VYPR
Vendor

Qos Ch

Products
4
CVEs
18
Across products
19
Status
Private

Products

4

Recent CVEs

18
  • CVE-2020-9493CriJun 16, 2021
    risk 0.64cvss 9.8epss 0.05

    A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution.

  • CVE-2022-23305CriJan 18, 2022
    risk 0.62cvss 9.8epss 0.67

    By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering…

  • CVE-2022-23302HigJan 18, 2022
    risk 0.62cvss 8.8epss 0.64

    JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a…

  • CVE-2022-23307HigJan 18, 2022
    risk 0.61cvss 8.8epss 0.54

    CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.

  • CVE-2018-8088CriMar 20, 2018
    risk 0.58cvss 9.8epss 0.15

    org.slf4j.ext.EventData in the slf4j-ext module in QOS.CH SLF4J before 1.8.0-beta2 allows remote attackers to bypass intended access restrictions via crafted data. EventData in the slf4j-ext module in QOS.CH SLF4J, has been fixed in SLF4J versions 1.7.26 later and in the 2.0.x…

  • CVE-2017-5929CriMar 13, 2017
    risk 0.57cvss 9.8epss 0.07

    QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.

  • CVE-2026-13006HigJun 24, 2026
    risk 0.46cvss epss 0.00

    ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.36 in Java applications, allows an attacker to execute arbitrary code circumventing existing protections against CVE-2025-11226 by compromising an existing…

  • CVE-2026-19880MedAug 14, 2026
    risk 0.41cvss epss

    Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, an MDC-based discriminator value flows unsanitized into a nested FileAppender path, letting an attacker who influences that MDC…

  • CVE-2025-11226HigOct 1, 2025
    risk 0.39cvss epss 0.00

    ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.18 in Java applications, allows an attacker to execute arbitrary code by compromising an existing logback configuration file or by injecting an environment…

  • CVE-2023-6481HigDec 4, 2023
    risk 0.39cvss 7.1epss 0.01

    A serialization vulnerability in logback receiver component part of logback version 1.4.13, 1.3.13 and 1.2.12 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.

  • CVE-2023-6378HigNov 29, 2023
    risk 0.39cvss 7.1epss 0.01

    A serialization vulnerability in logback receiver component part of logback version 1.4.11 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.

  • CVE-2021-42550MedDec 16, 2021
    risk 0.36cvss 6.6epss 0.04

    In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.

  • CVE-2024-12798MedDec 19, 2024
    risk 0.31cvss epss 0.00

    ACE vulnerability in JaninoEventEvaluator by QOS.CH logback-core upto including version 0.1 to 1.3.14 and 1.4.0 to 1.5.12 in Java applications allows attacker to execute arbitrary code by compromising an existing logback configuration file or by injecting an…

  • CVE-2026-10532LowJun 1, 2026
    risk 0.19cvss epss 0.00

    Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted. More precisely, an attacker able to influence serialized data sent to SimpleSocketServer…

  • CVE-2026-9828LowMay 28, 2026
    risk 0.19cvss epss 0.00

    Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted. More precisely, an attacker able to influence serialized data sent to SimpleSocketServer or…

  • CVE-2020-9488LowApr 27, 2020
    risk 0.18cvss 3.7epss 0.08

    Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1

  • CVE-2024-12801LowDec 19, 2024
    risk 0.09cvss epss 0.00

    Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 0.1 to 1.3.14 and 1.4.0 to 1.5.12  on the Java platform, allows an attacker to forge requests by compromising logback configuration files in XML. The attacks involves the modification of…

  • CVE-2026-1225LowJan 22, 2026
    risk 0.05cvss epss 0.00

    ACE vulnerability in configuration file processing by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file. The…