Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown

CVE-2014-7142

Disclosure Date: November 26, 2014 (last updated October 05, 2023)
The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (crash) via a crafted (1) ICMP or (2) ICMP6 packet size.
0
Attacker Value
Unknown

CVE-2014-7141

Disclosure Date: November 26, 2014 (last updated October 05, 2023)
The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and crash) via a crafted type in an (1) ICMP or (2) ICMP6 packet.
0
Attacker Value
Unknown

CVE-2014-6270

Disclosure Date: September 12, 2014 (last updated October 05, 2023)
Off-by-one error in the snmpHandleUdp function in snmp_core.cc in Squid 2.x and 3.x, when an SNMP port is configured, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted UDP SNMP request, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2014-3609

Disclosure Date: September 11, 2014 (last updated October 05, 2023)
HttpHdrRange.cc in Squid 3.x before 3.3.12 and 3.4.x before 3.4.6 allows remote attackers to cause a denial of service (crash) via a request with crafted "Range headers with unidentifiable byte-range values."
0
Attacker Value
Unknown

CVE-2014-0128

Disclosure Date: April 14, 2014 (last updated October 05, 2023)
Squid 3.1 before 3.3.12 and 3.4 before 3.4.4, when SSL-Bump is enabled, allows remote attackers to cause a denial of service (assertion failure) via a crafted range request, related to state management.
0
Attacker Value
Unknown

CVE-2013-0189

Disclosure Date: February 08, 2013 (last updated November 08, 2023)
cachemgr.cgi in Squid 3.1.x and 3.2.x, possibly 3.1.22, 3.2.4, and other versions, allows remote attackers to cause a denial of service (resource consumption) via a crafted request. NOTE: this issue is due to an incorrect fix for CVE-2012-5643, possibly involving an incorrect order of arguments or incorrect comparison.
0
Attacker Value
Unknown

CVE-2011-4096

Disclosure Date: November 17, 2011 (last updated October 04, 2023)
The idnsGrokReply function in Squid before 3.1.16 does not properly free memory, which allows remote attackers to cause a denial of service (daemon abort) via a DNS reply containing a CNAME record that references another CNAME record that contains an empty A record.
0
Attacker Value
Unknown

CVE-2011-3205

Disclosure Date: September 06, 2011 (last updated November 08, 2023)
Buffer overflow in the gopherToHTML function in gopher.cc in the Gopher reply parser in Squid 3.0 before 3.0.STABLE26, 3.1 before 3.1.15, and 3.2 before 3.2.0.11 allows remote Gopher servers to cause a denial of service (memory corruption and daemon restart) or possibly have unspecified other impact via a long line in a response. NOTE: This issue exists because of a CVE-2005-0094 regression.
0