Show filters
16 Total Results
Displaying 11-16 of 16
Sort by:
Attacker Value
Unknown

CVE-2005-0173

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a username with a space at the beginning or end, which is ignored by the LDAP server.
0
Attacker Value
Unknown

CVE-2005-0194

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.
0
Attacker Value
Unknown

CVE-2005-0446

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Qualified Domain Names (FQDN) in fqdncache.c or (2) IP addresses in ipcache.c, which trigger an assertion failure.
0
Attacker Value
Unknown

CVE-2005-0718

Disclosure Date: April 14, 2005 (last updated February 22, 2025)
Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (segmentation fault) by aborting the connection during a (1) PUT or (2) POST request, which causes Squid to access previously freed memory.
0
Attacker Value
Unknown

CVE-2004-0918

Disclosure Date: January 27, 2005 (last updated February 22, 2025)
The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of service (server restart) via certain SNMP packets with negative length fields that trigger a memory allocation error.
0
Attacker Value
Unknown

CVE-1999-1481

Disclosure Date: December 31, 1999 (last updated February 22, 2025)
Squid 2.2.STABLE5 and below, when using external authentication, allows attackers to bypass access controls via a newline in the user/password pair.
0