qos records
10 published records for vendor qos.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 90%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-502 Deserialization of Untrusted Data6
- CWE-295 Improper Certificate Validation1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
59Plan | CVE-2022-23305Proof of concept | SQL injection in JDBC Appender in Apache Log4j V1apache · log4j · CWE-89 | Critical9.8 | — | 66.5% | Jan 18, 2022 |
54Plan | CVE-2022-23302No exploit | Deserialization of untrusted data in JMSSink in Apache Log4j 1.xapache · log4j · CWE-502 | High8.8 | — | 63.6% | Jan 18, 2022 |
51Plan | CVE-2022-23307No exploit | A deserialization flaw in the Chainsaw component of Log4j 1 can lead to malicious code execution.apache · chainsaw · CWE-502 | High8.8 | — | 54.4% | Jan 18, 2022 |
43Plan | CVE-2018-8088No exploit | org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restricqos · slf4j | Critical9.8 | — | 14.7% | Mar 20, 2018 |
41Plan | CVE-2017-5929No exploit | QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.qos · logback · CWE-502 | Critical9.8 | — | 7.5% | Mar 13, 2017 |
40Plan | CVE-2020-9493No exploit | Java deserialization in Chainsawapache · chainsaw · CWE-502 | Critical9.8 | — | 4.6% | Jun 16, 2021 |
30Monitor | CVE-2023-6378No exploit | Logback "receiver" DOS vulnerabilityqos · logback · CWE-502 | High7.5 | — | 0.9% | Nov 29, 2023 |
30Monitor | CVE-2023-6481No exploit | Logback "receiver" DOS vulnerability CVE-2023-6378 incomplete fixqos · logback | High7.5 | — | 0.7% | Dec 4, 2023 |
27Monitor | CVE-2021-42550No exploit | RCE from attacker with configuration edit priviledges through JNDI lookupqos · logback · CWE-502 | Medium6.6 | — | 4.4% | Dec 16, 2021 |
16Monitor | CVE-2020-9488Proof of concept | Improper validation of certificate with host mismatch in Apache Log4j SMTP appender.apache · log4j · CWE-295 | Low3.7 | — | 8.1% | Apr 27, 2020 |
- CVE-2022-2330559Plan
SQL injection in JDBC Appender in Apache Log4j V1
CriticalCVSS 9.8Proof of conceptEPSS 67%apache · log4jJan 18, 2022
- CVE-2022-2330254Plan
Deserialization of untrusted data in JMSSink in Apache Log4j 1.x
HighCVSS 8.8No exploitEPSS 64%apache · log4jJan 18, 2022
- CVE-2022-2330751Plan
A deserialization flaw in the Chainsaw component of Log4j 1 can lead to malicious code execution.
HighCVSS 8.8No exploitEPSS 54%apache · chainsawJan 18, 2022
- CVE-2018-808843Plan
org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restric
CriticalCVSS 9.8No exploitEPSS 15%qos · slf4jMar 20, 2018
- CVE-2017-592941Plan
QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.
CriticalCVSS 9.8No exploitEPSS 8%qos · logbackMar 13, 2017
- CVE-2020-949340Plan
Java deserialization in Chainsaw
CriticalCVSS 9.8No exploitEPSS 5%apache · chainsawJun 16, 2021
- CVE-2023-637830Monitor
Logback "receiver" DOS vulnerability
HighCVSS 7.5No exploitEPSS 1%qos · logbackNov 29, 2023
- CVE-2023-648130Monitor
Logback "receiver" DOS vulnerability CVE-2023-6378 incomplete fix
HighCVSS 7.5No exploitEPSS 1%qos · logbackDec 4, 2023
- CVE-2021-4255027Monitor
RCE from attacker with configuration edit priviledges through JNDI lookup
MediumCVSS 6.6No exploitEPSS 4%qos · logbackDec 16, 2021
- CVE-2020-948816Monitor
Improper validation of certificate with host mismatch in Apache Log4j SMTP appender.
LowCVSS 3.7Proof of conceptEPSS 8%apache · log4jApr 27, 2020