Записи squid
41 опубликованных записей вендора squid.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 75,6 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-20 Improper Input Validation3
- CWE-399 Resource Management Errors2
- CWE-264 Permissions, Privileges, and Access Controls1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
41 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2009-0478Proof of concept | Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request wsquid · squid · CWE-20 | Средняя5,0 | — | 72,0 % | 8 февр. 2009 г. |
42В плане | CVE-2005-0194Эксплойта нет | Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth squid · squid | Критическая10,0 | — | 5,1 % | 2 мая 2005 г. |
41В плане | CVE-2005-0241Эксплойта нет | The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling squid · squid | Средняя5,0 | — | 69,7 % | 2 мая 2005 г. |
41В плане | CVE-2005-0095Эксплойта нет | The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WCsquid · squid | Средняя5,0 | — | 68,8 % | 15 янв. 2005 г. |
40В плане | CVE-2005-0173Эксплойта нет | squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a usernasquid · squid | Высокая7,5 | — | 31,9 % | 2 мая 2005 г. |
35Наблюдать | CVE-2005-0174Эксплойта нет | Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP ssquid · squid | Средняя5,0 | — | 50,5 % | 7 февр. 2005 г. |
35Наблюдать | CVE-2002-0163Proof of concept | Heap-based buffer overflow in Squid before 2.4 STABLE4, and Squid 2.5 and 2.6 until March 12, 2002 distributions, allows remote attackers tosquid · squid | Высокая7,5 | — | 15,1 % | 26 мар. 2002 г. |
34Наблюдать | CVE-2004-0189Proof of concept | The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00squid · squid | Высокая7,5 | — | 13,8 % | 15 мар. 2004 г. |
33Наблюдать | CVE-2002-0068Proof of concept | Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service (core dump) and possibly execute arbitrary code with an fsquid · squid | Высокая7,5 | — | 9,4 % | 8 мар. 2002 г. |
32Наблюдать | CVE-2005-0446Эксплойта нет | Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Quasquid · squid | Средняя5,0 | — | 41,1 % | 2 мая 2005 г. |
32Наблюдать | CVE-2005-0175Эксплойта нет | Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.squid · squid | Средняя5,0 | — | 40,7 % | 7 февр. 2005 г. |
32Наблюдать | CVE-2002-0713Эксплойта нет | Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary codesquid · squid | Высокая7,5 | — | 5,5 % | 26 июл. 2002 г. |
31Наблюдать | CVE-2002-0067Эксплойта нет | Squid 2.4 STABLE3 and earlier does not properly disable HTCP, even when "htcp_port 0" is specified in squid.conf, which could allow remote asquid · squid | Высокая7,5 | — | 3,7 % | 8 мар. 2002 г. |
31Наблюдать | CVE-2002-0714Эксплойта нет | FTP proxy in Squid before 2.4.STABLE6 does not compare the IP addresses of control and data connections with the FTP server, which allows resquid · squid | Высокая7,5 | — | 2,7 % | 26 июл. 2002 г. |
31Наблюдать | CVE-2001-1030Эксплойта нет | Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_psquid · squid web proxy | Высокая7,5 | — | 2,0 % | 18 июл. 2001 г. |
31Наблюдать | CVE-2005-1345Эксплойта нет | Squid 2.5.STABLE9 and earlier does not trigger a fatal error when it identifies missing or invalid ACLs in the http_access configuration, whsquid · squid | Высокая7,5 | — | 1,7 % | 2 мая 2005 г. |
30Наблюдать | CVE-2005-1711Эксплойта нет | Gibraltar Firewall 2.2 and earlier, when using the ClamAV update to 0.81 for Squid, uses a defunct ClamAV method to scan memory for viruses,gibraltar · gibraltar firewall | Высокая7,5 | — | 1,0 % | 24 мая 2005 г. |
28Наблюдать | CVE-2007-1560Эксплойта нет | The clientProcessRequest() function in src/client_side.c in Squid 2.6 before 2.6.STABLE12 allows remote attackers to cause a denial of servisquid · squid | Средняя5,0 | — | 27,5 % | 21 мар. 2007 г. |
28Наблюдать | CVE-2007-6239Эксплойта нет | The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial osquid · squid web proxy cache · CWE-20 | Средняя5,0 | — | 26,7 % | 4 дек. 2007 г. |
26Наблюдать | CVE-2007-0247Proof of concept | squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory lissquid · squid · CWE-399 | Средняя5,0 | — | 19,7 % | 16 янв. 2007 г. |
26Наблюдать | CVE-2005-1519Эксплойта нет | Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attacksquid · squid | Средняя6,4 | — | 2,4 % | 11 мая 2005 г. |
25Наблюдать | CVE-2004-0918Эксплойта нет | The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a desquid · squid · CWE-399 | Средняя5,0 | — | 15,8 % | 27 янв. 2005 г. |
24Наблюдать | CVE-2005-0718Эксплойта нет | Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (segmentation fault) by aborting the connection during a squid · squid | Средняя5,0 | — | 12,5 % | 14 апр. 2005 г. |
23Наблюдать | CVE-2005-0097Эксплойта нет | The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3squid · squid | Средняя5,0 | — | 10,6 % | 11 янв. 2005 г. |
23Наблюдать | CVE-2004-0832Эксплойта нет | The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and earlier, with NTLM authentication enabled, allow remote attacsquid · squid | Средняя5,0 | — | 10,4 % | 3 нояб. 2004 г. |
- CVE-2009-047842В плане
Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request w
СредняяCVSS 5,0Proof of conceptEPSS 72 %squid · squid8 февр. 2009 г.
