Записи squid-cache
111 опубликованных записей вендора squid-cache.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 2 · 1,8 %
- Pre-auth RCE
- 9
- С записью об исправлении
- 95,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation22
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer11
- CWE-787 Out-of-bounds Write6
- CWE-125 Out-of-bounds Read5
- CWE-190 Integer Overflow or Wraparound4
- CWE-444 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')4
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
111 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
58В плане | CVE-2016-4553Эксплойта нет | client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which alcanonical · ubuntu linux · CWE-345 | Высокая8,6 | — | 80,0 % | 10 мая 2016 г. |
57В плане | CVE-2023-46847Эксплойта нет | Squid: denial of service in http digest authenticationsquid-cache · squid · CWE-120 | Высокая7,5 | — | 88,4 % | 3 нояб. 2023 г. |
56В плане | CVE-2023-49285Эксплойта нет | Denial of Service in HTTP Message Processing in Squidsquid-cache · squid · CWE-126 | Высокая7,5 | — | 88,1 % | 4 дек. 2023 г. |
56В плане | CVE-2024-25617Эксплойта нет | Denial of Service in HTTP Header parser in squid proxysquid-cache · squid · CWE-182 | Высокая7,5 | — | 88,1 % | 14 февр. 2024 г. |
55В плане | CVE-2021-31806Готовый эксплойт | An issue was discovered in Squid before 4.15 and 5.x before 5.0.6.squid-cache · squid · CWE-116 | Средняя6,5 | — | 95,8 % | 27 мая 2021 г. |
55В плане | CVE-2016-4054Эксплойта нет | Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Inclcanonical · ubuntu linux · CWE-119 | Высокая8,1 | — | 77,6 % | 25 апр. 2016 г. |
51В плане | CVE-2020-8450Эксплойта нет | An issue was discovered in Squid before 4.10.squid-cache · squid · CWE-131 | Высокая7,3 | — | 71,8 % | 4 февр. 2020 г. |
50В плане | CVE-2021-33620Эксплойта нет | Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all clients) via an HTTsquid-cache · squid · CWE-20 | Средняя6,5 | — | 79,6 % | 28 мая 2021 г. |
50В плане | CVE-2024-25111Эксплойта нет | SQUID-2024:1 Denial of Service in HTTP Chunked Decodingsquid-cache · squid · CWE-674 | Высокая7,5 | — | 65,3 % | 6 мар. 2024 г. |
50В плане | CVE-2019-12527Эксплойта нет | An issue was discovered in Squid 4.0.23 through 4.7.squid-cache · squid · CWE-787 | Высокая8,8 | — | 49,0 % | 11 июл. 2019 г. |
49В плане | CVE-2025-62168Proof of concept | Squid vulnerable to information disclosure via authentication credential leakage in error handlingsquid-cache · squid · CWE-209 | Высокая7,5 | — | 63,4 % | 17 окт. 2025 г. |
48В плане | CVE-2014-7141Эксплойта нет | The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds reasquid-cache · squid · CWE-19 | Средняя6,4 | — | 76,1 % | 26 нояб. 2014 г. |
48В плане | CVE-2021-28662Эксплойта нет | An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6.squid-cache · squid · CWE-116 | Средняя6,5 | — | 71,8 % | 27 мая 2021 г. |
47В плане | CVE-2023-50269Эксплойта нет | SQUID-2023:10 Denial of Service in HTTP Request parsingsquid-cache · squid · CWE-674 | Высокая7,5 | — | 57,6 % | 14 дек. 2023 г. |
47В плане | CVE-2020-11945Эксплойта нет | An issue was discovered in Squid before 5.0.2.squid-cache · squid · CWE-190 | Критическая9,8 | — | 27,2 % | 23 апр. 2020 г. |
46В плане | CVE-2019-13345Эксплойта нет | The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.squid-cache · squid · CWE-79 | Средняя6,1 | — | 74,5 % | 5 июл. 2019 г. |
46В плане | CVE-2016-4555Эксплойта нет | client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via craftsquid-cache · squid · CWE-20 | Высокая7,5 | — | 53,9 % | 10 мая 2016 г. |
46В плане | CVE-2016-4554Эксплойта нет | mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisonioracle · linux · CWE-345 | Высокая8,6 | — | 38,9 % | 10 мая 2016 г. |
46В плане | CVE-2019-12525Эксплойта нет | An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7.squid-cache · squid · CWE-787 | Критическая9,8 | — | 24,4 % | 11 июл. 2019 г. |
46В плане | CVE-2025-54574Proof of concept | Squid's URN Handling can lead to Buffer Overflowsquid-cache · squid · CWE-122 | Критическая9,8 | — | 22,7 % | 1 авг. 2025 г. |
45В плане | CVE-2019-12526Эксплойта нет | An issue was discovered in Squid before 4.9.squid-cache · squid · CWE-787 | Критическая9,8 | — | 20,3 % | 26 нояб. 2019 г. |
44В плане | CVE-2013-4123Proof of concept | client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of service via a craftesquid-cache · squid · CWE-20 | Средняя5,0 | — | 80,5 % | 16 сент. 2013 г. |
44В плане | CVE-2024-23638Эксплойта нет | SQUID-2023:11 Denial of Service in Cache Managersquid-cache · squid · CWE-825 | Средняя6,5 | — | 60,1 % | 23 янв. 2024 г. |
44В плане | CVE-2024-45802Эксплойта нет | Squid Denial of Servicesquid-cache · squid · CWE-20 | Высокая7,5 | — | 47,9 % | 28 окт. 2024 г. |
43В плане | CVE-2013-4115Эксплойта нет | Buffer overflow in the idnsALookup function in dns_internal.cc in Squid 3.2 through 3.2.11 and 3.3 through 3.3.6 allows remote attackers to opensuse · opensuse · CWE-119 | Высокая7,5 | — | 43,9 % | 9 авг. 2013 г. |
- CVE-2016-455358В плане
client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which al
ВысокаяCVSS 8,6Эксплойта нетEPSS 80 %canonical · ubuntu linux10 мая 2016 г.
