Skip to main content

Vendor archive

squid-cache CVEs

Beta · best-effort

111 CVEs tagged to vendor squid-cache11 Critical, 47 High, 50 Medium, 3 Low, 0 Unrated.

CVE-2016-4052

Published Apr 25, 2016

Multiple stack-based buffer overflows in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote HTTP servers to cause a denial of service or execute arbitrary code via crafted…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2390

Published Apr 19, 2016

The FwdState::connectedToPeer method in FwdState.cc in Squid before 3.5.14 and 4.0.x before 4.0.6 does not properly handle SSL handshake errors when built with the --with-openssl…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-3948

Published Apr 7, 2016

Squid 3.x before 3.5.16 and 4.x before 4.0.8 improperly perform bounds checking, which allows remote attackers to cause a denial of service via a crafted HTTP response, related to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3947

Published Apr 7, 2016

Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.cc in the pinger utility in Squid before 3.5.16 and 4.x before 4.0.8 allows remote servers to cause a denial o…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2572

Published Feb 27, 2016

http.cc in Squid 4.x before 4.0.7 relies on the HTTP status code after a response-parsing failure, which allows remote HTTP servers to cause a denial of service (assertion failure…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2571

Published Feb 27, 2016

http.cc in Squid 3.x before 3.5.15 and 4.x before 4.0.7 proceeds with the storage of certain data after a response-parsing failure, which allows remote HTTP servers to cause a den…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2570

Published Feb 27, 2016

The Edge Side Includes (ESI) parser in Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not check buffer limits during XML parsing, which allows remote HTTP servers to cause a de…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-2569

Published Feb 27, 2016

Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of service (assertion failure and daemo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-9749

Published Nov 6, 2015

Squid 3.4.4 through 3.4.11 and 3.5.0.1 through 3.5.1, when Digest authentication is used, allow remote authenticated users to retain access by leveraging a stale nonce, aka "Nonce…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2015-0881

Published Feb 20, 2015

CRLF injection vulnerability in Squid before 3.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted header in a r…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-7141

Published Nov 26, 2014

The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and crash) via a crafted type in an (…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-6270

Published Sep 12, 2014

Off-by-one error in the snmpHandleUdp function in snmp_core.cc in Squid 2.x and 3.x, when an SNMP port is configured, allows remote attackers to cause a denial of service (crash)…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3609

Published Sep 11, 2014

HttpHdrRange.cc in Squid 3.x before 3.3.12 and 3.4.x before 3.4.6 allows remote attackers to cause a denial of service (crash) via a request with crafted "Range headers with unide…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-0128

Published Apr 14, 2014

Squid 3.1 before 3.3.12 and 3.4 before 3.4.4, when SSL-Bump is enabled, allows remote attackers to cause a denial of service (assertion failure) via a crafted range request, relat…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1839

Published Sep 30, 2013

The strHdrAcptLangGetItem function in errorpage.cc in Squid 3.2.x before 3.2.9 and 3.3.x before 3.3.3 allows remote attackers to cause a denial of service (infinite loop and CPU c…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-4123

Published Sep 16, 2013

client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of service via a crafted port number in a HTTP Host header.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4115

Published Aug 9, 2013

Buffer overflow in the idnsALookup function in dns_internal.cc in Squid 3.2 through 3.2.11 and 3.3 through 3.3.6 allows remote attackers to cause a denial of service (memory corru…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-0189

Published Feb 8, 2013

cachemgr.cgi in Squid 3.1.x and 3.2.x, possibly 3.1.22, 3.2.4, and other versions, allows remote attackers to cause a denial of service (resource consumption) via a crafted reques…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5643

Published Dec 20, 2012

Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and 3.x before 3.1.22, 3.2.x before 3.2.4, and 3.3.x before 3.3.0.2 allow remote attackers to cause a denia…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 76-100 of 111 CVEsPage 4 of 5