- CVE-2005-019442В плане
Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %squid · squid2 мая 2005 г.
- CVE-2005-024141В плане
The httpProcessReplyHeader function in http.c for Squid 2.5-STABLE7 and earlier does not properly set the debug context when it is handling
СредняяCVSS 5,0Эксплойта нетEPSS 70 %squid · squid2 мая 2005 г.
- CVE-2005-009541В плане
The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WC
СредняяCVSS 5,0Эксплойта нетEPSS 69 %squid · squid15 янв. 2005 г.
- CVE-2005-017340В плане
squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a userna
ВысокаяCVSS 7,5Эксплойта нетEPSS 32 %squid · squid2 мая 2005 г.
- CVE-2005-017435Наблюдать
Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP s
СредняяCVSS 5,0Эксплойта нетEPSS 50 %squid · squid7 февр. 2005 г.
- CVE-2002-016335Наблюдать
Heap-based buffer overflow in Squid before 2.4 STABLE4, and Squid 2.5 and 2.6 until March 12, 2002 distributions, allows remote attackers to
ВысокаяCVSS 7,5Proof of conceptEPSS 15 %squid · squid26 мар. 2002 г.
- CVE-2004-018934Наблюдать
The "%xx" URL decoding function in Squid 2.5STABLE4 and earlier allows remote attackers to bypass url_regex ACLs via a URL with a NULL ("%00
ВысокаяCVSS 7,5Proof of conceptEPSS 14 %squid · squid15 мар. 2004 г.
- CVE-2002-006833Наблюдать
Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service (core dump) and possibly execute arbitrary code with an f
ВысокаяCVSS 7,5Proof of conceptEPSS 9 %squid · squid8 мар. 2002 г.
- CVE-2005-044632Наблюдать
Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Qua
СредняяCVSS 5,0Эксплойта нетEPSS 41 %squid · squid2 мая 2005 г.
- CVE-2005-017532Наблюдать
Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.
СредняяCVSS 5,0Эксплойта нетEPSS 41 %squid · squid7 февр. 2005 г.
- CVE-2002-071332Наблюдать
Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code
ВысокаяCVSS 7,5Эксплойта нетEPSS 6 %squid · squid26 июл. 2002 г.
- CVE-2002-006731Наблюдать
Squid 2.4 STABLE3 and earlier does not properly disable HTCP, even when "htcp_port 0" is specified in squid.conf, which could allow remote a
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %squid · squid8 мар. 2002 г.
- CVE-2002-071431Наблюдать
FTP proxy in Squid before 2.4.STABLE6 does not compare the IP addresses of control and data connections with the FTP server, which allows re
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %squid · squid26 июл. 2002 г.
- CVE-2001-103031Наблюдать
Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_p
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %squid · squid web proxy18 июл. 2001 г.
- CVE-2005-134531Наблюдать
Squid 2.5.STABLE9 and earlier does not trigger a fatal error when it identifies missing or invalid ACLs in the http_access configuration, wh
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %squid · squid2 мая 2005 г.
- CVE-2005-171130Наблюдать
Gibraltar Firewall 2.2 and earlier, when using the ClamAV update to 0.81 for Squid, uses a defunct ClamAV method to scan memory for viruses,
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %gibraltar · gibraltar firewall24 мая 2005 г.
- CVE-2007-156028Наблюдать
The clientProcessRequest() function in src/client_side.c in Squid 2.6 before 2.6.STABLE12 allows remote attackers to cause a denial of servi
СредняяCVSS 5,0Эксплойта нетEPSS 27 %squid · squid21 мар. 2007 г.
- CVE-2007-623928Наблюдать
The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial o
СредняяCVSS 5,0Эксплойта нетEPSS 27 %squid · squid web proxy cache4 дек. 2007 г.
- CVE-2007-024726Наблюдать
squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory lis
СредняяCVSS 5,0Proof of conceptEPSS 20 %squid · squid16 янв. 2007 г.
- CVE-2005-151926Наблюдать
Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attack
СредняяCVSS 6,4Эксплойта нетEPSS 2 %squid · squid11 мая 2005 г.
- CVE-2004-091825Наблюдать
The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a de
СредняяCVSS 5,0Эксплойта нетEPSS 16 %squid · squid27 янв. 2005 г.
- CVE-2005-071824Наблюдать
Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (segmentation fault) by aborting the connection during a
СредняяCVSS 5,0Эксплойта нетEPSS 13 %squid · squid14 апр. 2005 г.
- CVE-2005-009723Наблюдать
The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3
СредняяCVSS 5,0Эксплойта нетEPSS 11 %squid · squid11 янв. 2005 г.
- CVE-2004-083223Наблюдать
The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and earlier, with NTLM authentication enabled, allow remote attac
СредняяCVSS 5,0Эксплойта нетEPSS 10 %squid · squid3 нояб. 2004 г.