Show filters
82 Total Results
Displaying 31-40 of 82
Sort by:
Attacker Value
Unknown

CVE-2016-3948

Disclosure Date: April 07, 2016 (last updated November 25, 2024)
Squid 3.x before 3.5.16 and 4.x before 4.0.8 improperly perform bounds checking, which allows remote attackers to cause a denial of service via a crafted HTTP response, related to Vary headers.
0
Attacker Value
Unknown

CVE-2016-2571

Disclosure Date: February 27, 2016 (last updated November 25, 2024)
http.cc in Squid 3.x before 3.5.15 and 4.x before 4.0.7 proceeds with the storage of certain data after a response-parsing failure, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a malformed response.
0
Attacker Value
Unknown

CVE-2016-2570

Disclosure Date: February 27, 2016 (last updated November 25, 2024)
The Edge Side Includes (ESI) parser in Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not check buffer limits during XML parsing, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a crafted XML document, related to esi/CustomParser.cc and esi/CustomParser.h.
0
Attacker Value
Unknown

CVE-2016-2569

Disclosure Date: February 27, 2016 (last updated November 25, 2024)
Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of service (assertion failure and daemon exit) via a long string, as demonstrated by a crafted HTTP Vary header.
0
Attacker Value
Unknown

CVE-2014-6270

Disclosure Date: September 12, 2014 (last updated October 05, 2023)
Off-by-one error in the snmpHandleUdp function in snmp_core.cc in Squid 2.x and 3.x, when an SNMP port is configured, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted UDP SNMP request, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2013-0149

Disclosure Date: August 05, 2013 (last updated October 05, 2023)
The OSPF implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.3, IOS-XE 2.x through 3.9.xS, ASA and PIX 7.x through 9.1, FWSM, NX-OS, and StarOS before 14.0.50488 does not properly validate Link State Advertisement (LSA) type 1 packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a (1) unicast or (2) multicast packet, aka Bug IDs CSCug34485, CSCug34469, CSCug39762, CSCug63304, and CSCug39795.
0
Attacker Value
Unknown

CVE-2012-5643

Disclosure Date: December 20, 2012 (last updated October 05, 2023)
Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and 3.x before 3.1.22, 3.2.x before 3.2.4, and 3.3.x before 3.3.0.2 allow remote attackers to cause a denial of service (memory consumption) via (1) invalid Content-Length headers, (2) long POST requests, or (3) crafted authentication credentials.
0
Attacker Value
Unknown

CVE-2011-4096

Disclosure Date: November 17, 2011 (last updated October 04, 2023)
The idnsGrokReply function in Squid before 3.1.16 does not properly free memory, which allows remote attackers to cause a denial of service (daemon abort) via a DNS reply containing a CNAME record that references another CNAME record that contains an empty A record.
0
Attacker Value
Unknown

CVE-2011-3205

Disclosure Date: September 06, 2011 (last updated November 08, 2023)
Buffer overflow in the gopherToHTML function in gopher.cc in the Gopher reply parser in Squid 3.0 before 3.0.STABLE26, 3.1 before 3.1.15, and 3.2 before 3.2.0.11 allows remote Gopher servers to cause a denial of service (memory corruption and daemon restart) or possibly have unspecified other impact via a long line in a response. NOTE: This issue exists because of a CVE-2005-0094 regression.
0
Attacker Value
Unknown

CVE-2011-1924

Disclosure Date: June 14, 2011 (last updated October 04, 2023)
Buffer overflow in the policy_summarize function in or/policies.c in Tor before 0.2.1.30 allows remote attackers to cause a denial of service (directory authority crash) via a crafted policy that triggers creation of a long port list.
0