Vulnerability index

Browse CVEs

32 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Squid Web Proxy Cache MEDIUM 5.4
CVE-2009-0801

Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to by…

Mitigation only
Fix from $1,600 2009-03-04
Squid MEDIUM 5.0
CVE-2009-0478EPSS 72%

Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request with an in…

Patch available
Fix from $1,600 2009-02-08
Squid Web Proxy Cache MEDIUM 5.0
CVE-2007-6239EPSS 27%

The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial of service…

Patch available
Fix from $1,600 2007-12-04
Squid MEDIUM 5.0
CVE-2007-1560EPSS 27%

The clientProcessRequest() function in src/client_side.c in Squid 2.6 before 2.6.STABLE12 allows remote attackers to cause a denial of service (daemo…

Patch available
Fix from $1,600 2007-03-21
Squid MEDIUM 5.0
CVE-2007-0247EPSS 20%

squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory listing resp…

Mitigation only
Fix from $1,600 2007-01-16
Squid MEDIUM 5.0
CVE-2007-0248EPSS 7%

The aclMatchExternal function in Squid before 2.6.STABLE7 allows remote attackers to cause a denial of service (crash) by causing an external_acl que…

Patch available
Fix from $1,600 2007-01-16
Squid MEDIUM 5.0
CVE-2005-3322

Unspecified vulnerability in Squid on SUSE Linux 9.0 allows remote attackers to cause a denial of service (crash) via HTTPs (SSL).

Mitigation only
Fix from $1,600 2005-10-27
Squid MEDIUM 5.0
CVE-2005-3258

The rfc1738_do_escape function in ftp.c for Squid 2.5 STABLE11 and earlier allows remote FTP servers to cause a denial of service (segmentation fault…

Patch available
Fix from $1,600 2005-10-20
Squid MEDIUM 5.0
CVE-2005-2917

Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to c…

Fix: after 2.5.stable10
Fix from $1,600 2005-09-30
Squid MEDIUM 5.0
CVE-2005-2794

store.c in Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (crash) via certain aborted requests that trigger an a…

Mitigation only
Fix from $1,600 2005-09-07
Squid MEDIUM 5.0
CVE-2005-2796EPSS 8%

The sslConnectTimeout function in ssl.c for Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (segmentation fault) …

Patch available
Fix from $1,600 2005-09-07
Squid MEDIUM 6.4
CVE-2005-1519

Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attackers to sp…

Fix: after 2.5_stable9
Fix from $1,600 2005-05-11
Squid HIGH 10.0
CVE-2005-0194EPSS 5%

Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, …

Patch available
Fix from $1,950 2005-05-02
Squid HIGH 7.5
CVE-2005-0173EPSS 32%

squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a username with a…

Patch available
Fix from $1,950 2005-05-02
Squid HIGH 7.5
CVE-2005-1345

Squid 2.5.STABLE9 and earlier does not trigger a fatal error when it identifies missing or invalid ACLs in the http_access configuration, which could…

Patch available
Fix from $1,950 2005-05-02
Squid MEDIUM 5.0
CVE-2005-0241EPSS 70%

The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling "oversize…

Patch available
Fix from $1,600 2005-05-02
Squid MEDIUM 5.0
CVE-2005-0446EPSS 41%

Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Qualified Do…

Patch available
Fix from $1,600 2005-05-02
Squid MEDIUM 5.0
CVE-2005-0718EPSS 13%

Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (segmentation fault) by aborting the connection during a (1) PUT o…

Mitigation only
Fix from $1,600 2005-04-14
Squid MEDIUM 5.0
CVE-2005-0174EPSS 51%

Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specificat…

Patch available
Fix from $1,600 2005-02-07
Squid MEDIUM 5.0
CVE-2005-0175EPSS 41%

Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.

Patch available
Fix from $1,600 2005-02-07
Squid MEDIUM 5.0
CVE-2005-0096EPSS 9%

Memory leak in the NTLM fakeauth_auth helper for Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (memory consumpti…

Patch available
Fix from $1,600 2005-01-25
Squid MEDIUM 5.0
CVE-2005-0094EPSS 9%

Buffer overflow in the gopherToHTML function in the Gopher reply parser for Squid 2.5.STABLE7 and earlier allows remote malicious Gopher servers to c…

Patch available
Fix from $1,600 2005-01-15
Squid MEDIUM 5.0
CVE-2005-0095EPSS 69%

The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WCCP messag…

Patch available
Fix from $1,600 2005-01-15
Squid MEDIUM 5.0
CVE-2005-0097EPSS 11%

The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3 message …

Patch available
Fix from $1,600 2005-01-11
Squid MEDIUM 5.0
CVE-2004-2654

The clientAbortBody function in client_side.c in Squid Web Proxy Cache before 2.6 STABLE6 allows remote attackers to cause a denial of service (segme…

Patch available
Fix from $1,600 2004-12-31
Squid MEDIUM 5.0
CVE-2004-0832EPSS 11%

The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and earlier, with NTLM authentication enabled, allow remote attackers to c…

Fix: after 2.5.6
Fix from $1,600 2004-11-03
Squid HIGH 7.5
CVE-2004-0189EPSS 14%

The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00") charac…

Patch available
Fix from $1,950 2004-03-15
Squid HIGH 7.5
CVE-2002-0713EPSS 6%

Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code (1) via …

Fix: after 2.4.stable6
Fix from $1,950 2002-07-26
Squid HIGH 7.5
CVE-2002-0714

FTP proxy in Squid before 2.4.STABLE6 does not compare the IP addresses of control and data connections with the FTP server, which allows remote atta…

Fix: after 2.4.stable6
Fix from $1,950 2002-07-26
Squid MEDIUM 5.0
CVE-2002-0715

Vulnerability in Squid before 2.4.STABLE6 related to proxy authentication credentials may allow remote web sites to obtain the user's proxy login and…

Fix: after 2.4.stable6
Fix from $1,600 2002-07-26