Show filters
563 Total Results
Displaying 291-300 of 563
Sort by:
Attacker Value
Unknown
CVE-2021-28165
Disclosure Date: April 01, 2021 (last updated February 22, 2025)
In Eclipse Jetty 7.2.2 to 9.4.38, 10.0.0.alpha0 to 10.0.1, and 11.0.0.alpha0 to 11.0.1, CPU usage can reach 100% upon receiving a large invalid TLS frame.
0
Attacker Value
Unknown
CVE-2021-28164
Disclosure Date: April 01, 2021 (last updated February 22, 2025)
In Eclipse Jetty 9.4.37.v20210219 to 9.4.38.v20210224, the default compliance mode allows requests with URIs that contain %2e or %2e%2e segments to access protected resources within the WEB-INF directory. For example a request to /context/%2e/WEB-INF/web.xml can retrieve the web.xml file. This can reveal sensitive information regarding the implementation of a web application.
0
Attacker Value
Unknown
CVE-2021-28163
Disclosure Date: April 01, 2021 (last updated February 22, 2025)
In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory.
0
Attacker Value
Unknown
CVE-2021-28161
Disclosure Date: March 12, 2021 (last updated February 22, 2025)
In Eclipse Theia versions up to and including 1.8.0, in the debug console there is no HTML escaping, so arbitrary Javascript code can be injected.
0
Attacker Value
Unknown
CVE-2021-28162
Disclosure Date: March 12, 2021 (last updated February 22, 2025)
In Eclipse Theia versions up to and including 0.16.0, in the notification messages there is no HTML escaping, so Javascript code can run.
0
Attacker Value
Unknown
CVE-2021-28134
Disclosure Date: March 11, 2021 (last updated November 28, 2024)
Clipper before 1.0.5 allows remote command execution. A remote attacker may send a crafted IPC message to the exposed vulnerable ipcRenderer IPC interface, which invokes the dangerous openExternal API.
0
Attacker Value
Unknown
CVE-2020-27225
Disclosure Date: March 09, 2021 (last updated February 22, 2025)
In versions 4.18 and earlier of the Eclipse Platform, the Help Subsystem does not authenticate active help requests to the local help web server, allowing an unauthenticated local attacker to issue active help commands to the associated Eclipse Platform process or Eclipse Rich Client Platform process.
0
Attacker Value
Unknown
CVE-2020-27223
Disclosure Date: February 26, 2021 (last updated February 22, 2025)
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.
0
Attacker Value
Unknown
CVE-2021-24087
Disclosure Date: February 25, 2021 (last updated February 22, 2025)
Azure IoT CLI extension Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2020-27224
Disclosure Date: February 24, 2021 (last updated February 22, 2025)
In Eclipse Theia versions up to and including 1.2.0, the Markdown Preview (@theia/preview), can be exploited to execute arbitrary code.
0