Qpid
Vendor:
First CVE: Oct 12, 2010 · Active for 15 years
16
Total CVEs
More Total CVEs than 92% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
5.6
Avg CVSS
Higher Avg CVSS than 16% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Qpid over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 12, 2010
15 years ago
Most Recent CVE
Apr 23, 2019
2,649 days ago
CVE Severity & Scoring
Qpid16 CVEs
81%
19%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network3 (18.8%)
Unknown13 (81.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (12.5%)
High1 (6.3%)
Unknown13 (81.3%)
User Interaction
None3 (18.8%)
Unknown13 (81.3%)
Required0 (0.0%)
Privileges Required
Low1 (6.3%)
High0 (0.0%)
None2 (12.5%)
Unknown13 (81.3%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-0223HIGH While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a pe | Apr 23, 2019 | 7.4 | 27 | NO | NO |
CVE-2015-0224HIGH qpidd in Apache Qpid 0.30 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted protocol sequence set. NOTE: this vulnerability exists beca | Oct 30, 2017 | 7.5 | 25 | NO | NO |
CVE-2012-4446MEDIUM The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows | Mar 14, 2013 | 6.8 | 21 | NO | NO |
CVE-2011-3620HIGH Apache Qpid 0.12 does not properly verify credentials during the joining of a cluster, which allows remote attackers to obtain access to the messaging functionality and job functio | May 3, 2012 | 7.5 | 21 | NO | NO |
CVE-2015-0203MEDIUM The qpidd broker in Apache Qpid 0.30 and earlier allows remote authenticated users to cause a denial of service (daemon crash) via an AMQP message with (1) an invalid range in a se | Feb 21, 2018 | 6.5 | 20 | NO | NO |
CVE-2012-2145MEDIUM Apache Qpid 0.17 and earlier does not properly restrict incoming client connections, which allows remote attackers to cause a denial of service (file descriptor consumption) via a | Sep 28, 2012 | 5.0 | 20 | NO | NO |
CVE-2012-3467MEDIUM Apache QPID 0.14, 0.16, and earlier uses a NullAuthenticator mechanism to authenticate catch-up shadow connections to AMQP brokers, which allows remote attackers to bypass authenti | Aug 27, 2012 | 5.0 | 20 | NO | NO |
CVE-2009-5005MEDIUM The Cluster::deliveredEvent function in cluster/Cluster.cpp in Apache Qpid, as used in Red Hat Enterprise MRG before 1.3 and other products, allows remote attackers to cause a deni | Oct 18, 2010 | 5.0 | 20 | NO | NO |
CVE-2012-4459MEDIUM Integer overflow in the qpid::framing::Buffer::checkAvailable function in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (crash) via a crafted me | Mar 14, 2013 | 5.0 | 19 | NO | NO |
CVE-2012-4458MEDIUM The AMQP type decoder in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (memory consumption and server crash) via a large number of zero width el | Mar 14, 2013 | 5.0 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Qpid
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.9 | 6 | 5.4 | 4.9% | 0 | 0 |
| 0.8 | 6 | 5.4 | 4.9% | 0 | 0 |
| 0.7 | 6 | 5.4 | 4.9% | 0 | 0 |
| 0.6 | 8 | 5.2 | 5.1% | 0 | 0 |
| 0.5 | 7 | 5.3 | 5.2% | 0 | 0 |
| 0.30 | 1 | 4.3 | 6.9% | 0 | 0 |
| 0.19 | 5 | 5.5 | 5.1% | 0 | 0 |
| 0.18 | 5 | 5.5 | 5.1% | 0 | 0 |
| 0.17 | 5 | 5.5 | 5.1% | 0 | 0 |
| 0.16 | 6 | 5.4 | 4.9% | 0 | 0 |
| 0.15 | 5 | 5.5 | 5.1% | 0 | 0 |
| 0.14 | 7 | 5.4 | 5.1% | 0 | 0 |
| 0.13 | 5 | 5.5 | 5.1% | 0 | 0 |
| 0.12 | 7 | 5.7 | 5.0% | 0 | 0 |
| 0.11 | 5 | 5.5 | 5.1% | 0 | 0 |
| 0.10 | 6 | 5.4 | 4.9% | 0 | 0 |