eclipse security advisories
16 threat alerts tracking vulnerabilities and security advisories that affect eclipse products.
Vulnios monitors eclipse CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent eclipse security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2020-27221 — eclipse — openj9
In Eclipse OpenJ9 up to and including version 0.23, there is potential for a stack-based buffer overflow when the virtual machine or JNI natives are converting from UTF-8 characters to platform encodi
criticalCVE-2020-27221Critical Vulnerability: CVE-2019-17640 — eclipse — vert.x
In Eclipse Vert.x 3.4.x up to 3.9.4, 4.0.0.milestone1, 4.0.0.milestone2, 4.0.0.milestone3, 4.0.0.milestone4, 4.0.0.milestone5, 4.0.0.Beta1, 4.0.0.Beta2, and 4.0.0.Beta3, StaticHandler doesn't correctl
criticalCVE-2019-17640Critical Vulnerability: CVE-2019-17638 — eclipse — jetty
In Eclipse Jetty, versions 9.4.27.v20200227 to 9.4.29.v20200521, in case of too large response headers, Jetty throws an exception to produce an HTTP 431 error. When this happens, the ByteBuffer contai
criticalCVE-2019-17638Critical Vulnerability: CVE-2019-17634 — eclipse — memory_analyzer
Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a cross site scripting (XSS) vulnerability when generating an HTML report from a malicious heap dump. The user must chose todownload, op
criticalCVE-2019-17634Critical Vulnerability: CVE-2019-17631 — eclipse, redhat — openj9, satellite
From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privilege checks.
criticalCVE-2019-17631Critical Vulnerability: CVE-2019-11772 — eclipse — openj9
In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that the provided index is in bounds when compiled by th
criticalCVE-2019-11772Critical Vulnerability: CVE-2018-12547 — eclipse, redhat — openj9, satellite
In Eclipse OpenJ9, prior to the 0.12.0 release, the jio_snprintf() and jio_vsnprintf() native methods ignored the length parameter. This affects existing APIs that called the functions to exceed the a
criticalCVE-2018-12547Critical Vulnerability: CVE-2018-12549 — eclipse, redhat — openj9, satellite
In Eclipse OpenJ9 version 0.11.0, the OpenJ9 JIT compiler may incorrectly omit a null check on the receiver object of an Unsafe call when accelerating it.
criticalCVE-2018-12549Critical Vulnerability: CVE-2018-12548 — eclipse — openj9
In OpenJDK + Eclipse OpenJ9 version 0.11.0 builds, the public jdk.crypto.jniprovider.NativeCrypto class contains public static natives which accept pointer values that are dereferenced in the native c
criticalCVE-2018-12548Critical Vulnerability: CVE-2018-12544 — eclipse — vert.x
In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense against XML attacks. This mechanism is exclusively when the
criticalCVE-2018-12544Critical Vulnerability: CVE-2018-12542 — eclipse, microsoft — vert.x, windows
In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '\' (f
criticalCVE-2018-12542Critical Vulnerability: CVE-2018-1000644 — eclipse — rdf4j
Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External Entity (XXE) vulnerability in RDF4j XML parser parsing RDF files that can result in the disclosure of confidential data, denial of ser
criticalCVE-2018-1000644Critical Vulnerability: CVE-2017-7657 — eclipse, debian — jetty, debian_linux
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), transfer-encoding chunks are handled poorly. The chunk le
criticalCVE-2017-7657Critical Vulnerability: CVE-2017-7658 — eclipse, debian — jetty, debian_linux
In Eclipse Jetty Server, versions 9.2.x and older, 9.3.x (all non HTTP/1.x configurations), and 9.4.x (all HTTP/1.x configurations), when presented with two content-lengths headers, Jetty ignored the
criticalCVE-2017-7658Critical Vulnerability: CVE-2017-7649 — eclipse — kura
The network enabled distribution of Kura before 2.1.0 takes control over the device's firewall setup but does not allow IPv6 firewall rules to be configured. Still the Equinox console port 5002 is lef
criticalCVE-2017-7649Critical Vulnerability: CVE-2016-4800 — eclipse, microsoft — jetty, windows
The path normalization mechanism in PathResource class in Eclipse Jetty 9.3.x before 9.3.9 on Windows allows remote attackers to bypass protected resource restrictions and other security constraints v
criticalCVE-2016-4800
Track eclipse exposure across your environment
Vulnios automatically cross-references your asset inventory against new eclipse CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan