squid-cache records
111 published records for vendor squid-cache.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 1.8%
- Pre-auth RCE
- 9
- With a fix record
- 95.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation22
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer11
- CWE-787 Out-of-bounds Write6
- CWE-125 Out-of-bounds Read5
- CWE-190 Integer Overflow or Wraparound4
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')4
The weakness classes this vendor ships most often: where to look.
CWEAll records
111 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
58Plan | CVE-2016-4553No exploit | client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which alcanonical · ubuntu linux · CWE-345 | High8.6 | — | 80.0% | May 10, 2016 |
57Plan | CVE-2023-46847No exploit | Squid: denial of service in http digest authenticationsquid-cache · squid · CWE-120 | High7.5 | — | 88.4% | Nov 3, 2023 |
56Plan | CVE-2023-49285No exploit | Denial of Service in HTTP Message Processing in Squidsquid-cache · squid · CWE-126 | High7.5 | — | 88.1% | Dec 4, 2023 |
56Plan | CVE-2024-25617No exploit | Denial of Service in HTTP Header parser in squid proxysquid-cache · squid · CWE-182 | High7.5 | — | 88.1% | Feb 14, 2024 |
55Plan | CVE-2021-31806Weaponized | An issue was discovered in Squid before 4.15 and 5.x before 5.0.6.squid-cache · squid · CWE-116 | Medium6.5 | — | 95.8% | May 27, 2021 |
55Plan | CVE-2016-4054No exploit | Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Inclcanonical · ubuntu linux · CWE-119 | High8.1 | — | 77.6% | Apr 25, 2016 |
51Plan | CVE-2020-8450No exploit | An issue was discovered in Squid before 4.10.squid-cache · squid · CWE-131 | High7.3 | — | 71.8% | Feb 4, 2020 |
50Plan | CVE-2021-33620No exploit | Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all clients) via an HTTsquid-cache · squid · CWE-20 | Medium6.5 | — | 79.6% | May 28, 2021 |
50Plan | CVE-2024-25111No exploit | SQUID-2024:1 Denial of Service in HTTP Chunked Decodingsquid-cache · squid · CWE-674 | High7.5 | — | 65.3% | Mar 6, 2024 |
50Plan | CVE-2019-12527No exploit | An issue was discovered in Squid 4.0.23 through 4.7.squid-cache · squid · CWE-787 | High8.8 | — | 49.0% | Jul 11, 2019 |
49Plan | CVE-2025-62168Proof of concept | Squid vulnerable to information disclosure via authentication credential leakage in error handlingsquid-cache · squid · CWE-209 | High7.5 | — | 63.4% | Oct 17, 2025 |
48Plan | CVE-2014-7141No exploit | The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds reasquid-cache · squid · CWE-19 | Medium6.4 | — | 76.1% | Nov 26, 2014 |
48Plan | CVE-2021-28662No exploit | An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6.squid-cache · squid · CWE-116 | Medium6.5 | — | 71.8% | May 27, 2021 |
47Plan | CVE-2023-50269No exploit | SQUID-2023:10 Denial of Service in HTTP Request parsingsquid-cache · squid · CWE-674 | High7.5 | — | 57.6% | Dec 14, 2023 |
47Plan | CVE-2020-11945No exploit | An issue was discovered in Squid before 5.0.2.squid-cache · squid · CWE-190 | Critical9.8 | — | 27.2% | Apr 23, 2020 |
46Plan | CVE-2019-13345No exploit | The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.squid-cache · squid · CWE-79 | Medium6.1 | — | 74.5% | Jul 5, 2019 |
46Plan | CVE-2016-4555No exploit | client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via craftsquid-cache · squid · CWE-20 | High7.5 | — | 53.9% | May 10, 2016 |
46Plan | CVE-2016-4554No exploit | mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisonioracle · linux · CWE-345 | High8.6 | — | 38.9% | May 10, 2016 |
46Plan | CVE-2019-12525No exploit | An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7.squid-cache · squid · CWE-787 | Critical9.8 | — | 24.4% | Jul 11, 2019 |
46Plan | CVE-2025-54574Proof of concept | Squid's URN Handling can lead to Buffer Overflowsquid-cache · squid · CWE-122 | Critical9.8 | — | 22.7% | Aug 1, 2025 |
45Plan | CVE-2019-12526No exploit | An issue was discovered in Squid before 4.9.squid-cache · squid · CWE-787 | Critical9.8 | — | 20.3% | Nov 26, 2019 |
44Plan | CVE-2013-4123Proof of concept | client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of service via a craftesquid-cache · squid · CWE-20 | Medium5.0 | — | 80.5% | Sep 16, 2013 |
44Plan | CVE-2024-23638No exploit | SQUID-2023:11 Denial of Service in Cache Managersquid-cache · squid · CWE-825 | Medium6.5 | — | 60.1% | Jan 23, 2024 |
44Plan | CVE-2024-45802No exploit | Squid Denial of Servicesquid-cache · squid · CWE-20 | High7.5 | — | 47.9% | Oct 28, 2024 |
43Plan | CVE-2013-4115No exploit | Buffer overflow in the idnsALookup function in dns_internal.cc in Squid 3.2 through 3.2.11 and 3.3 through 3.3.6 allows remote attackers to opensuse · opensuse · CWE-119 | High7.5 | — | 43.9% | Aug 9, 2013 |
- CVE-2016-455358Plan
client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which al
HighCVSS 8.6No exploitEPSS 80%canonical · ubuntu linuxMay 10, 2016
- CVE-2023-4684757Plan
Squid: denial of service in http digest authentication
HighCVSS 7.5No exploitEPSS 88%squid-cache · squidNov 3, 2023
- CVE-2023-4928556Plan
Denial of Service in HTTP Message Processing in Squid
HighCVSS 7.5No exploitEPSS 88%squid-cache · squidDec 4, 2023
- CVE-2024-2561756Plan
Denial of Service in HTTP Header parser in squid proxy
HighCVSS 7.5No exploitEPSS 88%squid-cache · squidFeb 14, 2024
- CVE-2021-3180655Plan
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6.
