Show filters
173 Total Results
Displaying 111-120 of 173
Sort by:
Attacker Value
Unknown

CVE-2010-0639

Disclosure Date: February 15, 2010 (last updated October 04, 2023)
The htcpHandleTstRequest function in htcp.c in Squid 2.x before 2.6.STABLE24 and 2.7 before 2.7.STABLE8, and htcp.cc in 3.0 before 3.0.STABLE24, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via crafted packets to the HTCP port.
0
Attacker Value
Unknown

CVE-2010-0308

Disclosure Date: February 03, 2010 (last updated October 04, 2023)
lib/rfc1035.c in Squid 2.x, 3.0 through 3.0.STABLE22, and 3.1 through 3.1.0.15 allows remote attackers to cause a denial of service (assertion failure) via a crafted DNS packet that only contains a header.
0
Attacker Value
Unknown

CVE-2009-3826

Disclosure Date: October 28, 2009 (last updated October 04, 2023)
Multiple buffer overflows in squidGuard 1.4 allow remote attackers to bypass intended URL blocking via a long URL, related to (1) the relationship between a certain buffer size in squidGuard and a certain buffer size in Squid and (2) a redirect URL that contains information about the originally requested URL.
0
Attacker Value
Unknown

CVE-2009-3700

Disclosure Date: October 28, 2009 (last updated October 04, 2023)
Buffer overflow in sgLog.c in squidGuard 1.3 and 1.4 allows remote attackers to cause a denial of service (application hang or loss of blocking functionality) via a long URL with many / (slash) characters, related to "emergency mode."
0
Attacker Value
Unknown

CVE-2009-2855

Disclosure Date: August 18, 2009 (last updated October 04, 2023)
The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.
0
Attacker Value
Unknown

CVE-2009-2622

Disclosure Date: July 28, 2009 (last updated October 04, 2023)
Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 allows remote attackers to cause a denial of service via malformed requests including (1) "missing or mismatched protocol identifier," (2) missing or negative status value," (3) "missing version," or (4) "missing or invalid status number," related to (a) HttpMsg.cc and (b) HttpReply.cc.
0
Attacker Value
Unknown

CVE-2009-2621

Disclosure Date: July 28, 2009 (last updated October 04, 2023)
Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 does not properly enforce "buffer limits and related bound checks," which allows remote attackers to cause a denial of service via (1) an incomplete request or (2) a request with a large header size, related to (a) HttpMsg.cc and (b) client_side.cc.
0
Attacker Value
Unknown

CVE-2009-0801

Disclosure Date: March 04, 2009 (last updated October 04, 2023)
Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.
0
Attacker Value
Unknown

CVE-2009-0478

Disclosure Date: February 08, 2009 (last updated October 04, 2023)
Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request with an invalid version number, which triggers a reachable assertion in (1) HttpMsg.c and (2) HttpStatusLine.c.
0
Attacker Value
Unknown

CVE-2008-2897

Disclosure Date: June 27, 2008 (last updated October 04, 2023)
SQL injection vulnerability in index.php in PageSquid CMS 0.3 Beta allows remote attackers to execute arbitrary SQL commands via the page parameter.
0