Loading HuntDB...

The Eclipse Foundation

30 Products 100 CVEs

CVE Severity Distribution (All Time)

Critical
1
High
3
Medium
7
Low
3

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 0 CVEs

Recent CVEs

View all
CVE-2023-0100 UNKNOWN 2 years, 8 months ago

In Eclipse BIRT, starting from version 2.6.2, the default configuration allowed to retrieve a report from the same host using an absolute HTTP path f…

CVE-2022-2712 MEDIUM 2 years, 9 months ago

In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting wi…

CVE-2022-3676 UNKNOWN 3 years, 1 month ago

In Eclipse Openj9 before version 0.35.0, interface calls can be inlined without a runtime type check. Malicious bytecode could make use of this inlin…

CVE-2022-2838 UNKNOWN 3 years, 3 months ago

In Eclipse Sphinx™ before version 0.13.1, Apache Xerces XML Parser was used without disabling processing of referenced external entities allowing the…

CVE-2022-2576 UNKNOWN 3 years, 3 months ago

In Eclipse Californium version 2.0.0 to 2.7.2 and 3.0.0-3.5.0 a DTLS resumption handshake falls back to a DTLS full handshake on a parameter mismatch…

CVE-2021-41037 CRITICAL 3 years, 4 months ago

In Eclipse p2, installable units are able to alter the Eclipse Platform installation and the local machine via touchpoints during installation. Those…

CVE-2021-41042 UNKNOWN 3 years, 4 months ago

In Eclipse Lyo versions 1.0.0 to 4.1.0, a TransformerFactory is initialized with the defaults that do not restrict DTD loading when working with RDF/…

CVE-2022-2191 HIGH 3 years, 4 months ago

In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffers from configured ByteBufferP…

CVE-2022-2047 LOW 3 years, 4 months ago

In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http…

CVE-2022-2048 HIGH 3 years, 4 months ago

In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properl…