Vulnerabilidades em Eclipse Foundation

170 resultados
Análise Vexday

Com 104 CVEs catalogadas e nenhuma entrada no catálogo CISA KEV, o Eclipse Foundation apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que sugere menor pressão imediata de ameaças confirmadas em ambiente real. Ainda assim, 9 vulnerabilidades de severidade crítica e 16 surgidas nos últimos 90 dias indicam ritmo de descoberta que exige atenção contínua. O CVE-2024-10525 se destaca como a falha de maior risco ativo, com escore EPSS de 0,579 — valor que aponta probabilidade relevante de exploração a curto prazo e deve ser tratado com prioridade nos ciclos de correção. A predominância de CWE-125 (leitura fora dos limites do buffer) como tipo de falha mais frequente sinaliza que revisões de segurança de memória em componentes nativos merecem atenção estrutural no processo de desenvolvimento.

CVE-2025-55095MEDIUMThe function _ux_host_class_storage_media_mount() is responsible for mounting partitions on a USB mass storage device. When it encounters anEPSS 0.1%CVE-2026-82955CRITICALIn the current development version of Eclipse aeriOS, which has not yet had an official release, the KrakenD instance included in the API GaEPSS 0.1%CVE-2025-55080HIGHImproper Parameter Check in ThreadX Syscall ImplementationEPSS 0.1%CVE-2026-19884HIGHIn Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiring the user to trustEPSS 0.1%CVE-2026-88819MEDIUMIn Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.EPSS 0.1%CVE-2026-84173HIGHIn Eclipse Ankaios versions v0.5.1 through v1.0.1, the agent-side Control Interface authorizer incorrectly evaluates multi-segment allow rulEPSS 0.1%CVE-2026-85201MEDIUMIn Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-delimited protobuf mEPSS 0.1%CVE-2026-0648HIGHThe vulnerability stems from an incorrect error-checking logic in the CreateCounter() function (in threadx/utility/rtos_compatibility_layersEPSS 0.1%CVE-2026-86836HIGHIn Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIFOs) under a predictaEPSS 0.1%CVE-2026-90882HIGHReflected arbitrary origins with credentials, allowing cross-origin reads of authenticated user dataEPSS