Vulnerability index

Browse CVEs

45 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Squid MEDIUM 6.8
CVE-2014-6270EPSS 23%

Off-by-one error in the snmpHandleUdp function in snmp_core.cc in Squid 2.x and 3.x, when an SNMP port is configured, allows remote attackers to caus…

Patch available
Fix from $1,600 2014-09-12
Squid MEDIUM 5.0
CVE-2014-3609EPSS 56%

HttpHdrRange.cc in Squid 3.x before 3.3.12 and 3.4.x before 3.4.6 allows remote attackers to cause a denial of service (crash) via a request with cra…

Patch available
Fix from $1,600 2014-09-11
Squid MEDIUM 5.0
CVE-2014-0128EPSS 33%

Squid 3.1 before 3.3.12 and 3.4 before 3.4.4, when SSL-Bump is enabled, allows remote attackers to cause a denial of service (assertion failure) via …

Mitigation only
Fix from $1,600 2014-04-14
Squid HIGH 7.8
CVE-2013-1839EPSS 18%

The strHdrAcptLangGetItem function in errorpage.cc in Squid 3.2.x before 3.2.9 and 3.3.x before 3.3.3 allows remote attackers to cause a denial of se…

Mitigation only
Fix from $1,950 2013-09-30
Squid MEDIUM 5.0
CVE-2013-4123EPSS 80%

client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of service via a crafted port nu…

Patch available
Fix from $1,600 2013-09-16
Squid MEDIUM 5.0
CVE-2012-5643EPSS 23%

Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and 3.x before 3.1.22, 3.2.x before 3.2.4, and 3.3.x before 3.3.0.2 allow rem…

Patch available
Fix from $1,600 2012-12-20
Squid MEDIUM 5.0
CVE-2012-2213EPSS 12%

Squid 3.1.9 allows remote attackers to bypass the access configuration for the CONNECT method by providing an arbitrary allowed hostname in the Host …

Mitigation only
Fix from $1,600 2012-04-28
Squid MEDIUM 5.0
CVE-2011-4096EPSS 37%

The idnsGrokReply function in Squid before 3.1.16 does not properly free memory, which allows remote attackers to cause a denial of service (daemon a…

Fix: after 3.1.15
Fix from $1,600 2011-11-17
Squid MEDIUM 6.8
CVE-2011-3205EPSS 27%

Buffer overflow in the gopherToHTML function in gopher.cc in the Gopher reply parser in Squid 3.0 before 3.0.STABLE26, 3.1 before 3.1.15, and 3.2 bef…

Patch available
Fix from $1,600 2011-09-06
Squid MEDIUM 5.0
CVE-2010-2951EPSS 31%

dns_internal.cc in Squid 3.1.6, when IPv6 DNS resolution is not enabled, accesses an invalid socket during an IPv4 TCP DNS query, which allows remote…

Patch available
Fix from $1,600 2010-10-12
Squid MEDIUM 5.0
CVE-2010-3072EPSS 64%

The string-comparison functions in String.cci in Squid 3.x before 3.1.8 and 3.2.x before 3.2.0.2 allow remote attackers to cause a denial of service …

Patch available
Fix from $1,600 2010-09-20
Squid MEDIUM 5.0
CVE-2010-0639EPSS 31%

The htcpHandleTstRequest function in htcp.c in Squid 2.x before 2.6.STABLE24 and 2.7 before 2.7.STABLE8, and htcp.cc in 3.0 before 3.0.STABLE24, allo…

Patch available
Fix from $1,600 2010-02-15
Squid MEDIUM 5.0
CVE-2009-2855EPSS 37%

The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with…

Mitigation only
Fix from $1,600 2009-08-18
Squid MEDIUM 5.0
CVE-2009-2621EPSS 23%

Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 does not properly enforce "buffer limits and related bound checks," which allows remote attac…

Patch available
Fix from $1,600 2009-07-28
Squid MEDIUM 5.0
CVE-2009-2622EPSS 57%

Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 allows remote attackers to cause a denial of service via malformed requests including (1) "mi…

Patch available
Fix from $1,600 2009-07-28