CVE-2012-4459: Apache Qpid

Medium severity, CVSS 5.0. EPSS: 9.2% chance of exploitation in the next 30 days.

Integer overflow in the qpid::framing::Buffer::checkAvailable function in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (crash) via a crafted message, which triggers an out-of-bounds read.

Affected products

  • Apache Qpid: up to and including 0.20; version 0.5 only; version 0.6 only; version 0.7 only; version 0.8 only; version 0.9 only; …

Published 2013-03-14. Last modified 2026-06-16.