CVE-2021-41041
- EPSS 1.01%
- Veröffentlicht 27.04.2022 02:15:38
- Zuletzt bearbeitet 21.11.2024 06:25:20
In Eclipse Openj9 before version 0.32.0, Java 8 & 11 fail to throw the exception captured during bytecode verification when verification is triggered by a MethodHandle invocation, allowing unverified methods to be invoked using MethodHandles.
CVE-2021-41035
- EPSS 1.82%
- Veröffentlicht 25.10.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:25:19
In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.
CVE-2021-28167
- EPSS 1.1%
- Veröffentlicht 21.04.2021 18:15:08
- Zuletzt bearbeitet 21.11.2024 05:59:14
In Eclipse Openj9 to version 0.25.0, usage of the jdk.internal.reflect.ConstantPool API causes the JVM in some cases to pre-resolve certain constant pool entries. This allows a user to call static methods or access static members without running the ...
CVE-2020-27221
- EPSS 1.53%
- Veröffentlicht 21.01.2021 05:15:10
- Zuletzt bearbeitet 21.11.2024 05:20:53
In Eclipse OpenJ9 up to and including version 0.23, there is potential for a stack-based buffer overflow when the virtual machine or JNI natives are converting from UTF-8 characters to platform encoding.
CVE-2019-17639
- EPSS 1.5%
- Veröffentlicht 15.07.2020 22:15:13
- Zuletzt bearbeitet 21.11.2024 04:32:41
In Eclipse OpenJ9 prior to version 0.21 on Power platforms, calling the System.arraycopy method with a length longer than the length of the source or destination array can, in certain specially crafted code patterns, cause the current method to retur...
CVE-2019-17631
- EPSS 2.07%
- Veröffentlicht 17.10.2019 18:15:12
- Zuletzt bearbeitet 21.11.2024 04:32:39
From Eclipse OpenJ9 0.15 to 0.16, access to diagnostic operations such as causing a GC or creating a diagnostic file are permitted without any privilege checks.
CVE-2019-11775
- EPSS 1.47%
- Veröffentlicht 30.07.2019 14:15:14
- Zuletzt bearbeitet 21.11.2024 04:21:46
All builds of Eclipse OpenJ9 prior to 0.15 contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by versioning - for example if there is a condition that is moved out of the loop that reads a field we may...
CVE-2019-11772
- EPSS 2.1%
- Veröffentlicht 17.07.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:21:45
In Eclipse OpenJ9 prior to 0.15, the String.getBytes(int, int, byte[], int) method does not verify that the provided byte array is non-null nor that the provided index is in bounds when compiled by the JIT. This allows arbitrary writes to any 32-bit ...
CVE-2019-11771
- EPSS 0.39%
- Veröffentlicht 17.07.2019 21:15:11
- Zuletzt bearbeitet 21.11.2024 04:21:45
AIX builds of Eclipse OpenJ9 before 0.15.0 contain unused RPATHs which may facilitate code injection and privilege elevation by local users.
CVE-2019-10245
- EPSS 2.49%
- Veröffentlicht 19.04.2019 14:29:00
- Zuletzt bearbeitet 21.11.2024 04:18:43
In Eclipse OpenJ9 prior to the 0.14.0 release, the Java bytecode verifier incorrectly allows a method to execute past the end of bytecode array causing crashes. Eclipse OpenJ9 v0.14.0 correctly detects this case and rejects the attempted class load.