Omr
Vendor:
First CVE: Sep 12, 2019 · Active for 6 years
6
Total CVEs
More Total CVEs than 80% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 62% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Omr over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 12, 2019
6 years ago
Most Recent CVE
Jan 29, 2026
176 days ago
CVE Severity & Scoring
Omr6 CVEs
17%
67%
17%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (50.0%)
Network3 (50.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (83.3%)
High1 (16.7%)
Unknown0 (0.0%)
User Interaction
None5 (83.3%)
Unknown0 (0.0%)
Required1 (16.7%)
Privileges Required
Low3 (50.0%)
High0 (0.0%)
None3 (50.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-1188CRITICAL In the Eclipse OMR port library component since release 0.2.0, an API function to return the textual names of all supported processor features was not accounting for the separator | Jan 29, 2026 | 9.8 | 31 | NO | NO |
CVE-2025-14549HIGH In the Eclipse OMR compiler component, since release 0.7.0, an optimization enabled for Eclipse OpenJ9 consumers of OMR on Z processors incorrectly handles NUL (0x00) characters du | Dec 15, 2025 | 8.1 | 26 | NO | NO |
CVE-2019-11773HIGH Prior to 0.1, AIX builds of Eclipse OMR contain unused RPATHs which may facilitate code injection and privilege elevation by local users. | Sep 12, 2019 | 7.8 | 25 | NO | NO |
CVE-2025-1471HIGH In Eclipse OMR versions 0.2.0 to 0.4.0, some of the z/OS atoe print functions use a constant length buffer for string conversion. If the input format string and arguments are large | Feb 21, 2025 | 7.8 | 24 | NO | NO |
CVE-2019-11774HIGH Prior to 0.1, all builds of Eclipse OMR contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by versioning - for example if there is | Sep 12, 2019 | 7.4 | 24 | NO | NO |
CVE-2025-1470MEDIUM In Eclipse OMR, from the initial contribution to version 0.4.0, some OMR internal port library and utilities consumers of z/OS atoe functions do not check their return values for N | Feb 21, 2025 | 5.5 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Omr
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.7.0 | 1 | 8.1 | 0.3% | 0 | 0 |