Skip to main content

Vendor archive

squid-cache CVEs

Beta · best-effort

111 CVEs tagged to vendor squid-cache11 Critical, 47 High, 50 Medium, 3 Low, 0 Unrated.

CVE-2021-46784

Published Jul 17, 2022

In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41611

Published Oct 18, 2021

An issue was discovered in Squid 5.0.6 through 5.1.x before 5.2. When validating an origin server or peer certificate, Squid may incorrectly classify certain certificates as trust…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-14059

Published Jun 30, 2020

An issue was discovered in Squid 5.x before 5.0.3. Due to an Incorrect Synchronization, a Denial of Service can occur when processing objects in an SMP cache because of an Ipc::Me…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15049

Published Jun 30, 2020

An issue was discovered in http/ContentLengthInterpreter.cc in Squid before 4.12 and 5.x before 5.0.3. A Request Smuggling and Poisoning attack can succeed against the HTTP cache.…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-12522

Published Apr 15, 2020

An issue was discovered in Squid through 4.7. When Squid is run as root, it spawns its child processes as a lesser user, by default the user nobody. This is done via the leave_sui…

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 26-50 of 111 CVEsPage 2 of 5