Show filters
103 Total Results
Displaying 91-100 of 103
Sort by:
Attacker Value
Unknown
CVE-2013-0189
Disclosure Date: February 08, 2013 (last updated November 08, 2023)
cachemgr.cgi in Squid 3.1.x and 3.2.x, possibly 3.1.22, 3.2.4, and other versions, allows remote attackers to cause a denial of service (resource consumption) via a crafted request. NOTE: this issue is due to an incorrect fix for CVE-2012-5643, possibly involving an incorrect order of arguments or incorrect comparison.
0
Attacker Value
Unknown
CVE-2012-5643
Disclosure Date: December 20, 2012 (last updated October 05, 2023)
Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and 3.x before 3.1.22, 3.2.x before 3.2.4, and 3.3.x before 3.3.0.2 allow remote attackers to cause a denial of service (memory consumption) via (1) invalid Content-Length headers, (2) long POST requests, or (3) crafted authentication credentials.
0
Attacker Value
Unknown
CVE-2012-2213
Disclosure Date: April 28, 2012 (last updated November 08, 2023)
Squid 3.1.9 allows remote attackers to bypass the access configuration for the CONNECT method by providing an arbitrary allowed hostname in the Host HTTP header. NOTE: this issue might not be reproducible, because the researcher is unable to provide a squid.conf file for a vulnerable system, and the observed behavior is consistent with a squid.conf file that was (perhaps inadvertently) designed to allow access based on a "req_header Host" acl regex that matches www.uol.com.br
0
Attacker Value
Unknown
CVE-2011-4096
Disclosure Date: November 17, 2011 (last updated October 04, 2023)
The idnsGrokReply function in Squid before 3.1.16 does not properly free memory, which allows remote attackers to cause a denial of service (daemon abort) via a DNS reply containing a CNAME record that references another CNAME record that contains an empty A record.
0
Attacker Value
Unknown
CVE-2011-3205
Disclosure Date: September 06, 2011 (last updated November 08, 2023)
Buffer overflow in the gopherToHTML function in gopher.cc in the Gopher reply parser in Squid 3.0 before 3.0.STABLE26, 3.1 before 3.1.15, and 3.2 before 3.2.0.11 allows remote Gopher servers to cause a denial of service (memory corruption and daemon restart) or possibly have unspecified other impact via a long line in a response. NOTE: This issue exists because of a CVE-2005-0094 regression.
0
Attacker Value
Unknown
CVE-2010-2951
Disclosure Date: October 12, 2010 (last updated October 04, 2023)
dns_internal.cc in Squid 3.1.6, when IPv6 DNS resolution is not enabled, accesses an invalid socket during an IPv4 TCP DNS query, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via vectors that trigger an IPv4 DNS response with the TC bit set.
0
Attacker Value
Unknown
CVE-2010-3072
Disclosure Date: September 20, 2010 (last updated October 04, 2023)
The string-comparison functions in String.cci in Squid 3.x before 3.1.8 and 3.2.x before 3.2.0.2 allow remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request.
0
Attacker Value
Unknown
CVE-2010-0639
Disclosure Date: February 15, 2010 (last updated October 04, 2023)
The htcpHandleTstRequest function in htcp.c in Squid 2.x before 2.6.STABLE24 and 2.7 before 2.7.STABLE8, and htcp.cc in 3.0 before 3.0.STABLE24, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via crafted packets to the HTCP port.
0
Attacker Value
Unknown
CVE-2010-0308
Disclosure Date: February 03, 2010 (last updated October 04, 2023)
lib/rfc1035.c in Squid 2.x, 3.0 through 3.0.STABLE22, and 3.1 through 3.1.0.15 allows remote attackers to cause a denial of service (assertion failure) via a crafted DNS packet that only contains a header.
0
Attacker Value
Unknown
CVE-2009-2855
Disclosure Date: August 18, 2009 (last updated October 04, 2023)
The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.
0