Show filters
103 Total Results
Displaying 61-70 of 103
Sort by:
Attacker Value
Unknown

CVE-2018-1000027

Disclosure Date: February 09, 2018 (last updated November 26, 2024)
The Squid Software Foundation Squid HTTP Caching Proxy version prior to version 4.0.23 contains a NULL Pointer Dereference vulnerability in HTTP Response X-Forwarded-For header processing that can result in Denial of Service to all clients of the proxy. This attack appear to be exploitable via Remote HTTP server responding with an X-Forwarded-For header to certain types of HTTP request. This vulnerability appears to have been fixed in 4.0.23 and later.
0
Attacker Value
Unknown

CVE-2016-10003

Disclosure Date: January 27, 2017 (last updated February 02, 2024)
Incorrect HTTP Request header comparison in Squid HTTP Proxy 3.5.0.1 through 3.5.22, and 4.0.1 through 4.0.16 results in Collapsed Forwarding feature mistakenly identifying some private responses as being suitable for delivery to multiple clients.
Attacker Value
Unknown

CVE-2016-10002

Disclosure Date: January 27, 2017 (last updated November 25, 2024)
Incorrect processing of responses to If-None-Modified HTTP conditional requests in Squid HTTP Proxy 3.1.10 through 3.1.23, 3.2.0.3 through 3.5.22, and 4.0.1 through 4.0.16 leads to client-specific Cookie data being leaked to other clients. Attack requests can easily be crafted by a client to probe a cache for this information.
0
Attacker Value
Unknown

CVE-2016-4555

Disclosure Date: May 10, 2016 (last updated November 25, 2024)
client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via crafted Edge Side Includes (ESI) responses.
0
Attacker Value
Unknown

CVE-2016-4556

Disclosure Date: May 10, 2016 (last updated November 25, 2024)
Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via a crafted Edge Side Includes (ESI) response.
0
Attacker Value
Unknown

CVE-2016-4554

Disclosure Date: May 10, 2016 (last updated November 25, 2024)
mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crafted HTTP Host header, aka a "header smuggling" issue.
0
Attacker Value
Unknown

CVE-2016-4553

Disclosure Date: May 10, 2016 (last updated November 25, 2024)
client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.
0
Attacker Value
Unknown

CVE-2016-4053

Disclosure Date: April 25, 2016 (last updated November 25, 2024)
Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers to obtain sensitive stack layout information via crafted Edge Side Includes (ESI) responses, related to incorrect use of assert and compiler optimization.
0
Attacker Value
Unknown

CVE-2016-4051

Disclosure Date: April 25, 2016 (last updated November 25, 2024)
Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data.
0
Attacker Value
Unknown

CVE-2016-4052

Disclosure Date: April 25, 2016 (last updated November 25, 2024)
Multiple stack-based buffer overflows in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote HTTP servers to cause a denial of service or execute arbitrary code via crafted Edge Side Includes (ESI) responses.
0