Show filters
19 Total Results
Displaying 1-10 of 19
Sort by:
Attacker Value
Unknown
CVE-2016-4555
Disclosure Date: May 10, 2016 (last updated November 25, 2024)
client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via crafted Edge Side Includes (ESI) responses.
0
Attacker Value
Unknown
CVE-2016-4556
Disclosure Date: May 10, 2016 (last updated November 25, 2024)
Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via a crafted Edge Side Includes (ESI) response.
0
Attacker Value
Unknown
CVE-2016-4053
Disclosure Date: April 25, 2016 (last updated November 25, 2024)
Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers to obtain sensitive stack layout information via crafted Edge Side Includes (ESI) responses, related to incorrect use of assert and compiler optimization.
0
Attacker Value
Unknown
CVE-2016-4051
Disclosure Date: April 25, 2016 (last updated November 25, 2024)
Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data.
0
Attacker Value
Unknown
CVE-2016-4052
Disclosure Date: April 25, 2016 (last updated November 25, 2024)
Multiple stack-based buffer overflows in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote HTTP servers to cause a denial of service or execute arbitrary code via crafted Edge Side Includes (ESI) responses.
0
Attacker Value
Unknown
CVE-2016-4054
Disclosure Date: April 25, 2016 (last updated November 25, 2024)
Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Includes (ESI) responses.
0
Attacker Value
Unknown
CVE-2016-3948
Disclosure Date: April 07, 2016 (last updated November 25, 2024)
Squid 3.x before 3.5.16 and 4.x before 4.0.8 improperly perform bounds checking, which allows remote attackers to cause a denial of service via a crafted HTTP response, related to Vary headers.
0
Attacker Value
Unknown
CVE-2016-2571
Disclosure Date: February 27, 2016 (last updated November 25, 2024)
http.cc in Squid 3.x before 3.5.15 and 4.x before 4.0.7 proceeds with the storage of certain data after a response-parsing failure, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a malformed response.
0
Attacker Value
Unknown
CVE-2016-2570
Disclosure Date: February 27, 2016 (last updated November 25, 2024)
The Edge Side Includes (ESI) parser in Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not check buffer limits during XML parsing, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a crafted XML document, related to esi/CustomParser.cc and esi/CustomParser.h.
0
Attacker Value
Unknown
CVE-2016-2569
Disclosure Date: February 27, 2016 (last updated November 25, 2024)
Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of service (assertion failure and daemon exit) via a long string, as demonstrated by a crafted HTTP Vary header.
0