squid records
41 published records for vendor squid.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 75.6%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-20 Improper Input Validation3
- CWE-399 Resource Management Errors2
- CWE-264 Permissions, Privileges, and Access Controls1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
41 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2009-0478Proof of concept | Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request wsquid · squid · CWE-20 | Medium5.0 | — | 72.0% | Feb 8, 2009 |
42Plan | CVE-2005-0194No exploit | Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth squid · squid | Critical10.0 | — | 5.1% | May 2, 2005 |
41Plan | CVE-2005-0241No exploit | The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling squid · squid | Medium5.0 | — | 69.7% | May 2, 2005 |
41Plan | CVE-2005-0095No exploit | The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WCsquid · squid | Medium5.0 | — | 68.8% | Jan 15, 2005 |
40Plan | CVE-2005-0173No exploit | squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a usernasquid · squid | High7.5 | — | 31.9% | May 2, 2005 |
35Monitor | CVE-2005-0174No exploit | Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP ssquid · squid | Medium5.0 | — | 50.5% | Feb 7, 2005 |
35Monitor | CVE-2002-0163Proof of concept | Heap-based buffer overflow in Squid before 2.4 STABLE4, and Squid 2.5 and 2.6 until March 12, 2002 distributions, allows remote attackers tosquid · squid | High7.5 | — | 15.1% | Mar 26, 2002 |
34Monitor | CVE-2004-0189Proof of concept | The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00squid · squid | High7.5 | — | 13.8% | Mar 15, 2004 |
33Monitor | CVE-2002-0068Proof of concept | Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service (core dump) and possibly execute arbitrary code with an fsquid · squid | High7.5 | — | 9.4% | Mar 8, 2002 |
32Monitor | CVE-2005-0446No exploit | Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Quasquid · squid | Medium5.0 | — | 41.1% | May 2, 2005 |
32Monitor | CVE-2005-0175No exploit | Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.squid · squid | Medium5.0 | — | 40.7% | Feb 7, 2005 |
32Monitor | CVE-2002-0713No exploit | Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary codesquid · squid | High7.5 | — | 5.5% | Jul 26, 2002 |
31Monitor | CVE-2002-0067No exploit | Squid 2.4 STABLE3 and earlier does not properly disable HTCP, even when "htcp_port 0" is specified in squid.conf, which could allow remote asquid · squid | High7.5 | — | 3.7% | Mar 8, 2002 |
31Monitor | CVE-2002-0714No exploit | FTP proxy in Squid before 2.4.STABLE6 does not compare the IP addresses of control and data connections with the FTP server, which allows resquid · squid | High7.5 | — | 2.7% | Jul 26, 2002 |
31Monitor | CVE-2001-1030No exploit | Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_psquid · squid web proxy | High7.5 | — | 2.0% | Jul 18, 2001 |
31Monitor | CVE-2005-1345No exploit | Squid 2.5.STABLE9 and earlier does not trigger a fatal error when it identifies missing or invalid ACLs in the http_access configuration, whsquid · squid | High7.5 | — | 1.7% | May 2, 2005 |
30Monitor | CVE-2005-1711No exploit | Gibraltar Firewall 2.2 and earlier, when using the ClamAV update to 0.81 for Squid, uses a defunct ClamAV method to scan memory for viruses,gibraltar · gibraltar firewall | High7.5 | — | 1.0% | May 24, 2005 |
28Monitor | CVE-2007-1560No exploit | The clientProcessRequest() function in src/client_side.c in Squid 2.6 before 2.6.STABLE12 allows remote attackers to cause a denial of servisquid · squid | Medium5.0 | — | 27.5% | Mar 21, 2007 |
28Monitor | CVE-2007-6239No exploit | The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial osquid · squid web proxy cache · CWE-20 | Medium5.0 | — | 26.7% | Dec 4, 2007 |
26Monitor | CVE-2007-0247Proof of concept | squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory lissquid · squid · CWE-399 | Medium5.0 | — | 19.7% | Jan 16, 2007 |
26Monitor | CVE-2005-1519No exploit | Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attacksquid · squid | Medium6.4 | — | 2.4% | May 11, 2005 |
25Monitor | CVE-2004-0918No exploit | The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a desquid · squid · CWE-399 | Medium5.0 | — | 15.8% | Jan 27, 2005 |
24Monitor | CVE-2005-0718No exploit | Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (segmentation fault) by aborting the connection during a squid · squid | Medium5.0 | — | 12.5% | Apr 14, 2005 |
