VendorsEclipseomrall versions
Vulnerabilities

Eclipse OMR

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2026-1188
In the Eclipse OMR port library component since release 0.2.0, an API function to return the textual names of all supported processor features was not accounting for the separator inserted between processor features. If the output buffer supplied to this function was incorrectly sized, failing to account for the separator when determining when a write to the buffer was safe could lead to a buffer overflow. This issue is fixed in Eclipse OMR version 0.8.0.
Published 2026-01-29 · Analyzed
9.8EPSS 0.005
CVE-2025-14549
OMR on Z processors Exposing a possible buffer over-read problem
Published 2025-12-15 · Analyzed
8.1EPSS 0.003
CVE-2019-11773
Prior to 0.1, AIX builds of Eclipse OMR contain unused RPATHs which may facilitate code injection and privilege elevation by local users.
Published 2019-09-12 · Modified
7.8EPSS 0.004
CVE-2025-1471
Eclipse OMR: Buffer overflow vulnerability
Published 2025-02-21 · Analyzed
7.8EPSS 0.002
CVE-2026-16243
Eclipse OMR : arraycmp SIMD implementation does not check if the number of bytes to compare is zero
Published 2026-07-21 · Analyzed
7.5EPSS 0.004
CVE-2019-11774
Prior to 0.1, all builds of Eclipse OMR contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by versioning - for example if there is a condition that is moved out of the loop that reads a field we may not privatize the value of that field in the modified copy of the loop allowing the test to see one value of the field and subsequently the loop to see a modified field value without retesting the condition moved out of the loop. This can lead to a variety of different issues but read out of array bounds is one major consequence of these problems.
Published 2019-09-12 · Modified
7.4EPSS 0.007
CVE-2025-1470
Eclipse OMR: Null pointer dereference vulnerability
Published 2025-02-21 · Analyzed
5.5EPSS 0.002