CVE-2012-6092
- EPSS 6.93%
- Veröffentlicht 21.04.2013 21:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Multiple cross-site scripting (XSS) vulnerabilities in the web demos in Apache ActiveMQ before 5.8.0 allow remote attackers to inject arbitrary web script or HTML via (1) the refresh parameter to PortfolioPublishServlet.java (aka demo/portfolioPublis...
CVE-2012-5784
- EPSS 5.72%
- Veröffentlicht 04.11.2012 22:55:03
- Zuletzt bearbeitet 16.06.2026 23:47:19
Apache Axis 1.4 and earlier, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a do...
- EPSS 8.44%
- Veröffentlicht 05.01.2012 16:55:00
- Zuletzt bearbeitet 16.06.2026 23:35:36
Apache ActiveMQ before 5.6.0 allows remote attackers to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending many openwire failover:tcp:// connection requests.
- EPSS 78.02%
- Veröffentlicht 28.04.2010 22:30:00
- Zuletzt bearbeitet 16.06.2026 23:18:39
The Jetty ResourceHandler in Apache ActiveMQ 5.x before 5.3.2 and 5.4.x before 5.4.0 allows remote attackers to read JSP source code via a // (slash slash) initial substring in a URI for (1) admin/index.jsp, (2) admin/queues.jsp, or (3) admin/topics....
CVE-2010-0684
- EPSS 4.28%
- Veröffentlicht 05.04.2010 16:30:00
- Zuletzt bearbeitet 16.06.2026 23:16:38
Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue action.
CVE-2010-1244
- EPSS 1.08%
- Veröffentlicht 05.04.2010 16:30:00
- Zuletzt bearbeitet 16.06.2026 23:17:56
Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ before 5.3.1 allows remote attackers to hijack the authentication of unspecified victims for requests that create queues via the JMSDestination parameter i...