Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown

CVE-2007-6239

Disclosure Date: December 04, 2007 (last updated October 04, 2023)
The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial of service (crash) via unknown vectors related to HTTP headers and an Array memory leak during requests for cached objects.
0
Attacker Value
Unknown

CVE-2005-3258

Disclosure Date: October 20, 2005 (last updated February 22, 2025)
The rfc1738_do_escape function in ftp.c for Squid 2.5 STABLE11 and earlier allows remote FTP servers to cause a denial of service (segmentation fault) via certain "odd" responses.
0
Attacker Value
Unknown

CVE-2005-2794

Disclosure Date: September 07, 2005 (last updated February 22, 2025)
store.c in Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (crash) via certain aborted requests that trigger an assert error related to STORE_PENDING.
0
Attacker Value
Unknown

CVE-2005-2796

Disclosure Date: September 07, 2005 (last updated February 22, 2025)
The sslConnectTimeout function in ssl.c for Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (segmentation fault) via certain crafted requests.
0
Attacker Value
Unknown

CVE-2005-0173

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a username with a space at the beginning or end, which is ignored by the LDAP server.
0
Attacker Value
Unknown

CVE-2005-0194

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.
0
Attacker Value
Unknown

CVE-2005-0446

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Qualified Domain Names (FQDN) in fqdncache.c or (2) IP addresses in ipcache.c, which trigger an assertion failure.
0
Attacker Value
Unknown

CVE-2005-0718

Disclosure Date: April 14, 2005 (last updated February 22, 2025)
Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (segmentation fault) by aborting the connection during a (1) PUT or (2) POST request, which causes Squid to access previously freed memory.
0
Attacker Value
Unknown

CVE-2004-0918

Disclosure Date: January 27, 2005 (last updated February 22, 2025)
The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of service (server restart) via certain SNMP packets with negative length fields that trigger a memory allocation error.
0
Attacker Value
Unknown

CVE-2005-0096

Disclosure Date: January 25, 2005 (last updated February 22, 2025)
Memory leak in the NTLM fakeauth_auth helper for Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (memory consumption).
0