Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown

CVE-2016-3948

Disclosure Date: April 07, 2016 (last updated November 25, 2024)
Squid 3.x before 3.5.16 and 4.x before 4.0.8 improperly perform bounds checking, which allows remote attackers to cause a denial of service via a crafted HTTP response, related to Vary headers.
0
Attacker Value
Unknown

CVE-2016-2571

Disclosure Date: February 27, 2016 (last updated November 25, 2024)
http.cc in Squid 3.x before 3.5.15 and 4.x before 4.0.7 proceeds with the storage of certain data after a response-parsing failure, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a malformed response.
0
Attacker Value
Unknown

CVE-2016-2570

Disclosure Date: February 27, 2016 (last updated November 25, 2024)
The Edge Side Includes (ESI) parser in Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not check buffer limits during XML parsing, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a crafted XML document, related to esi/CustomParser.cc and esi/CustomParser.h.
0
Attacker Value
Unknown

CVE-2016-2569

Disclosure Date: February 27, 2016 (last updated November 25, 2024)
Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of service (assertion failure and daemon exit) via a long string, as demonstrated by a crafted HTTP Vary header.
0
Attacker Value
Unknown

CVE-2016-2572

Disclosure Date: February 27, 2016 (last updated November 25, 2024)
http.cc in Squid 4.x before 4.0.7 relies on the HTTP status code after a response-parsing failure, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a malformed response.
0