Eclipse / Openj9
23 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-16441 | Eclipse OpenJ9 : Method resolution default method precedence failure | MEDIUM | 6.9 | Jul 21, 2026 |
| CVE-2026-16439 | Eclipse OpenJ9 : Using -Xtrace to trace method arguments can lead to buffer underflow | MEDIUM | 5.8 | Jul 21, 2026 |
| CVE-2026-6918 | Eclipse Open9J: Denial of Service in JITServer via crafted TCP message | HIGH | 8.7 | May 5, 2026 |
| CVE-2025-4447 | Buffer Overflow in Eclipse OpenJ9 | HIGH | 7.0 | May 9, 2025 |
| CVE-2024-10917 | Eclipse OpenJ9 might return an incorrect value in JNI function GetStringUTFLength | MEDIUM | 5.3 | Nov 11, 2024 |
| CVE-2024-3933 | Eclipse Open J9 With -Xgc:concurrentScavenge on IBM Z, could write/read outside of a buffer | HIGH | 7.3 | May 27, 2024 |
| CVE-2023-5676 | Eclipse OpenJ9 possible infinite busy hang | MEDIUM | 5.9 | Nov 15, 2023 |
| CVE-2023-2597 | In Eclipse Openj9 before version 0.38.0, in the implementation of the shared cache (which is enabled by default in OpenJ9 builds) the size of a string is not p… | CRITICAL | 9.1 | May 22, 2023 |
| CVE-2022-3676 | In Eclipse Openj9 before version 0.35.0, interface calls can be inlined without a runtime type check. Malicious bytecode could make use of this inlining to acc… | MEDIUM | 6.5 | Oct 24, 2022 |
| CVE-2021-41041 | java-11-openj9,java-1_8_0-openj9: unverified methods can be invoked using MethodHandles | MEDIUM | 5.3 | Apr 27, 2022 |
| CVE-2021-41035 | JDK: IllegalAccessError exception not thrown for MethodHandles that invoke inaccessible interface methods | CRITICAL | 9.8 | Oct 25, 2021 |
| CVE-2021-28167 | In Eclipse Openj9 to version 0.25.0, usage of the jdk.internal.reflect.ConstantPool API causes the JVM in some cases to pre-resolve certain constant pool entri… | MEDIUM | 6.5 | Apr 21, 2021 |
| CVE-2020-27221 | JDK: Stack-based buffer overflow when converting from UTF-8 characters to platform encoding | CRITICAL | 9.8 | Jan 21, 2021 |
| CVE-2019-17639 | JDK: Information disclosure via calls to System.arraycopy() with invalid length | MEDIUM | 5.3 | Jul 15, 2020 |
| CVE-2019-17631 | JDK: Unrestricted access to diagnostic operations | CRITICAL | 9.1 | Oct 17, 2019 |
| CVE-2019-11775 | JDK: Failure to privatize a value pulled out of the loop by versioning | HIGH | 7.4 | Jul 30, 2019 |
| CVE-2019-11772 | JDK: Out-of-bounds access in the String.getBytes method | CRITICAL | 9.8 | Jul 17, 2019 |
| CVE-2019-11771 | JDK: Insecure RPATH in OpenJ9 on AIX | HIGH | 7.8 | Jul 17, 2019 |
| CVE-2019-10245 | JDK: Read beyond the end of bytecode array causing JVM crash | HIGH | 7.5 | Apr 19, 2019 |
| CVE-2018-12549 | JDK: missing null check when accelerating Unsafe calls | CRITICAL | 9.8 | Feb 11, 2019 |
| CVE-2018-12547 | JDK: buffer overflow in jio_snprintf() and jio_vsnprintf() | CRITICAL | 9.8 | Feb 11, 2019 |
| CVE-2018-12548 | In OpenJDK + Eclipse OpenJ9 version 0.11.0 builds, the public jdk.crypto.jniprovider.NativeCrypto class contains public static natives which accept pointer val… | CRITICAL | 9.8 | Jan 31, 2019 |
| CVE-2018-12539 | JDK: privilege escalation via insufficiently restricted access to Attach API | HIGH | 8.4 | Aug 14, 2018 |
Showing 1 to 23 of 23 CVEs