Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
apache activemq 1.1 vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2014-3579
XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x prior to 1.7.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.
Apache Activemq Apollo 1.7
Apache Activemq Apollo 1.6
Apache Activemq Apollo 1.5
Apache Activemq Apollo 1.4
Apache Activemq Apollo 1.3
Apache Activemq Apollo 1.2
Apache Activemq Apollo 1.1
Apache Activemq Apollo 1.0
6.8
CVSSv2
CVE-2010-1244
Cross-site request forgery (CSRF) vulnerability in createDestination.action in Apache ActiveMQ prior to 5.3.1 allows remote malicious users to hijack the authentication of unspecified victims for requests that create queues via the JMSDestination parameter in a queue action.
Apache Activemq
Apache Activemq 5.2.0
Apache Activemq 4.0
Apache Activemq 5.1.0
Apache Activemq 5.0.0
Apache Activemq 3.2.2
Apache Activemq 1.5
Apache Activemq 1.4
Apache Activemq 4.0.2
Apache Activemq 4.0.1
Apache Activemq 3.1
Apache Activemq 3.0
Apache Activemq 4.1.1
Apache Activemq 4.1.0
Apache Activemq 3.2.1
Apache Activemq 3.2
Apache Activemq 1.3
Apache Activemq 1.2
Apache Activemq 1.1
Apache Activemq 2.0
Apache Activemq 2.1
5.8
CVSSv2
CVE-2012-5784
Apache Axis 1.4 and previous versions, as used in PayPal Payments Pro, PayPal Mass Pay, PayPal Transactional Information SOAP, the Java Message Service implementation in Apache ActiveMQ, and other products, does not verify that the server hostname matches a domain name in the sub...
Apache Axis 1.0
Paypal Mass Pay -
Apache Axis -
Apache Axis 1.1
Apache Axis 1.2
Paypal Transactional Information Soap -
Paypal Payments Pro -
Apache Axis 1.2.1
Apache Activemq
Apache Axis
Apache Axis 1.3
5
CVSSv2
CVE-2014-7816
Directory traversal vulnerability in JBoss Undertow 1.0.x prior to 1.0.17, 1.1.x prior to 1.1.0.CR5, and 1.2.x prior to 1.2.0.Beta3, when running on Windows, allows remote malicious users to read arbitrary files via a .. (dot dot) in a resource URI.
Redhat Undertow
5
CVSSv2
CVE-2011-4905
Apache ActiveMQ prior to 5.6.0 allows remote malicious users to cause a denial of service (file-descriptor exhaustion and broker crash or hang) by sending many openwire failover:tcp:// connection requests.
Apache Activemq 5.3.1
Apache Activemq 5.3.0
Apache Activemq 5.2.0
Apache Activemq 5.1.0
Apache Activemq 3.0
Apache Activemq 2.1
Apache Activemq 2.0
Apache Activemq 1.5
Apache Activemq
Apache Activemq 5.5.0
Apache Activemq 5.4.3
Apache Activemq 4.0.2
Apache Activemq 4.0.1
Apache Activemq 4.0
Apache Activemq 5.4.2
Apache Activemq 5.4.0
Apache Activemq 4.1.2
Apache Activemq 4.1.0
Apache Activemq 3.2.1
Apache Activemq 3.1
Apache Activemq 1.4
Apache Activemq 1.2
3.5
CVSSv2
CVE-2010-0684
Cross-site scripting (XSS) vulnerability in createDestination.action in Apache ActiveMQ prior to 5.3.1 allows remote authenticated users to inject arbitrary web script or HTML via the JMSDestination parameter in a queue action.
Apache Activemq
Apache Activemq 4.0.1
Apache Activemq 4.0
Apache Activemq 3.0
Apache Activemq 2.0
Apache Activemq 5.2.0
Apache Activemq 5.1.0
Apache Activemq 2.1
Apache Activemq 1.5
Apache Activemq 4.1.0
Apache Activemq 4.0.2
Apache Activemq 3.2
Apache Activemq 3.1
Apache Activemq 1.1
Apache Activemq 5.0.0
Apache Activemq 4.1.1
Apache Activemq 3.2.2
Apache Activemq 3.2.1
Apache Activemq 1.4
Apache Activemq 1.3
Apache Activemq 1.2
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7073
CVE-2024-5496
CVE-2024-5495
XPath injection
bypass
CVE-2024-30043
CVE-2024-24919
denial of service
CVE-2024-35468
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started