7.5

CVE-2002-0067

Squid 2.4 STABLE3 and earlier does not properly disable HTCP, even when "htcp_port 0" is specified in squid.conf, which could allow remote attackers to bypass intended access restrictions.

Data is provided by the National Vulnerability Database (NVD)
SquidSquid Version <= 2.4_stable_2
RedhatLinux Version6.2 Editionalpha
RedhatLinux Version6.2 Editioni386
RedhatLinux Version6.2 Editionsparc
RedhatLinux Version7.0 Editionalpha
RedhatLinux Version7.0 Editioni386
RedhatLinux Version7.1 Editionalpha
RedhatLinux Version7.1 Editioni386
RedhatLinux Version7.1 Editionia64
RedhatLinux Version7.2 Editioni386
RedhatLinux Version7.2 Editionia64
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.22% 0.419
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P