Show filters
158 Total Results
Displaying 21-30 of 158
Sort by:
Attacker Value
Unknown

CVE-2023-46724

Disclosure Date: November 01, 2023 (last updated February 14, 2025)
Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This bug is fixed in Squid version 6.4. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. Those who you use a prepackaged version of Squid should refer to the package vendor for availability information on updated packages.
Attacker Value
Unknown

CVE-2023-3580

Disclosure Date: July 10, 2023 (last updated October 08, 2023)
Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.
Attacker Value
Unknown

CVE-2023-24278

Disclosure Date: March 18, 2023 (last updated October 08, 2023)
Squidex before 7.4.0 was discovered to contain a squid.svg cross-site scripting (XSS) vulnerability.
Attacker Value
Unknown

CVE-2023-0643

Disclosure Date: February 02, 2023 (last updated October 08, 2023)
Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.
Attacker Value
Unknown

CVE-2023-0642

Disclosure Date: February 02, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) in GitHub repository squidex/squidex prior to 7.4.0.
Attacker Value
Unknown

CVE-2022-41318

Disclosure Date: December 25, 2022 (last updated October 08, 2023)
A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection, the SSPI and SMB authentication helpers are vulnerable to reading unintended memory locations. In some configurations, cleartext credentials from these locations are sent to a client. This is fixed in 5.7.
Attacker Value
Unknown

CVE-2022-41317

Disclosure Date: December 25, 2022 (last updated October 08, 2023)
An issue was discovered in Squid 4.9 through 4.17 and 5.0.6 through 5.6. Due to inconsistent handling of internal URIs, there can be Exposure of Sensitive Information about clients using the proxy via an HTTPS request to an internal cache manager URL. This is fixed in 5.7.
Attacker Value
Unknown

CVE-2021-46784

Disclosure Date: July 17, 2022 (last updated October 07, 2023)
In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses.
Attacker Value
Unknown

CVE-2021-41611

Disclosure Date: October 18, 2021 (last updated February 23, 2025)
An issue was discovered in Squid 5.0.6 through 5.1.x before 5.2. When validating an origin server or peer certificate, Squid may incorrectly classify certain certificates as trusted. This problem allows a remote server to obtain security trust well improperly. This indication of trust may be passed along to clients, allowing access to unsafe or hijacked services.
Attacker Value
Unknown

CVE-2021-31807

Disclosure Date: June 08, 2021 (last updated February 22, 2025)
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to achieve Denial of Service when delivering responses to HTTP Range requests. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent.