İçeriğe atla
Noroxi

squid kayıtları

squid üreticisine ait 41 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
3
Düzeltme kaydı olan
%75,6
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Yıllara göre kayıt

    Çubuk: toplam · koyu kısım: CISA KEV.

    Tekrar eden sınıflar

    Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.

    CWE

    Tüm kayıtlar

    41 kayıt
    • CVE-2009-0478
      42Planlayın

      Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request w

      OrtaCVSS 5,0Kavram kanıtıEPSS %72

      squid · squid8 Şub 2009

    • CVE-2005-0194
      42Planlayın

      Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth

      KritikCVSS 10,0İstismar yokEPSS %5

      squid · squid2 May 2005

    • CVE-2005-0241
      41Planlayın

      The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling

      OrtaCVSS 5,0İstismar yokEPSS %70

      squid · squid2 May 2005

    • CVE-2005-0095
      41Planlayın

      The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WC

      OrtaCVSS 5,0İstismar yokEPSS %69

      squid · squid15 Oca 2005

    • CVE-2005-0173
      40Planlayın

      squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a userna

      YüksekCVSS 7,5İstismar yokEPSS %32

      squid · squid2 May 2005

    • CVE-2005-0174
      35İzleyin

      Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP s

      OrtaCVSS 5,0İstismar yokEPSS %50

      squid · squid7 Şub 2005

    • CVE-2002-0163
      35İzleyin

      Heap-based buffer overflow in Squid before 2.4 STABLE4, and Squid 2.5 and 2.6 until March 12, 2002 distributions, allows remote attackers to

      YüksekCVSS 7,5Kavram kanıtıEPSS %15

      squid · squid26 Mar 2002

    • CVE-2004-0189
      34İzleyin

      The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00

      YüksekCVSS 7,5Kavram kanıtıEPSS %14

      squid · squid15 Mar 2004

    • CVE-2002-0068
      33İzleyin

      Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service (core dump) and possibly execute arbitrary code with an f

      YüksekCVSS 7,5Kavram kanıtıEPSS %9

      squid · squid8 Mar 2002

    • CVE-2005-0446
      32İzleyin

      Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Qua

      OrtaCVSS 5,0İstismar yokEPSS %41

      squid · squid2 May 2005

    • CVE-2005-0175
      32İzleyin

      Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.

      OrtaCVSS 5,0İstismar yokEPSS %41

      squid · squid7 Şub 2005

    • CVE-2002-0713
      32İzleyin

      Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code

      YüksekCVSS 7,5İstismar yokEPSS %6

      squid · squid26 Tem 2002

    • CVE-2002-0067
      31İzleyin

      Squid 2.4 STABLE3 and earlier does not properly disable HTCP, even when "htcp_port 0" is specified in squid.conf, which could allow remote a

      YüksekCVSS 7,5İstismar yokEPSS %4

      squid · squid8 Mar 2002

    • CVE-2002-0714
      31İzleyin

      FTP proxy in Squid before 2.4.STABLE6 does not compare the IP addresses of control and data connections with the FTP server, which allows re

      YüksekCVSS 7,5İstismar yokEPSS %3

      squid · squid26 Tem 2002

    • CVE-2001-1030
      31İzleyin

      Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_p

      YüksekCVSS 7,5İstismar yokEPSS %2

      squid · squid web proxy18 Tem 2001

    • CVE-2005-1345
      31İzleyin

      Squid 2.5.STABLE9 and earlier does not trigger a fatal error when it identifies missing or invalid ACLs in the http_access configuration, wh

      YüksekCVSS 7,5İstismar yokEPSS %2

      squid · squid2 May 2005

    • CVE-2005-1711
      30İzleyin

      Gibraltar Firewall 2.2 and earlier, when using the ClamAV update to 0.81 for Squid, uses a defunct ClamAV method to scan memory for viruses,

      YüksekCVSS 7,5İstismar yokEPSS %1

      gibraltar · gibraltar firewall24 May 2005

    • CVE-2007-1560
      28İzleyin

      The clientProcessRequest() function in src/client_side.c in Squid 2.6 before 2.6.STABLE12 allows remote attackers to cause a denial of servi

      OrtaCVSS 5,0İstismar yokEPSS %27

      squid · squid21 Mar 2007

    • CVE-2007-6239
      28İzleyin

      The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial o

      OrtaCVSS 5,0İstismar yokEPSS %27

      squid · squid web proxy cache4 Ara 2007

    • CVE-2007-0247
      26İzleyin

      squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory lis

      OrtaCVSS 5,0Kavram kanıtıEPSS %20

      squid · squid16 Oca 2007

    • CVE-2005-1519
      26İzleyin

      Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attack

      OrtaCVSS 6,4İstismar yokEPSS %2

      squid · squid11 May 2005

    • CVE-2004-0918
      25İzleyin

      The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a de

      OrtaCVSS 5,0İstismar yokEPSS %16

      squid · squid27 Oca 2005

    • CVE-2005-0718
      24İzleyin

      Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (segmentation fault) by aborting the connection during a

      OrtaCVSS 5,0İstismar yokEPSS %13

      squid · squid14 Nis 2005

    • CVE-2005-0097
      23İzleyin

      The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3

      OrtaCVSS 5,0İstismar yokEPSS %11

      squid · squid11 Oca 2005

    • CVE-2004-0832
      23İzleyin

      The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and earlier, with NTLM authentication enabled, allow remote attac

      OrtaCVSS 5,0İstismar yokEPSS %10

      squid · squid3 Kas 2004