Skip to main content

Vendor/product archive

eclipse / openj9 CVEs

Beta · best-effort

21 CVEs tagged to eclipse / openj97 Critical, 7 High, 6 Medium, 1 Low, 0 Unrated.

CVE-2026-6918

Published May 5, 2026

In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message.

CVSS 8.7 · High
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2025-4447

Published May 9, 2025

In Eclipse OpenJ9 versions up to 0.51, when used with OpenJDK version 8 a stack based buffer overflow can be caused by modifying a file on disk that is read when the JVM starts.

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10917

Published Nov 11, 2024

In Eclipse OpenJ9 versions up to 0.47, the JNI function GetStringUTFLength may return an incorrect value which has wrapped around. From 0.48 the value is correct but may be trunca…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-3933

Published May 27, 2024

In Eclipse OpenJ9 release versions prior to 0.44.0 and after 0.13.0, when running with JVM option -Xgc:concurrentScavenge, the sequence generated for System.arrayCopy on the IBM Z…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5676

Published Nov 15, 2023

In Eclipse OpenJ9 before version 0.41.0, the JVM can be forced into an infinite busy hang on a spinlock or a segmentation fault if a shutdown signal (SIGTERM, SIGINT or SIGHUP) is…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2597

Published May 22, 2023

In Eclipse Openj9 before version 0.38.0, in the implementation of the shared cache (which is enabled by default in OpenJ9 builds) the size of a string is not properly checked agai…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3676

Published Oct 24, 2022

In Eclipse Openj9 before version 0.35.0, interface calls can be inlined without a runtime type check. Malicious bytecode could make use of this inlining to access or modify memory…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41035

Published Oct 25, 2021

In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-28167

Published Apr 21, 2021

In Eclipse Openj9 to version 0.25.0, usage of the jdk.internal.reflect.ConstantPool API causes the JVM in some cases to pre-resolve certain constant pool entries. This allows a us…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-27221

Published Jan 21, 2021

In Eclipse OpenJ9 up to and including version 0.23, there is potential for a stack-based buffer overflow when the virtual machine or JNI natives are converting from UTF-8 characte…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-17639

Published Jul 15, 2020

In Eclipse OpenJ9 prior to version 0.21 on Power platforms, calling the System.arraycopy method with a length longer than the length of the source or destination array can, in cer…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11772

Published Jul 17, 2019

In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that the provided index is in bound…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-11771

Published Jul 17, 2019

AIX builds of Eclipse OpenJ9 before 0.15.0 contain unused RPATHs which may facilitate code injection and privilege elevation by local users.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-12548

Published Jan 31, 2019

In OpenJDK + Eclipse OpenJ9 version 0.11.0 builds, the public jdk.crypto.jniprovider.NativeCrypto class contains public static natives which accept pointer values that are derefer…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-21 of 21 CVEsPage 1 of 1