23Monitor | CVE-2005-0097No exploit | The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3squid · squid | Medium5.0 | — | 10.6% | Jan 11, 2005 |
23Monitor | CVE-2004-0832No exploit | The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and earlier, with NTLM authentication enabled, allow remote attacsquid · squid | Medium5.0 | — | 10.4% | Nov 3, 2004 |
- CVE-2009-047842Plan
Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request w
MediumCVSS 5.0Proof of conceptEPSS 72%squid · squidFeb 8, 2009
- CVE-2005-019442Plan
Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth
CriticalCVSS 10.0No exploitEPSS 5%squid · squidMay 2, 2005
- CVE-2005-024141Plan
The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling
MediumCVSS 5.0No exploitEPSS 70%squid · squidMay 2, 2005
- CVE-2005-009541Plan
The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WC
MediumCVSS 5.0No exploitEPSS 69%squid · squidJan 15, 2005
- CVE-2005-017340Plan
squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a userna
HighCVSS 7.5No exploitEPSS 32%squid · squidMay 2, 2005
- CVE-2005-017435Monitor
Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP s
MediumCVSS 5.0No exploitEPSS 50%squid · squidFeb 7, 2005
- CVE-2002-016335Monitor
Heap-based buffer overflow in Squid before 2.4 STABLE4, and Squid 2.5 and 2.6 until March 12, 2002 distributions, allows remote attackers to
HighCVSS 7.5Proof of conceptEPSS 15%squid · squidMar 26, 2002
- CVE-2004-018934Monitor
The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00
HighCVSS 7.5Proof of conceptEPSS 14%squid · squidMar 15, 2004
- CVE-2002-006833Monitor
Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service (core dump) and possibly execute arbitrary code with an f
HighCVSS 7.5Proof of conceptEPSS 9%squid · squidMar 8, 2002
- CVE-2005-044632Monitor
Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Qua
MediumCVSS 5.0No exploitEPSS 41%squid · squidMay 2, 2005
- CVE-2005-017532Monitor
Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.
MediumCVSS 5.0No exploitEPSS 41%squid · squidFeb 7, 2005
- CVE-2002-071332Monitor
Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code
HighCVSS 7.5No exploitEPSS 6%squid · squidJul 26, 2002
- CVE-2002-006731Monitor
Squid 2.4 STABLE3 and earlier does not properly disable HTCP, even when "htcp_port 0" is specified in squid.conf, which could allow remote a
HighCVSS 7.5No exploitEPSS 4%squid · squidMar 8, 2002
- CVE-2002-071431Monitor
FTP proxy in Squid before 2.4.STABLE6 does not compare the IP addresses of control and data connections with the FTP server, which allows re
HighCVSS 7.5No exploitEPSS 3%squid · squidJul 26, 2002
- CVE-2001-103031Monitor
Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_p
HighCVSS 7.5No exploitEPSS 2%squid · squid web proxyJul 18, 2001
- CVE-2005-134531Monitor
Squid 2.5.STABLE9 and earlier does not trigger a fatal error when it identifies missing or invalid ACLs in the http_access configuration, wh
HighCVSS 7.5No exploitEPSS 2%squid · squidMay 2, 2005
- CVE-2005-171130Monitor
Gibraltar Firewall 2.2 and earlier, when using the ClamAV update to 0.81 for Squid, uses a defunct ClamAV method to scan memory for viruses,
HighCVSS 7.5No exploitEPSS 1%gibraltar · gibraltar firewallMay 24, 2005
- CVE-2007-156028Monitor
The clientProcessRequest() function in src/client_side.c in Squid 2.6 before 2.6.STABLE12 allows remote attackers to cause a denial of servi
MediumCVSS 5.0No exploitEPSS 27%squid · squidMar 21, 2007
- CVE-2007-623928Monitor
The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial o
MediumCVSS 5.0No exploitEPSS 27%squid · squid web proxy cacheDec 4, 2007
- CVE-2007-024726Monitor
squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory lis
MediumCVSS 5.0Proof of conceptEPSS 20%squid · squidJan 16, 2007
- CVE-2005-151926Monitor
Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attack
MediumCVSS 6.4No exploitEPSS 2%squid · squidMay 11, 2005
- CVE-2004-091825Monitor
The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a de
MediumCVSS 5.0No exploitEPSS 16%squid · squidJan 27, 2005
- CVE-2005-071824Monitor
Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (segmentation fault) by aborting the connection during a
MediumCVSS 5.0No exploitEPSS 13%squid · squidApr 14, 2005
- CVE-2005-009723Monitor
The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3
MediumCVSS 5.0No exploitEPSS 11%squid · squidJan 11, 2005
- CVE-2004-083223Monitor
The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and earlier, with NTLM authentication enabled, allow remote attac
MediumCVSS 5.0No exploitEPSS 10%squid · squidNov 3, 2004