MediumCVSS 6.5WeaponizedEPSS 96%squid-cache · squidMay 27, 2021
- CVE-2016-405455Plan
Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Incl
HighCVSS 8.1No exploitEPSS 78%canonical · ubuntu linuxApr 25, 2016
- CVE-2020-845051Plan
An issue was discovered in Squid before 4.10.
HighCVSS 7.3No exploitEPSS 72%squid-cache · squidFeb 4, 2020
- CVE-2021-3362050Plan
Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all clients) via an HTT
MediumCVSS 6.5No exploitEPSS 80%squid-cache · squidMay 28, 2021
- CVE-2024-2511150Plan
SQUID-2024:1 Denial of Service in HTTP Chunked Decoding
HighCVSS 7.5No exploitEPSS 65%squid-cache · squidMar 6, 2024
- CVE-2019-1252750Plan
An issue was discovered in Squid 4.0.23 through 4.7.
HighCVSS 8.8No exploitEPSS 49%squid-cache · squidJul 11, 2019
- CVE-2025-6216849Plan
Squid vulnerable to information disclosure via authentication credential leakage in error handling
HighCVSS 7.5Proof of conceptEPSS 63%squid-cache · squidOct 17, 2025
- CVE-2014-714148Plan
The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds rea
MediumCVSS 6.4No exploitEPSS 76%squid-cache · squidNov 26, 2014
- CVE-2021-2866248Plan
An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6.
MediumCVSS 6.5No exploitEPSS 72%squid-cache · squidMay 27, 2021
- CVE-2023-5026947Plan
SQUID-2023:10 Denial of Service in HTTP Request parsing
HighCVSS 7.5No exploitEPSS 58%squid-cache · squidDec 14, 2023
- CVE-2020-1194547Plan
An issue was discovered in Squid before 5.0.2.
CriticalCVSS 9.8No exploitEPSS 27%squid-cache · squidApr 23, 2020
- CVE-2019-1334546Plan
The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.
MediumCVSS 6.1No exploitEPSS 74%squid-cache · squidJul 5, 2019
- CVE-2016-455546Plan
client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via craft
HighCVSS 7.5No exploitEPSS 54%squid-cache · squidMay 10, 2016
- CVE-2016-455446Plan
mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoni
HighCVSS 8.6No exploitEPSS 39%oracle · linuxMay 10, 2016
- CVE-2019-1252546Plan
An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7.
CriticalCVSS 9.8No exploitEPSS 24%squid-cache · squidJul 11, 2019
- CVE-2025-5457446Plan
Squid's URN Handling can lead to Buffer Overflow
CriticalCVSS 9.8Proof of conceptEPSS 23%squid-cache · squidAug 1, 2025
- CVE-2019-1252645Plan
An issue was discovered in Squid before 4.9.
CriticalCVSS 9.8No exploitEPSS 20%squid-cache · squidNov 26, 2019
- CVE-2013-412344Plan
client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of service via a crafte
MediumCVSS 5.0Proof of conceptEPSS 80%squid-cache · squidSep 16, 2013
- CVE-2024-2363844Plan
SQUID-2023:11 Denial of Service in Cache Manager
MediumCVSS 6.5No exploitEPSS 60%squid-cache · squidJan 23, 2024
- CVE-2024-4580244Plan
Squid Denial of Service
HighCVSS 7.5No exploitEPSS 48%squid-cache · squidOct 28, 2024
- CVE-2013-411543Plan
Buffer overflow in the idnsALookup function in dns_internal.cc in Squid 3.2 through 3.2.11 and 3.3 through 3.3.6 allows remote attackers to
HighCVSS 7.5No exploitEPSS 44%opensuse · opensuseAug 9, 2013