Show filters
173 Total Results
Displaying 121-130 of 173
Sort by:
Attacker Value
Unknown
CVE-2008-1922
Disclosure Date: May 13, 2008 (last updated October 04, 2023)
Multiple stack-based buffer overflows in Sarg might allow attackers to execute arbitrary code via unknown vectors, probably a crafted Squid log file.
0
Attacker Value
Unknown
CVE-2008-1612
Disclosure Date: April 01, 2008 (last updated November 08, 2023)
The arrayShrink function (lib/Array.c) in Squid 2.6.STABLE17 allows attackers to cause a denial of service (process exit) via unknown vectors that cause an array to shrink to 0 entries, which triggers an assert error. NOTE: this issue is due to an incorrect fix for CVE-2007-6239.
0
Attacker Value
Unknown
CVE-2008-1167
Disclosure Date: March 05, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in the useragent function in useragent.c in Squid Analysis Report Generator (Sarg) 2.2.3.1 allows remote attackers to execute arbitrary code via a long Squid proxy server User-Agent header. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2008-1168
Disclosure Date: March 05, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Squid Analysis Report Generator (Sarg) 2.2.3.1 allows remote attackers to inject arbitrary web script or HTML via the User-Agent header, which is not properly handled when displaying the Squid proxy log. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2007-6239
Disclosure Date: December 04, 2007 (last updated October 04, 2023)
The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial of service (crash) via unknown vectors related to HTTP headers and an Array memory leak during requests for cached objects.
0
Attacker Value
Unknown
CVE-2007-4936
Disclosure Date: September 18, 2007 (last updated October 04, 2023)
Unspecified vulnerability in Office Efficiencies SafeSquid 4.1.x has unknown impact and attack vectors, related to a "serious security flaw," possibly specific to Linux.
0
Attacker Value
Unknown
CVE-2007-1560
Disclosure Date: March 21, 2007 (last updated October 04, 2023)
The clientProcessRequest() function in src/client_side.c in Squid 2.6 before 2.6.STABLE12 allows remote attackers to cause a denial of service (daemon crash) via crafted TRACE requests that trigger an assertion error.
0
Attacker Value
Unknown
CVE-2007-0248
Disclosure Date: January 16, 2007 (last updated October 04, 2023)
The aclMatchExternal function in Squid before 2.6.STABLE7 allows remote attackers to cause a denial of service (crash) by causing an external_acl queue overload, which triggers an infinite loop.
0
Attacker Value
Unknown
CVE-2007-0247
Disclosure Date: January 16, 2007 (last updated October 04, 2023)
squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory listing responses, possibly related to the (1) ftpListingFinish and (2) ftpHtmlifyListEntry functions.
0
Attacker Value
Unknown
CVE-2005-3322
Disclosure Date: October 27, 2005 (last updated February 22, 2025)
Unspecified vulnerability in Squid on SUSE Linux 9.0 allows remote attackers to cause a denial of service (crash) via HTTPs (SSL).
0