Skip to content
Noroxi

qos records

10 published records for vendor qos.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
90%
Median publish → KEV
No record has entered KEV

All records

10 records
  • SQL injection in JDBC Appender in Apache Log4j V1

    CriticalCVSS 9.8Proof of conceptEPSS 67%

    apache · log4jJan 18, 2022

  • Deserialization of untrusted data in JMSSink in Apache Log4j 1.x

    HighCVSS 8.8No exploitEPSS 64%

    apache · log4jJan 18, 2022

  • A deserialization flaw in the Chainsaw component of Log4j 1 can lead to malicious code execution.

    HighCVSS 8.8No exploitEPSS 54%

    apache · chainsawJan 18, 2022

  • org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restric

    CriticalCVSS 9.8No exploitEPSS 15%

    qos · slf4jMar 20, 2018

  • QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.

    CriticalCVSS 9.8No exploitEPSS 8%

    qos · logbackMar 13, 2017

  • Java deserialization in Chainsaw

    CriticalCVSS 9.8No exploitEPSS 5%

    apache · chainsawJun 16, 2021

  • CVE-2023-6378
    30Monitor

    Logback "receiver" DOS vulnerability

    HighCVSS 7.5No exploitEPSS 1%

    qos · logbackNov 29, 2023

  • CVE-2023-6481
    30Monitor

    Logback "receiver" DOS vulnerability CVE-2023-6378 incomplete fix

    HighCVSS 7.5No exploitEPSS 1%

    qos · logbackDec 4, 2023

  • RCE from attacker with configuration edit priviledges through JNDI lookup

    MediumCVSS 6.6No exploitEPSS 4%

    qos · logbackDec 16, 2021

  • CVE-2020-9488
    16Monitor

    Improper validation of certificate with host mismatch in Apache Log4j SMTP appender.

    LowCVSS 3.7Proof of conceptEPSS 8%

    apache · log4jApr 27, 2020