Cross Site Scripting Vulnerability in Eclipse Memory Analyzer
CVE-2019-17634
What is CVE-2019-17634?
Eclipse Memory Analyzer versions prior to 1.9.1 are vulnerable to a cross site scripting (XSS) flaw when generating HTML reports from potentially malicious heap dumps. Users must download and open a crafted heap dump, which could originate from compromised applications or malicious data inputs. When the report is generated and accessed either via the Memory Analyzer GUI or in batch mode through a web browser, the XSS vulnerability can be exploited, potentially allowing execution of unauthorized code on the local system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Eclipse Memory Analyzer All versions prior to version 1.9.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
