Skip to content
Noroxi

squid records

41 published records for vendor squid.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
3
With a fix record
75.6%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    All records

    41 records
    • Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request w

      MediumCVSS 5.0Proof of conceptEPSS 72%

      squid · squidFeb 8, 2009

    • Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth

      CriticalCVSS 10.0No exploitEPSS 5%

      squid · squidMay 2, 2005

    • The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling

      MediumCVSS 5.0No exploitEPSS 70%

      squid · squidMay 2, 2005

    • The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WC

      MediumCVSS 5.0No exploitEPSS 69%

      squid · squidJan 15, 2005

    • squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a userna

      HighCVSS 7.5No exploitEPSS 32%

      squid · squidMay 2, 2005

    • CVE-2005-0174
      35Monitor

      Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP s

      MediumCVSS 5.0No exploitEPSS 50%

      squid · squidFeb 7, 2005

    • CVE-2002-0163
      35Monitor

      Heap-based buffer overflow in Squid before 2.4 STABLE4, and Squid 2.5 and 2.6 until March 12, 2002 distributions, allows remote attackers to

      HighCVSS 7.5Proof of conceptEPSS 15%

      squid · squidMar 26, 2002

    • CVE-2004-0189
      34Monitor

      The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00

      HighCVSS 7.5Proof of conceptEPSS 14%

      squid · squidMar 15, 2004

    • CVE-2002-0068
      33Monitor

      Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service (core dump) and possibly execute arbitrary code with an f

      HighCVSS 7.5Proof of conceptEPSS 9%

      squid · squidMar 8, 2002

    • CVE-2005-0446
      32Monitor

      Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Qua

      MediumCVSS 5.0No exploitEPSS 41%

      squid · squidMay 2, 2005

    • CVE-2005-0175
      32Monitor

      Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.

      MediumCVSS 5.0No exploitEPSS 41%

      squid · squidFeb 7, 2005

    • CVE-2002-0713
      32Monitor

      Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code

      HighCVSS 7.5No exploitEPSS 6%

      squid · squidJul 26, 2002

    • CVE-2002-0067
      31Monitor

      Squid 2.4 STABLE3 and earlier does not properly disable HTCP, even when "htcp_port 0" is specified in squid.conf, which could allow remote a

      HighCVSS 7.5No exploitEPSS 4%

      squid · squidMar 8, 2002

    • CVE-2002-0714
      31Monitor

      FTP proxy in Squid before 2.4.STABLE6 does not compare the IP addresses of control and data connections with the FTP server, which allows re

      HighCVSS 7.5No exploitEPSS 3%

      squid · squidJul 26, 2002

    • CVE-2001-1030
      31Monitor

      Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_p

      HighCVSS 7.5No exploitEPSS 2%

      squid · squid web proxyJul 18, 2001

    • CVE-2005-1345
      31Monitor

      Squid 2.5.STABLE9 and earlier does not trigger a fatal error when it identifies missing or invalid ACLs in the http_access configuration, wh

      HighCVSS 7.5No exploitEPSS 2%

      squid · squidMay 2, 2005

    • CVE-2005-1711
      30Monitor

      Gibraltar Firewall 2.2 and earlier, when using the ClamAV update to 0.81 for Squid, uses a defunct ClamAV method to scan memory for viruses,

      HighCVSS 7.5No exploitEPSS 1%

      gibraltar · gibraltar firewallMay 24, 2005

    • CVE-2007-1560
      28Monitor

      The clientProcessRequest() function in src/client_side.c in Squid 2.6 before 2.6.STABLE12 allows remote attackers to cause a denial of servi

      MediumCVSS 5.0No exploitEPSS 27%

      squid · squidMar 21, 2007

    • CVE-2007-6239
      28Monitor

      The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial o

      MediumCVSS 5.0No exploitEPSS 27%

      squid · squid web proxy cacheDec 4, 2007

    • CVE-2007-0247
      26Monitor

      squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory lis

      MediumCVSS 5.0Proof of conceptEPSS 20%

      squid · squidJan 16, 2007

    • CVE-2005-1519
      26Monitor

      Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attack

      MediumCVSS 6.4No exploitEPSS 2%

      squid · squidMay 11, 2005

    • CVE-2004-0918
      25Monitor

      The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a de

      MediumCVSS 5.0No exploitEPSS 16%

      squid · squidJan 27, 2005

    • CVE-2005-0718
      24Monitor

      Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (segmentation fault) by aborting the connection during a

      MediumCVSS 5.0No exploitEPSS 13%

      squid · squidApr 14, 2005

    • CVE-2005-0097
      23Monitor

      The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3

      MediumCVSS 5.0No exploitEPSS 11%

      squid · squidJan 11, 2005

    • CVE-2004-0832
      23Monitor

      The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and earlier, with NTLM authentication enabled, allow remote attac

      MediumCVSS 5.0No exploitEPSS 10%

      squid · squidNov 3, 2004