Qos
3 CVEs tracked since 2022. Since Jan 2022, none of them reached CISA KEV.
Qos CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2022-01 | 3 | 0 |
Products
The products that kept showing up in Qos's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 10 most recently published vulnerabilities affecting Qos.
- CVE-2023-6481Logback "receiver" DOS vulnerability CVE-2023-6378 incomplete fix7.1
- CVE-2023-6378Logback "receiver" DOS vulnerability 7.1
- CVE-2022-23307A deserialization flaw in the Chainsaw component of Log4j 1 can lead to malicious code execution.8.8
- CVE-2022-23305SQL injection in JDBC Appender in Apache Log4j V19.8
- CVE-2022-23302Deserialization of untrusted data in JMSSink in Apache Log4j 1.x8.8
- CVE-2021-42550RCE from attacker with configuration edit priviledges through JNDI lookup6.6
- CVE-2020-9493Java deserialization in Chainsaw9.8
- CVE-2020-9488Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log me...3.7
- CVE-2018-8088org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module...9.8
- CVE-2017-5929QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.9.8
The record
- Peak rank
- #184 in Jan 2022
- Busiest month shown
- Jan 2022, 3 CVEs
- Months with a KEV entry
- 0 since Jan 2022
- Monthly snapshots
- 1 since 2022