Skip to main content

Vendor archive

squid-cache CVEs

Beta · best-effort

111 CVEs tagged to vendor squid-cache11 Critical, 47 High, 50 Medium, 3 Low, 0 Unrated.

CVE-2012-2213

Published Apr 28, 2012

Squid 3.1.9 allows remote attackers to bypass the access configuration for the CONNECT method by providing an arbitrary allowed hostname in the Host HTTP header. NOTE: this issue…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4096

Published Nov 17, 2011

The idnsGrokReply function in Squid before 3.1.16 does not properly free memory, which allows remote attackers to cause a denial of service (daemon abort) via a DNS reply containi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-3205

Published Sep 6, 2011

Buffer overflow in the gopherToHTML function in gopher.cc in the Gopher reply parser in Squid 3.0 before 3.0.STABLE26, 3.1 before 3.1.15, and 3.2 before 3.2.0.11 allows remote Gop…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-2951

Published Oct 12, 2010

dns_internal.cc in Squid 3.1.6, when IPv6 DNS resolution is not enabled, accesses an invalid socket during an IPv4 TCP DNS query, which allows remote attackers to cause a denial o…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3072

Published Sep 20, 2010

The string-comparison functions in String.cci in Squid 3.x before 3.1.8 and 3.2.x before 3.2.0.2 allow remote attackers to cause a denial of service (NULL pointer dereference and…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0639

Published Feb 15, 2010

The htcpHandleTstRequest function in htcp.c in Squid 2.x before 2.6.STABLE24 and 2.7 before 2.7.STABLE8, and htcp.cc in 3.0 before 3.0.STABLE24, allows remote attackers to cause a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0308

Published Feb 3, 2010

lib/rfc1035.c in Squid 2.x, 3.0 through 3.0.STABLE22, and 3.1 through 3.1.0.15 allows remote attackers to cause a denial of service (assertion failure) via a crafted DNS packet th…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2855

Published Aug 18, 2009

The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2622

Published Jul 28, 2009

Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 allows remote attackers to cause a denial of service via malformed requests including (1) "missing or mismatched protocol i…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-2621

Published Jul 28, 2009

Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 does not properly enforce "buffer limits and related bound checks," which allows remote attackers to cause a denial of serv…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-0211

Published May 2, 2005

Buffer overflow in wccp.c in Squid 2.5 before 2.5.STABLE7 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long WCCP packet, which is…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 101-111 of 111 CVEsPage 5 of 5