Перейти к содержимому
Noroxi

Записи squid

41 опубликованных записей вендора squid.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
3
С записью об исправлении
75,6 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

    Столбик: всего · тёмная часть: CISA KEV.

    Повторяющиеся классы

    Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

    CWE

    Все записи

    41 записей
    • CVE-2009-0478
      42В плане

      Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request w

      СредняяCVSS 5,0Proof of conceptEPSS 72 %

      squid · squid8 февр. 2009 г.

    • CVE-2005-0194
      42В плане

      Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth

      КритическаяCVSS 10,0Эксплойта нетEPSS 5 %

      squid · squid2 мая 2005 г.

    • CVE-2005-0241
      41В плане

      The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling

      СредняяCVSS 5,0Эксплойта нетEPSS 70 %

      squid · squid2 мая 2005 г.

    • CVE-2005-0095
      41В плане

      The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WC

      СредняяCVSS 5,0Эксплойта нетEPSS 69 %

      squid · squid15 янв. 2005 г.

    • CVE-2005-0173
      40В плане

      squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a userna

      ВысокаяCVSS 7,5Эксплойта нетEPSS 32 %

      squid · squid2 мая 2005 г.

    • CVE-2005-0174
      35Наблюдать

      Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP s

      СредняяCVSS 5,0Эксплойта нетEPSS 50 %

      squid · squid7 февр. 2005 г.

    • CVE-2002-0163
      35Наблюдать

      Heap-based buffer overflow in Squid before 2.4 STABLE4, and Squid 2.5 and 2.6 until March 12, 2002 distributions, allows remote attackers to

      ВысокаяCVSS 7,5Proof of conceptEPSS 15 %

      squid · squid26 мар. 2002 г.

    • CVE-2004-0189
      34Наблюдать

      The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00

      ВысокаяCVSS 7,5Proof of conceptEPSS 14 %

      squid · squid15 мар. 2004 г.

    • CVE-2002-0068
      33Наблюдать

      Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service (core dump) and possibly execute arbitrary code with an f

      ВысокаяCVSS 7,5Proof of conceptEPSS 9 %

      squid · squid8 мар. 2002 г.

    • CVE-2005-0446
      32Наблюдать

      Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Qua

      СредняяCVSS 5,0Эксплойта нетEPSS 41 %

      squid · squid2 мая 2005 г.

    • CVE-2005-0175
      32Наблюдать

      Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.

      СредняяCVSS 5,0Эксплойта нетEPSS 41 %

      squid · squid7 февр. 2005 г.

    • CVE-2002-0713
      32Наблюдать

      Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code

      ВысокаяCVSS 7,5Эксплойта нетEPSS 6 %

      squid · squid26 июл. 2002 г.

    • CVE-2002-0067
      31Наблюдать

      Squid 2.4 STABLE3 and earlier does not properly disable HTCP, even when "htcp_port 0" is specified in squid.conf, which could allow remote a

      ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %

      squid · squid8 мар. 2002 г.

    • CVE-2002-0714
      31Наблюдать

      FTP proxy in Squid before 2.4.STABLE6 does not compare the IP addresses of control and data connections with the FTP server, which allows re

      ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

      squid · squid26 июл. 2002 г.

    • CVE-2001-1030
      31Наблюдать

      Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_p

      ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

      squid · squid web proxy18 июл. 2001 г.

    • CVE-2005-1345
      31Наблюдать

      Squid 2.5.STABLE9 and earlier does not trigger a fatal error when it identifies missing or invalid ACLs in the http_access configuration, wh

      ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

      squid · squid2 мая 2005 г.

    • CVE-2005-1711
      30Наблюдать

      Gibraltar Firewall 2.2 and earlier, when using the ClamAV update to 0.81 for Squid, uses a defunct ClamAV method to scan memory for viruses,

      ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

      gibraltar · gibraltar firewall24 мая 2005 г.

    • CVE-2007-1560
      28Наблюдать

      The clientProcessRequest() function in src/client_side.c in Squid 2.6 before 2.6.STABLE12 allows remote attackers to cause a denial of servi

      СредняяCVSS 5,0Эксплойта нетEPSS 27 %

      squid · squid21 мар. 2007 г.

    • CVE-2007-6239
      28Наблюдать

      The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial o

      СредняяCVSS 5,0Эксплойта нетEPSS 27 %

      squid · squid web proxy cache4 дек. 2007 г.

    • CVE-2007-0247
      26Наблюдать

      squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory lis

      СредняяCVSS 5,0Proof of conceptEPSS 20 %

      squid · squid16 янв. 2007 г.

    • CVE-2005-1519
      26Наблюдать

      Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attack

      СредняяCVSS 6,4Эксплойта нетEPSS 2 %

      squid · squid11 мая 2005 г.

    • CVE-2004-0918
      25Наблюдать

      The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a de

      СредняяCVSS 5,0Эксплойта нетEPSS 16 %

      squid · squid27 янв. 2005 г.

    • CVE-2005-0718
      24Наблюдать

      Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (segmentation fault) by aborting the connection during a

      СредняяCVSS 5,0Эксплойта нетEPSS 13 %

      squid · squid14 апр. 2005 г.

    • CVE-2005-0097
      23Наблюдать

      The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3

      СредняяCVSS 5,0Эксплойта нетEPSS 11 %

      squid · squid11 янв. 2005 г.

    • CVE-2004-0832
      23Наблюдать

      The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and earlier, with NTLM authentication enabled, allow remote attac

      СредняяCVSS 5,0Эксплойта нетEPSS 10 %

      squid · squid3 нояб. 2004 г.