Eclipse

Memory Analyzer

3 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.04%
  • Published 11.12.2023 14:15:31
  • Last modified 21.11.2024 08:43:19

In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit document type definition (DTD) references to external entities. This means that if a user chooses to use a malicious report definition XML fil...

Exploit
  • EPSS 0.47%
  • Published 17.01.2020 19:15:12
  • Last modified 21.11.2024 04:32:40

Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a deserialization vulnerability if an index file of a parsed heap dump is replaced by a malicious version and the heap dump is reopened in Memory Analyzer. The user must chose to reopen ...

Exploit
  • EPSS 1.28%
  • Published 17.01.2020 19:15:11
  • Last modified 21.11.2024 04:32:40

Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a cross site scripting (XSS) vulnerability when generating an HTML report from a malicious heap dump. The user must chose todownload, open the malicious heap dump and generate an HTML re...