Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown
CVE-2016-10002
Disclosure Date: January 27, 2017 (last updated November 25, 2024)
Incorrect processing of responses to If-None-Modified HTTP conditional requests in Squid HTTP Proxy 3.1.10 through 3.1.23, 3.2.0.3 through 3.5.22, and 4.0.1 through 4.0.16 leads to client-specific Cookie data being leaked to other clients. Attack requests can easily be crafted by a client to probe a cache for this information.
0
Attacker Value
Unknown
CVE-2016-4555
Disclosure Date: May 10, 2016 (last updated November 25, 2024)
client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via crafted Edge Side Includes (ESI) responses.
0
Attacker Value
Unknown
CVE-2016-4556
Disclosure Date: May 10, 2016 (last updated November 25, 2024)
Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via a crafted Edge Side Includes (ESI) response.
0
Attacker Value
Unknown
CVE-2016-4053
Disclosure Date: April 25, 2016 (last updated November 25, 2024)
Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers to obtain sensitive stack layout information via crafted Edge Side Includes (ESI) responses, related to incorrect use of assert and compiler optimization.
0
Attacker Value
Unknown
CVE-2016-4051
Disclosure Date: April 25, 2016 (last updated November 25, 2024)
Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data.
0
Attacker Value
Unknown
CVE-2016-4052
Disclosure Date: April 25, 2016 (last updated November 25, 2024)
Multiple stack-based buffer overflows in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote HTTP servers to cause a denial of service or execute arbitrary code via crafted Edge Side Includes (ESI) responses.
0
Attacker Value
Unknown
CVE-2016-4054
Disclosure Date: April 25, 2016 (last updated November 25, 2024)
Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Includes (ESI) responses.
0
Attacker Value
Unknown
CVE-2015-3455
Disclosure Date: May 18, 2015 (last updated October 05, 2023)
Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate.
0
Attacker Value
Unknown
CVE-2014-7142
Disclosure Date: November 26, 2014 (last updated October 05, 2023)
The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (crash) via a crafted (1) ICMP or (2) ICMP6 packet size.
0
Attacker Value
Unknown
CVE-2014-7141
Disclosure Date: November 26, 2014 (last updated October 05, 2023)
The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and crash) via a crafted type in an (1) ICMP or (2) ICMP6 packet.
0