CVE-2026-68073
- EPSS 0.19%
- Veröffentlicht 05.08.2026 05:32:25
- Zuletzt bearbeitet 06.08.2026 22:18:24
A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, which fix...
CVE-2026-68060
- EPSS 0.48%
- Veröffentlicht 05.08.2026 05:26:27
- Zuletzt bearbeitet 07.08.2026 20:36:01
A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0,...
CVE-2026-68074
- EPSS 0.49%
- Veröffentlicht 05.08.2026 05:19:55
- Zuletzt bearbeitet 07.08.2026 12:52:35
A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue affects Apache Qpid Broker-J: through 10.0.1. Users are recommended to upgrade to version 10.1.0, whic...
CVE-2019-0200
- EPSS 3.82%
- Veröffentlicht 06.03.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:16:28
A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 6.0.0-7.0.6 (inclusive) and 7.1.0 which allows an unauthenticated attacker to crash the broker instance by sending specially crafted commands using AMQP protocol versions be...
CVE-2018-8030
- EPSS 3.98%
- Veröffentlicht 20.06.2018 01:29:03
- Zuletzt bearbeitet 21.11.2024 04:13:07
A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 7.0.0-7.0.4 when AMQP protocols 0-8, 0-9 or 0-91 are used to publish messages with size greater than allowed maximum message size limit (100MB by default). The broker crashe...
CVE-2018-1298
- EPSS 2.33%
- Veröffentlicht 09.02.2018 14:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:34
A Denial of Service vulnerability was found in Apache Qpid Broker-J 7.0.0 in functionality for authentication of connections for AMQP protocols 0-8, 0-9, 0-91 and 0-10 when PLAIN or XOAUTH2 SASL mechanism is used. The vulnerability allows unauthentic...
CVE-2017-15702
- EPSS 6.21%
- Veröffentlicht 01.12.2017 15:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Apache Qpid Broker-J 0.18 through 0.32, if the broker is configured with different authentication providers on different ports one of which is an HTTP port, then the broker can be tricked by a remote unauthenticated attacker connecting to the HTTP...
CVE-2017-15701
- EPSS 4.39%
- Veröffentlicht 01.12.2017 15:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In Apache Qpid Broker-J versions 6.1.0 through 6.1.4 (inclusive) the broker does not properly enforce a maximum frame size in AMQP 1.0 frames. A remote unauthenticated attacker could exploit this to cause the broker to exhaust all available memory an...
CVE-2016-8741
- EPSS 6.3%
- Veröffentlicht 15.05.2017 14:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
The Apache Qpid Broker for Java can be configured to use different so called AuthenticationProviders to handle user authentication. Among the choices are the SCRAM-SHA-1 and SCRAM-SHA-256 AuthenticationProvider types. It was discovered that these Aut...
CVE-2016-4432
- EPSS 8.15%
- Veröffentlicht 01.06.2016 20:59:07
- Zuletzt bearbeitet 06.05.2026 22:30:45
The AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication and consequently perform actions via vectors related to connection state logging.