Known vulnerabilities in OpenJ9

Vendor: Eclipse
Software: OpenJ9
Software CPE: cpe:2.3:a:eclipse:openj9:*:*:*:*:*:*:*:*
Total vulnerabilities: 13
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting OpenJ9 OpenJ9 is affected by 13 known vulnerabilities: 5 high, 5 medium, 3 low Critical High Medium Low

Vulnerabilities (13)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU144400 - Uncontrolled Recursion
CVE-2026-16440
CWE-674 Low
No
No
0.61.0 19.08.2026 SB20260819144
SB2026091031
SB2026091115
#VU130954 - Out-of-bounds read
CVE-2026-6918
CWE-125 Medium
No
No
0.59.0 11.05.2026 SB2026051152
SB20260528261
SB2026060168
and 12 more
#VU112132 - Stack-based buffer overflow
CVE-2025-4447
CWE-121 Medium
No
No
0.51.0 03.07.2025 SB2025070315
SB2025070316
SB2025070319
and 54 more
#VU101344 - Integer overflow
CVE-2024-10917
CWE-190 Low
No
No
0.48.0 09.12.2024 SB2024120927
SB2024120928
SB2024120929
and 66 more
#VU77334 - Memory corruption
CVE-2019-10245
CWE-119 Medium
No
No
0.14.0 15.06.2023 SB2019041923
SB2019051119
SB2019051329
and 4 more
#VU75888 - Integer overflow
CVE-2023-2004
CWE-190 High
No
No
0.38.0 09.05.2023 SB2023050976
SB2023050989
SB2023060845
and 34 more
#VU68844 - Type confusion
CVE-2022-3676
CWE-843 Medium
No
No
0.35.0 31.10.2022 SB2022103129
SB2022111110
SB2022111724
and 60 more
#VU67029 - Error Handling
CVE-2021-41041
CWE-388 Low
No
No
0.32.0 06.09.2022 SB2022090642
SB2022090643
SB2022093005
and 25 more
#VU66153 - Heap-based Buffer Overflow
CVE-2022-37434
CWE-122 High
Available
No
0.35.0 07.08.2022 SB2022080705
SB2022081833
SB2022081851
and 154 more
#VU60084 - Missing initialization of resource
CVE-2021-28167
CWE-909 Medium
No
No
0.26.0 27.01.2022 SB2021042158
SB2022102806
SB2022112426
and 15 more
#VU60083 - Improper Access Control
CVE-2021-41035
CWE-284 High
No
No
0.29.0 27.01.2022 SB2022012712
SB2022020177
SB2022021424
and 28 more
#VU49916 - Stack-based buffer overflow
CVE-2020-27221
CWE-121 High
No
No
0.24.0 21.01.2021 SB2021012130
SB2021030504
SB2021030505
and 16 more
#VU44142 - Type confusion
CVE-2019-17639
CWE-843 High
No
No
0.21.0 11.08.2020 SB20200716142
SB2020081106
SB2020081107
and 10 more