- CVE-2023-4684757В плане
Squid: denial of service in http digest authentication
ВысокаяCVSS 7,5Эксплойта нетEPSS 88 %squid-cache · squid3 нояб. 2023 г.
- CVE-2023-4928556В плане
Denial of Service in HTTP Message Processing in Squid
ВысокаяCVSS 7,5Эксплойта нетEPSS 88 %squid-cache · squid4 дек. 2023 г.
- CVE-2024-2561756В плане
Denial of Service in HTTP Header parser in squid proxy
ВысокаяCVSS 7,5Эксплойта нетEPSS 88 %squid-cache · squid14 февр. 2024 г.
- CVE-2021-3180655В плане
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6.
СредняяCVSS 6,5Готовый эксплойтEPSS 96 %squid-cache · squid27 мая 2021 г.
- CVE-2016-405455В плане
Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Incl
ВысокаяCVSS 8,1Эксплойта нетEPSS 78 %canonical · ubuntu linux25 апр. 2016 г.
- CVE-2020-845051В плане
An issue was discovered in Squid before 4.10.
ВысокаяCVSS 7,3Эксплойта нетEPSS 72 %squid-cache · squid4 февр. 2020 г.
- CVE-2021-3362050В плане
Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all clients) via an HTT
СредняяCVSS 6,5Эксплойта нетEPSS 80 %squid-cache · squid28 мая 2021 г.
- CVE-2024-2511150В плане
SQUID-2024:1 Denial of Service in HTTP Chunked Decoding
ВысокаяCVSS 7,5Эксплойта нетEPSS 65 %squid-cache · squid6 мар. 2024 г.
- CVE-2019-1252750В плане
An issue was discovered in Squid 4.0.23 through 4.7.
ВысокаяCVSS 8,8Эксплойта нетEPSS 49 %squid-cache · squid11 июл. 2019 г.
- CVE-2025-6216849В плане
Squid vulnerable to information disclosure via authentication credential leakage in error handling
ВысокаяCVSS 7,5Proof of conceptEPSS 63 %squid-cache · squid17 окт. 2025 г.
- CVE-2014-714148В плане
The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds rea
СредняяCVSS 6,4Эксплойта нетEPSS 76 %squid-cache · squid26 нояб. 2014 г.
- CVE-2021-2866248В плане
An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6.
СредняяCVSS 6,5Эксплойта нетEPSS 72 %squid-cache · squid27 мая 2021 г.
- CVE-2023-5026947В плане
SQUID-2023:10 Denial of Service in HTTP Request parsing
ВысокаяCVSS 7,5Эксплойта нетEPSS 58 %squid-cache · squid14 дек. 2023 г.
- CVE-2020-1194547В плане
An issue was discovered in Squid before 5.0.2.
КритическаяCVSS 9,8Эксплойта нетEPSS 27 %squid-cache · squid23 апр. 2020 г.
- CVE-2019-1334546В плане
The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.
СредняяCVSS 6,1Эксплойта нетEPSS 74 %squid-cache · squid5 июл. 2019 г.
- CVE-2016-455546В плане
client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via craft
ВысокаяCVSS 7,5Эксплойта нетEPSS 54 %squid-cache · squid10 мая 2016 г.
- CVE-2016-455446В плане
mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoni
ВысокаяCVSS 8,6Эксплойта нетEPSS 39 %oracle · linux10 мая 2016 г.
- CVE-2019-1252546В плане
An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7.
КритическаяCVSS 9,8Эксплойта нетEPSS 24 %squid-cache · squid11 июл. 2019 г.
- CVE-2025-5457446В плане
Squid's URN Handling can lead to Buffer Overflow
КритическаяCVSS 9,8Proof of conceptEPSS 23 %squid-cache · squid1 авг. 2025 г.
- CVE-2019-1252645В плане
An issue was discovered in Squid before 4.9.
КритическаяCVSS 9,8Эксплойта нетEPSS 20 %squid-cache · squid26 нояб. 2019 г.
- CVE-2013-412344В плане
client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of service via a crafte
СредняяCVSS 5,0Proof of conceptEPSS 80 %squid-cache · squid16 сент. 2013 г.
- CVE-2024-2363844В плане
SQUID-2023:11 Denial of Service in Cache Manager
СредняяCVSS 6,5Эксплойта нетEPSS 60 %squid-cache · squid23 янв. 2024 г.
- CVE-2024-4580244В плане
Squid Denial of Service
ВысокаяCVSS 7,5Эксплойта нетEPSS 48 %squid-cache · squid28 окт. 2024 г.
- CVE-2013-411543В плане
Buffer overflow in the idnsALookup function in dns_internal.cc in Squid 3.2 through 3.2.11 and 3.3 through 3.3.6 allows remote attackers to
ВысокаяCVSS 7,5Эксплойта нетEPSS 44 %opensuse · opensuse9 авг. 2013 г.