Show filters
20 Total Results
Displaying 1-10 of 20
Sort by:
Attacker Value
Unknown
CVE-2016-4051
Disclosure Date: April 25, 2016 (last updated November 25, 2024)
Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data.
0
Attacker Value
Unknown
CVE-2014-6270
Disclosure Date: September 12, 2014 (last updated October 05, 2023)
Off-by-one error in the snmpHandleUdp function in snmp_core.cc in Squid 2.x and 3.x, when an SNMP port is configured, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted UDP SNMP request, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2012-5643
Disclosure Date: December 20, 2012 (last updated October 05, 2023)
Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and 3.x before 3.1.22, 3.2.x before 3.2.4, and 3.3.x before 3.3.0.2 allow remote attackers to cause a denial of service (memory consumption) via (1) invalid Content-Length headers, (2) long POST requests, or (3) crafted authentication credentials.
0
Attacker Value
Unknown
CVE-2010-0639
Disclosure Date: February 15, 2010 (last updated October 04, 2023)
The htcpHandleTstRequest function in htcp.c in Squid 2.x before 2.6.STABLE24 and 2.7 before 2.7.STABLE8, and htcp.cc in 3.0 before 3.0.STABLE24, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via crafted packets to the HTCP port.
0
Attacker Value
Unknown
CVE-2010-0308
Disclosure Date: February 03, 2010 (last updated October 04, 2023)
lib/rfc1035.c in Squid 2.x, 3.0 through 3.0.STABLE22, and 3.1 through 3.1.0.15 allows remote attackers to cause a denial of service (assertion failure) via a crafted DNS packet that only contains a header.
0
Attacker Value
Unknown
CVE-2007-6239
Disclosure Date: December 04, 2007 (last updated October 04, 2023)
The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial of service (crash) via unknown vectors related to HTTP headers and an Array memory leak during requests for cached objects.
0
Attacker Value
Unknown
CVE-2005-3258
Disclosure Date: October 20, 2005 (last updated February 22, 2025)
The rfc1738_do_escape function in ftp.c for Squid 2.5 STABLE11 and earlier allows remote FTP servers to cause a denial of service (segmentation fault) via certain "odd" responses.
0
Attacker Value
Unknown
CVE-2005-2794
Disclosure Date: September 07, 2005 (last updated February 22, 2025)
store.c in Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (crash) via certain aborted requests that trigger an assert error related to STORE_PENDING.
0
Attacker Value
Unknown
CVE-2005-2796
Disclosure Date: September 07, 2005 (last updated February 22, 2025)
The sslConnectTimeout function in ssl.c for Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (segmentation fault) via certain crafted requests.
0
Attacker Value
Unknown
CVE-2005-0173
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a username with a space at the beginning or end, which is ignored by the LDAP server.
0