Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown
CVE-2016-4051
Disclosure Date: April 25, 2016 (last updated November 25, 2024)
Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data.
0
Attacker Value
Unknown
CVE-2012-5643
Disclosure Date: December 20, 2012 (last updated October 05, 2023)
Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and 3.x before 3.1.22, 3.2.x before 3.2.4, and 3.3.x before 3.3.0.2 allow remote attackers to cause a denial of service (memory consumption) via (1) invalid Content-Length headers, (2) long POST requests, or (3) crafted authentication credentials.
0
Attacker Value
Unknown
CVE-2010-0639
Disclosure Date: February 15, 2010 (last updated October 04, 2023)
The htcpHandleTstRequest function in htcp.c in Squid 2.x before 2.6.STABLE24 and 2.7 before 2.7.STABLE8, and htcp.cc in 3.0 before 3.0.STABLE24, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via crafted packets to the HTCP port.
0
Attacker Value
Unknown
CVE-2010-0308
Disclosure Date: February 03, 2010 (last updated October 04, 2023)
lib/rfc1035.c in Squid 2.x, 3.0 through 3.0.STABLE22, and 3.1 through 3.1.0.15 allows remote attackers to cause a denial of service (assertion failure) via a crafted DNS packet that only contains a header.
0
Attacker Value
Unknown
CVE-2008-1167
Disclosure Date: March 05, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in the useragent function in useragent.c in Squid Analysis Report Generator (Sarg) 2.2.3.1 allows remote attackers to execute arbitrary code via a long Squid proxy server User-Agent header. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2008-1168
Disclosure Date: March 05, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Squid Analysis Report Generator (Sarg) 2.2.3.1 allows remote attackers to inject arbitrary web script or HTML via the User-Agent header, which is not properly handled when displaying the Squid proxy log. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2005-3258
Disclosure Date: October 20, 2005 (last updated February 22, 2025)
The rfc1738_do_escape function in ftp.c for Squid 2.5 STABLE11 and earlier allows remote FTP servers to cause a denial of service (segmentation fault) via certain "odd" responses.
0
Attacker Value
Unknown
CVE-2005-2794
Disclosure Date: September 07, 2005 (last updated February 22, 2025)
store.c in Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (crash) via certain aborted requests that trigger an assert error related to STORE_PENDING.
0
Attacker Value
Unknown
CVE-2005-2796
Disclosure Date: September 07, 2005 (last updated February 22, 2025)
The sslConnectTimeout function in ssl.c for Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (segmentation fault) via certain crafted requests.
0
Attacker Value
Unknown
CVE-2005-1711
Disclosure Date: May 24, 2005 (last updated February 22, 2025)
Gibraltar Firewall 2.2 and earlier, when using the ClamAV update to 0.81 for Squid, uses a defunct ClamAV method to scan memory for viruses, which does not return an error code and prevents viruses from being detected.
0