Qpid

Vendor:

First CVE: Oct 12, 2010 · Active for 15 years

16
Total CVEs
More Total CVEs than 92% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
5.6
Avg CVSS
Higher Avg CVSS than 16% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Qpid over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 12, 2010
15 years ago
Most Recent CVE
Apr 23, 2019
2,649 days ago

CVE Severity & Scoring

Qpid16 CVEs
All CVEs352,231 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network3 (18.8%)
Unknown13 (81.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (12.5%)
High1 (6.3%)
Unknown13 (81.3%)
User Interaction
None3 (18.8%)
Unknown13 (81.3%)
Required0 (0.0%)
Privileges Required
Low1 (6.3%)
High0 (0.0%)
None2 (12.5%)
Unknown13 (81.3%)

Top CVEs

Signals from CVEs in this product scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a pe
Apr 23, 20197.427NONO
qpidd in Apache Qpid 0.30 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted protocol sequence set. NOTE: this vulnerability exists beca
Oct 30, 20177.525NONO
The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows
Mar 14, 20136.821NONO
Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messaging functionality and job functio
May 3, 20127.521NONO
The qpidd broker in Apache Qpid 0.30 and earlier allows remote authenticated users to cause a denial of service (daemon crash) via an AMQP message with (1) an invalid range in a se
Feb 21, 20186.520NONO
Apache Qpid 0.17 and earlier does not properly restrict incoming client connections, which allows remote attackers to cause a denial of service (file descriptor consumption) via a
Sep 28, 20125.020NONO
Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remote attackers to bypass authenti
Aug 27, 20125.020NONO
The Cluster::deliveredEvent function in cluster/Cluster.cpp in Apache Qpid, as used in Red Hat Enterprise MRG before 1.3 and other products, allows remote attackers to cause a deni
Oct 18, 20105.020NONO
Integer overflow in the qpid::framing::Buffer::checkAvailable function in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (crash) via a crafted me
Mar 14, 20135.019NONO
The AMQP type decoder in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (memory consumption and server crash) via a large number of zero width el
Mar 14, 20135.019NONO

Exploit Exposure

Signals from CVEs in this product scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (16 CVEs).

Media Mentions

Signals from CVEs in this product scope (16 CVEs).

Top CNAs Publishing CVEs For Qpid

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
0.965.44.9%00
0.865.44.9%00
0.765.44.9%00
0.685.25.1%00
0.575.35.2%00
0.3014.36.9%00
0.1955.55.1%00
0.1855.55.1%00
0.1755.55.1%00
0.1665.44.9%00
0.1555.55.1%00
0.1475.45.1%00
0.1355.55.1%00
0.1275.75.0%00
0.1155.55.1%00
0.1065.44.9%00