cbcvebase.

Eclipse Foundation Openj9 vulnerabilities

4 known vulnerabilities affecting eclipse_foundation/openj9.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2025-4447P3HIGHCVSS 7.8≥ 0.8.0, ≤ 0.49.02025-05-09
CVE-2025-4447 [HIGH] CWE-121 CVE-2025-4447: In Eclipse OpenJ9 versions up to 0.51, when used with OpenJDK version 8 a stack based buffer overflo In Eclipse OpenJ9 versions up to 0.51, when used with OpenJDK version 8 a stack based buffer overflow can be caused by modifying a file on disk that is read when the JVM starts.
nvd
CVE-2026-16441P3MEDIUMCVSS 6.9≥ 0.8.0, < 0.60.02026-07-21
CVE-2026-16441 [MEDIUM] CWE-758 CVE-2026-16441: In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superc In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been recompiled as abstract, execution is incorrectly delegated to an interface default method.
nvd
CVE-2026-16439P4MEDIUMCVSS 5.8≥ 0.8.0, < 0.60.02026-07-21
CVE-2026-16439 [MEDIUM] CWE-124 CVE-2026-16439: In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer un In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow.
nvd
CVE-2023-5676P4MEDIUMCVSS 5.9fixed in 0.41.02023-11-15
CVE-2023-5676 [MEDIUM] CWE-364 CVE-2023-5676: In Eclipse OpenJ9 before version 0.41.0, the JVM can be forced into an infinite busy hang on a spinl In Eclipse OpenJ9 before version 0.41.0, the JVM can be forced into an infinite busy hang on a spinlock or a segmentation fault if a shutdown signal (SIGTERM, SIGINT or SIGHUP) is received before the JVM has finished initializing.
nvd
Eclipse Foundation Openj9 vulnerabilities | cvebase