Show filters
563 Total Results
Displaying 241-250 of 563
Sort by:
Attacker Value
Unknown
CVE-2020-18735
Disclosure Date: August 23, 2021 (last updated February 23, 2025)
A heap buffer overflow in /src/dds_stream.c of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.
0
Attacker Value
Unknown
CVE-2020-18734
Disclosure Date: August 23, 2021 (last updated February 23, 2025)
A stack buffer overflow in /ddsi/q_bitset.h of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.
0
Attacker Value
Unknown
CVE-2021-34433
Disclosure Date: August 20, 2021 (last updated February 23, 2025)
In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally succeeds without verifying the server side's signature on the client side, if that signature is not included in the server's ServerKeyExchange.
0
Attacker Value
Unknown
CVE-2021-34432
Disclosure Date: July 27, 2021 (last updated February 23, 2025)
In Eclipse Mosquitto versions 2.07 and earlier, the server will crash if the client tries to send a PUBLISH packet with topic length = 0.
0
Attacker Value
Unknown
CVE-2021-34431
Disclosure Date: July 22, 2021 (last updated February 23, 2025)
In Eclipse Mosquitto version 1.6 to 2.0.10, if an authenticated client that had connected with MQTT v5 sent a crafted CONNECT message to the broker a memory leak would occur, which could be used to provide a DoS attack against the broker.
0
Attacker Value
Unknown
CVE-2021-34429
Disclosure Date: July 15, 2021 (last updated February 23, 2025)
For Eclipse Jetty versions 9.4.37-9.4.42, 10.0.1-10.0.5 & 11.0.1-11.0.5, URIs can be crafted using some encoded characters to access the content of the WEB-INF directory and/or bypass some security constraints. This is a variation of the vulnerability reported in CVE-2021-28164/GHSA-v7ff-8wcx-gmc5.
0
Attacker Value
Unknown
CVE-2021-34430
Disclosure Date: July 08, 2021 (last updated February 23, 2025)
Eclipse TinyDTLS through 0.9-rc1 relies on the rand function in the C library, which makes it easier for remote attackers to compute the master key and then decrypt DTLS traffic.
0
Attacker Value
Unknown
CVE-2021-34427
Disclosure Date: June 25, 2021 (last updated February 22, 2025)
In Eclipse BIRT versions 4.8.0 and earlier, an attacker can use query parameters to create a JSP file which is accessible from remote (current BIRT viewer dir) to inject JSP code into the running instance.
0
Attacker Value
Unknown
CVE-2021-34428
Disclosure Date: June 22, 2021 (last updated February 22, 2025)
For Eclipse Jetty versions <= 9.4.40, <= 10.0.2, <= 11.0.2, if an exception is thrown from the SessionListener#sessionDestroyed() method, then the session ID is not invalidated in the session ID manager. On deployments with clustered sessions and multiple contexts this can result in a session not being invalidated. This can result in an application used on a shared computer being left logged in.
0
Attacker Value
Unknown
CVE-2020-20444
Disclosure Date: June 16, 2021 (last updated February 22, 2025)
Jact OpenClinic 0.8.20160412 allows the attacker to read server files after login to the the admin account by an infected 'file' GET parameter in '/shared/view_source.php' which "could" lead to RCE vulnerability .
0