Vulnerabilidades en Eclipse Foundation

170 resultados
Análisis Vexday

Com 104 CVEs catalogadas e nenhuma entrada no catálogo CISA KEV, o Eclipse Foundation apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão imediata de ameaças confirmadas em ambiente real. Ainda assim, 9 vulnerabilidades de severidade crítica e 16 surgidas nos últimos 90 dias indicam ritmo de descoberta que exige atenção contínua. O CVE-2024-10525 se destaca como a falha de maior risco ativo, com escore EPSS de 0,579 — valor que aponta probabilidade relevante de exploração a curto prazo e deve ser tratado com prioridade nos ciclos de correção. A predominância de CWE-125 (leitura fora dos limites do buffer) como tipo de falha mais frequente sinaliza que revisões de segurança de memória em componentes nativos merecem atenção estrutural no processo de desenvolvimento.

CVE-2023-2597HIGHIn Eclipse Openj9 before version 0.38.0, in the implementation of the shared cache (which is enabled by default in OpenJ9 builds) the size oEPSS 0.4%CVE-2026-63252HIGHIn Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel EPSS 0.4%CVE-2024-10917LOWEclipse OpenJ9 might return an incorrect value in JNI function GetStringUTFLengthEPSS 0.4%CVE-2025-55086MEDIUMIn NetXDuo version before 6.4.4, a networking support module for Eclipse Foundation ThreadX, in the DHCPV6 client there was an unchecked indEPSS 0.4%CVE-2024-4536MEDIUMEclipse EDC: OAuth2 Credential Exfiltration VulnerabilityEPSS 0.4%CVE-2025-55094MEDIUMPotential out-of-bounds read in _nx_icmpv6_validate_options()EPSS 0.4%CVE-2023-5676MEDIUMEclipse OpenJ9 possible infinite busy hangEPSS 0.4%CVE-2026-12609HIGHIn Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/hostedPlugin/:pluginId/:path(*EPSS 0.4%CVE-2026-44691HIGHIn Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be EPSS 0.4%CVE-2024-8642MEDIUMEclipse EDC: Consumer pull transfer token validation checks not appliedEPSS 0.4%CVE-2024-9342MEDIUMIn Eclipse GlassFish versions before 8.0.3 it is possible to perform Login Brute Force attacks as there is no limitation in the number of faEPSS 0.4%CVE-2025-12999CRITICALUrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwarded-Host, X-ForwardEPSS 0.4%CVE-2026-22886CRITICALOpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires authentication. However, the product ships with a defaulEPSS 0.4%CVE-2026-10055HIGHIn Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connecteEPSS 0.4%CVE-2026-13699MEDIUMDatabroker 0.6.1 PublishValue missing data_point panicEPSS 0.4%CVE-2023-4218MEDIUMXXE in eclipse.platform / Eclipse IDEEPSS 0.4%CVE-2024-8646MEDIUMEclipse Glassfish: URL redirection vulnerability to untrusted sitesEPSS 0.4%CVE-2026-60007CRITICALIn Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding aEPSS 0.4%CVE-2025-55102HIGHA denial-of-service vulnerability exists in the NetX IPv6 component functionality of Eclipse ThreadX NetX Duo. A specially crafted network pEPSS 0.4%CVE-2026-82217HIGHIn Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI "Agent Mode" file-change tools (writeFileContent, suggestFileContentEPSS 0.4%