CVE-2012-4459: Apache Qpid
Medium severity, CVSS 5.0. EPSS: 9.2% chance of exploitation in the next 30 days.
Integer overflow in the qpid::framing::Buffer::checkAvailable function in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (crash) via a crafted message, which triggers an out-of-bounds read.
Affected products
- Apache Qpid: up to and including 0.20; version 0.5 only; version 0.6 only; version 0.7 only; version 0.8 only; version 0.9 only; …
Published 2013-03-14. Last modified 2026-06-16.