local users. | |
| Modificada | Alta (8.1) | 1.3% | — | Eclipse Buildship | 14/6/2019 | 17/6/2026 | In Eclipse Buildship versions prior to 3.1.1, the build files indicate that this project is resolving dependencies over HTTP instead of HTTPS. Any of these artifacts could have been MITM to maliciously compromise them and infect the build artifacts that were produced. Additionally, if any of these JARs or other… | |
| Modificada | Alta (8.1) | 0.65% | — | Eclipse XtendEclipse Xtext | 6/5/2019 | 17/6/2026 | All Xtext & Xtend versions prior to 2.18.0 were built using HTTP instead of HTTPS file transfer and thus the built artifacts may have been compromised. | |
| Modificada | Alta (8.1) | 0.43% | — | Eclipse Vorto | 22/4/2019 | 17/6/2026 | Eclipse Vorto versions prior to 0.11 resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by a MITM attack. Hence produced build artifacts of Vorto might be infected. | |
| Modificada | Media (5.3) | 5.9% | — | Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkNetapp Snapcenter+22 | 22/4/2019 | 17/6/2026 | In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version combination will reveal the configured fully qualified directory base resource location on the output of the 404 error for not finding a Context that matches the requested path.… | |
| Modificada | Media (5.3) | 4.1% | — | Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkNetapp Snapcenter+21 | 22/4/2019 | 17/6/2026 | In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base Resource directory name on Windows to a remote client when it is configured for showing a Listing of directory contents. This information reveal is restricted to only the content in… | |
| Modificada | Media (6.1) | 9.4% | — | Eclipse JettyDebian LinuxApache ActivemqApache Drill+3 | 22/4/2019 | 17/6/2026 | In Eclipse Jetty version 9.2.26 and older, 9.3.25 and older, and 9.4.15 and older, the server is vulnerable to XSS conditions if a remote client USES a specially formatted URL against the DefaultServlet or ResourceHandler that is configured for showing a Listing of directory contents. | |
| Modificada | Alta (7.5) | 2.5% | — | Eclipse Openj9Redhat SatelliteRedhat Enterprise LinuxRedhat Enterprise Linux Desktop+2 | 19/4/2019 | 17/6/2026 | In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causing crashes. Eclipse OpenJ9 v0.14.0 correctly detects this case and rejects the attempted class load. | |
| Modificada | Alta (7.5) | 1.8% | — | Eclipse Kura | 9/4/2019 | 17/6/2026 | In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service (not part of the device distribution) could potentially be target of XXE attack due to an improper factory and parser initialisation. | |
| Modificada | Media (5.3) | 1.3% | — | Eclipse Kura | 9/4/2019 | 17/6/2026 | In Eclipse Kura versions up to 4.0.0, Kura exposes the underlying Ui Web server version in its replies. This can be used as a hint by an attacker to specifically craft attacks to the web server run by Kura. | |
| Modificada | Media (5.3) | 2.0% | — | Eclipse Kura | 9/4/2019 | 17/6/2026 | In Eclipse Kura versions up to 4.0.0, the SkinServlet did not checked the path passed during servlet call, potentially allowing path traversal in get requests for a limited number of file types. | |
| Modificada | Alta (8.1) | 0.43% | — | Eclipse Hawkbit | 3/4/2019 | 17/6/2026 | Eclipse hawkBit versions prior to 0.3.0M2 resolved Maven build artifacts for the Vaadin based UI over HTTP instead of HTTPS. Any of these dependent artifacts could have been maliciously compromised by a MITM attack. Hence produced build artifacts of hawkBit might be infected. | |
| Modificada | Alta (7.5) | 5.1% | — | Eclipse JettyFedoraproject Fedora | 27/3/2019 | 17/6/2026 | In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs frames container containing many settings, or many small SETTINGs frames. The vulnerability is due to the additional CPU and memory allocations required to handle changed… | |
| Modificada | Alta (7.5) | 1.8% | — | Eclipse MosquittoDebian Linux | 27/3/2019 | 17/6/2026 | In Eclipse Mosquitto version from 1.0 to 1.4.15, a Null Dereference vulnerability was found in the Mosquitto library which could lead to crashes for those applications using the library. | |
| Modificada | Alta (8.1) | 1.5% | — | Eclipse Mosquitto | 27/3/2019 | 17/6/2026 | When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use a password file for authentication, any malformed data in the password file will be treated as valid. This typically means that the malformed data becomes a username and no password. If this occurs, clients can circumvent authentication and… | |
| Modificada | Alta (8.1) | 1.4% | — | Eclipse Mosquitto | 27/3/2019 | 17/6/2026 | When Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) is configured to use an ACL file, and that ACL file is empty, or contains only comments or blank lines, then Mosquitto will treat this as though no ACL file has been defined and use a default allow policy. The new behaviour is to have an empty ACL file mean that… | |
| Modificada | Media (6.5) | 0.80% | — | Eclipse Mosquitto | 27/3/2019 | 17/6/2026 | In Eclipse Mosquitto version 1.0 to 1.5.5 (inclusive) when a client publishes a retained message to a topic, then has its access to that topic revoked, the retained message will still be published to clients that subscribe to that topic in the future. In some applications this may result in clients being able cause… | |
| Modificada | Alta (7.5) | 1.5% | — | Eclipse Wakaama | 22/2/2019 | 17/6/2026 | In Eclipse Wakaama (formerly liblwm2m) 1.0, core/er-coap-13/er-coap-13.c in lwm2mserver in the LWM2M server mishandles invalid options, leading to a memory leak. Processing of a single crafted packet leads to leaking (wasting) 24 bytes of memory. This can lead to termination of the LWM2M server after exhausting all… | |
| Modificada | Crítica (9.8) | 2.3% | — | Eclipse Openj9Redhat SatelliteRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 11/2/2019 | 17/6/2026 | In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when accelerating it. | |
| Modificada | Crítica (9.8) | 2.7% | — | Eclipse Openj9Redhat SatelliteRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+1 | 11/2/2019 | 17/6/2026 | In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects existing APIs that called the functions to exceed the allocated buffer. This functions were not directly callable by non-native user code. | |
| Modificada | Crítica (9.8) | 1.1% | — | Eclipse Openj9 | 31/1/2019 | 17/6/2026 | In OpenJDK + Eclipse OpenJ9 version 0.11.0 builds, the public jdk.crypto.jniprovider.NativeCrypto class contains public static natives which accept pointer values that are dereferenced in the native code. |