Skip to main content

Vendor/product archive

eclipse / memory_analyzer CVEs

Beta · best-effort

3 CVEs tagged to eclipse / memory_analyzer1 Critical, 1 High, 0 Medium, 1 Low, 0 Unrated.

CVE-2023-6194

Published Dec 11, 2023

In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit document type definition (DTD) references to external entities. This me…

CVSS 2.8 · Low
Vendor/product tagsBeta · best-effort

CVE-2019-17635

Published Jan 17, 2020

Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a deserialization vulnerability if an index file of a parsed heap dump is replaced by a malicious version and the h…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-17634

Published Jan 17, 2020

Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a cross site scripting (XSS) vulnerability when generating an HTML report from a malicious heap dump. The user must…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1