Vulnerabilities > Apache > Qpid > 0.22

DATE CVE VULNERABILITY TITLE RISK
2019-04-23 CVE-2019-0223 While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS *even when configured to verify the peer certificate* while used with OpenSSL versions before 1.1.0.
network
high complexity
apache redhat
7.4
2018-02-21 CVE-2015-0203 Data Processing Errors vulnerability in Apache Qpid
The qpidd broker in Apache Qpid 0.30 and earlier allows remote authenticated users to cause a denial of service (daemon crash) via an AMQP message with (1) an invalid range in a sequence set, (2) content-bearing methods other than message-transfer, or (3) a session-gap control before a corresponding session-attach.
network
low complexity
apache CWE-19
4.0
2017-10-30 CVE-2015-0224 Data Processing Errors vulnerability in Apache Qpid
qpidd in Apache Qpid 0.30 and earlier allows remote attackers to cause a denial of service (daemon crash) via a crafted protocol sequence set.
network
low complexity
apache CWE-19
7.5
2015-02-02 CVE-2015-0223 Permissions, Privileges, and Access Controls vulnerability in Apache Qpid
Unspecified vulnerability in Apache Qpid 0.30 and earlier allows remote attackers to bypass access restrictions on qpidd via unknown vectors, related to 0-10 connection handling.
network
low complexity
apache CWE-264
5.0