squid kayıtları
squid üreticisine ait 41 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %75,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-20 Improper Input Validation3
- CWE-399 Resource Management Errors2
- CWE-264 Permissions, Privileges, and Access Controls1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
41 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2009-0478Kavram kanıtı | Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request wsquid · squid · CWE-20 | Orta5,0 | — | %72,0 | 8 Şub 2009 |
42Planlayın | CVE-2005-0194İstismar yok | Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth squid · squid | Kritik10,0 | — | %5,1 | 2 May 2005 |
41Planlayın | CVE-2005-0241İstismar yok | The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling squid · squid | Orta5,0 | — | %69,7 | 2 May 2005 |
41Planlayın | CVE-2005-0095İstismar yok | The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WCsquid · squid | Orta5,0 | — | %68,8 | 15 Oca 2005 |
40Planlayın | CVE-2005-0173İstismar yok | squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a usernasquid · squid | Yüksek7,5 | — | %31,9 | 2 May 2005 |
35İzleyin | CVE-2005-0174İstismar yok | Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP ssquid · squid | Orta5,0 | — | %50,5 | 7 Şub 2005 |
35İzleyin | CVE-2002-0163Kavram kanıtı | Heap-based buffer overflow in Squid before 2.4 STABLE4, and Squid 2.5 and 2.6 until March 12, 2002 distributions, allows remote attackers tosquid · squid | Yüksek7,5 | — | %15,1 | 26 Mar 2002 |
34İzleyin | CVE-2004-0189Kavram kanıtı | The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00squid · squid | Yüksek7,5 | — | %13,8 | 15 Mar 2004 |
33İzleyin | CVE-2002-0068Kavram kanıtı | Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service (core dump) and possibly execute arbitrary code with an fsquid · squid | Yüksek7,5 | — | %9,4 | 8 Mar 2002 |
32İzleyin | CVE-2005-0446İstismar yok | Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Quasquid · squid | Orta5,0 | — | %41,1 | 2 May 2005 |
32İzleyin | CVE-2005-0175İstismar yok | Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.squid · squid | Orta5,0 | — | %40,7 | 7 Şub 2005 |
32İzleyin | CVE-2002-0713İstismar yok | Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary codesquid · squid | Yüksek7,5 | — | %5,5 | 26 Tem 2002 |
31İzleyin | CVE-2002-0067İstismar yok | Squid 2.4 STABLE3 and earlier does not properly disable HTCP, even when "htcp_port 0" is specified in squid.conf, which could allow remote asquid · squid | Yüksek7,5 | — | %3,7 | 8 Mar 2002 |
31İzleyin | CVE-2002-0714İstismar yok | FTP proxy in Squid before 2.4.STABLE6 does not compare the IP addresses of control and data connections with the FTP server, which allows resquid · squid | Yüksek7,5 | — | %2,7 | 26 Tem 2002 |
31İzleyin | CVE-2001-1030İstismar yok | Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_psquid · squid web proxy | Yüksek7,5 | — | %2,0 | 18 Tem 2001 |
31İzleyin | CVE-2005-1345İstismar yok | Squid 2.5.STABLE9 and earlier does not trigger a fatal error when it identifies missing or invalid ACLs in the http_access configuration, whsquid · squid | Yüksek7,5 | — | %1,7 | 2 May 2005 |
30İzleyin | CVE-2005-1711İstismar yok | Gibraltar Firewall 2.2 and earlier, when using the ClamAV update to 0.81 for Squid, uses a defunct ClamAV method to scan memory for viruses,gibraltar · gibraltar firewall | Yüksek7,5 | — | %1,0 | 24 May 2005 |
28İzleyin | CVE-2007-1560İstismar yok | The clientProcessRequest() function in src/client_side.c in Squid 2.6 before 2.6.STABLE12 allows remote attackers to cause a denial of servisquid · squid | Orta5,0 | — | %27,5 | 21 Mar 2007 |
28İzleyin | CVE-2007-6239İstismar yok | The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial osquid · squid web proxy cache · CWE-20 | Orta5,0 | — | %26,7 | 4 Ara 2007 |
26İzleyin | CVE-2007-0247Kavram kanıtı | squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory lissquid · squid · CWE-399 | Orta5,0 | — | %19,7 | 16 Oca 2007 |
26İzleyin | CVE-2005-1519İstismar yok | Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attacksquid · squid | Orta6,4 | — | %2,4 | 11 May 2005 |
25İzleyin | CVE-2004-0918İstismar yok | The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a desquid · squid · CWE-399 | Orta5,0 | — | %15,8 | 27 Oca 2005 |
24İzleyin | CVE-2005-0718İstismar yok | Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (segmentation fault) by aborting the connection during a squid · squid | Orta5,0 | — | %12,5 | 14 Nis 2005 |
23İzleyin | CVE-2005-0097İstismar yok | The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3squid · squid | Orta5,0 | — | %10,6 | 11 Oca 2005 |
23İzleyin | CVE-2004-0832İstismar yok | The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and earlier, with NTLM authentication enabled, allow remote attacsquid · squid | Orta5,0 | — | %10,4 | 3 Kas 2004 |
- CVE-2009-047842Planlayın
Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request w
OrtaCVSS 5,0Kavram kanıtıEPSS %72squid · squid8 Şub 2009
- CVE-2005-019442Planlayın
Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth
KritikCVSS 10,0İstismar yokEPSS %5squid · squid2 May 2005
- CVE-2005-024141Planlayın
The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling
OrtaCVSS 5,0İstismar yokEPSS %70squid · squid2 May 2005
- CVE-2005-009541Planlayın
The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WC
OrtaCVSS 5,0İstismar yokEPSS %69squid · squid15 Oca 2005
- CVE-2005-017340Planlayın
squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a userna
YüksekCVSS 7,5İstismar yokEPSS %32squid · squid2 May 2005
- CVE-2005-017435İzleyin
Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP s
OrtaCVSS 5,0İstismar yokEPSS %50squid · squid7 Şub 2005
- CVE-2002-016335İzleyin
Heap-based buffer overflow in Squid before 2.4 STABLE4, and Squid 2.5 and 2.6 until March 12, 2002 distributions, allows remote attackers to
YüksekCVSS 7,5Kavram kanıtıEPSS %15squid · squid26 Mar 2002
- CVE-2004-018934İzleyin
The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00
YüksekCVSS 7,5Kavram kanıtıEPSS %14squid · squid15 Mar 2004
- CVE-2002-006833İzleyin
Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service (core dump) and possibly execute arbitrary code with an f
YüksekCVSS 7,5Kavram kanıtıEPSS %9squid · squid8 Mar 2002
- CVE-2005-044632İzleyin
Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Qua
OrtaCVSS 5,0İstismar yokEPSS %41squid · squid2 May 2005
- CVE-2005-017532İzleyin
Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.
OrtaCVSS 5,0İstismar yokEPSS %41squid · squid7 Şub 2005
- CVE-2002-071332İzleyin
Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code
YüksekCVSS 7,5İstismar yokEPSS %6squid · squid26 Tem 2002
- CVE-2002-006731İzleyin
Squid 2.4 STABLE3 and earlier does not properly disable HTCP, even when "htcp_port 0" is specified in squid.conf, which could allow remote a
YüksekCVSS 7,5İstismar yokEPSS %4squid · squid8 Mar 2002
- CVE-2002-071431İzleyin
FTP proxy in Squid before 2.4.STABLE6 does not compare the IP addresses of control and data connections with the FTP server, which allows re
YüksekCVSS 7,5İstismar yokEPSS %3squid · squid26 Tem 2002
- CVE-2001-103031İzleyin
Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_p
YüksekCVSS 7,5İstismar yokEPSS %2squid · squid web proxy18 Tem 2001
- CVE-2005-134531İzleyin
Squid 2.5.STABLE9 and earlier does not trigger a fatal error when it identifies missing or invalid ACLs in the http_access configuration, wh
YüksekCVSS 7,5İstismar yokEPSS %2squid · squid2 May 2005
- CVE-2005-171130İzleyin
Gibraltar Firewall 2.2 and earlier, when using the ClamAV update to 0.81 for Squid, uses a defunct ClamAV method to scan memory for viruses,
YüksekCVSS 7,5İstismar yokEPSS %1gibraltar · gibraltar firewall24 May 2005
- CVE-2007-156028İzleyin
The clientProcessRequest() function in src/client_side.c in Squid 2.6 before 2.6.STABLE12 allows remote attackers to cause a denial of servi
OrtaCVSS 5,0İstismar yokEPSS %27squid · squid21 Mar 2007
- CVE-2007-623928İzleyin
The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial o
OrtaCVSS 5,0İstismar yokEPSS %27squid · squid web proxy cache4 Ara 2007
- CVE-2007-024726İzleyin
squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory lis
OrtaCVSS 5,0Kavram kanıtıEPSS %20squid · squid16 Oca 2007
- CVE-2005-151926İzleyin
Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attack
OrtaCVSS 6,4İstismar yokEPSS %2squid · squid11 May 2005
- CVE-2004-091825İzleyin
The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a de
OrtaCVSS 5,0İstismar yokEPSS %16squid · squid27 Oca 2005
- CVE-2005-071824İzleyin
Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (segmentation fault) by aborting the connection during a
OrtaCVSS 5,0İstismar yokEPSS %13squid · squid14 Nis 2005
- CVE-2005-009723İzleyin
The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3
OrtaCVSS 5,0İstismar yokEPSS %11squid · squid11 Oca 2005
- CVE-2004-083223İzleyin
The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and earlier, with NTLM authentication enabled, allow remote attac
OrtaCVSS 5,0İstismar yokEPSS %10squid · squid3 Kas 2004