Squid

Squid

37 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 77.41%
  • Published 08.02.2009 22:30:00
  • Last modified 09.04.2025 00:30:58

Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request with an invalid version number, which triggers a reachable assertion in (1) HttpMsg.c and (2) HttpStatusLine.c.

Exploit
  • EPSS 19.35%
  • Published 01.04.2008 17:44:00
  • Last modified 09.04.2025 00:30:58

The arrayShrink function (lib/Array.c) in Squid 2.6.STABLE17 allows attackers to cause a denial of service (process exit) via unknown vectors that cause an array to shrink to 0 entries, which triggers an assert error. NOTE: this issue is due to an i...

  • EPSS 63.98%
  • Published 21.03.2007 18:19:00
  • Last modified 09.04.2025 00:30:58

The clientProcessRequest() function in src/client_side.c in Squid 2.6 before 2.6.STABLE12 allows remote attackers to cause a denial of service (daemon crash) via crafted TRACE requests that trigger an assertion error.

  • EPSS 46.99%
  • Published 16.01.2007 18:28:00
  • Last modified 09.04.2025 00:30:58

The aclMatchExternal function in Squid before 2.6.STABLE7 allows remote attackers to cause a denial of service (crash) by causing an external_acl queue overload, which triggers an infinite loop.

  • EPSS 39.5%
  • Published 16.01.2007 18:28:00
  • Last modified 09.04.2025 00:30:58

squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory listing responses, possibly related to the (1) ftpListingFinish and (2) ftpHtmlifyListEntry functions.

  • EPSS 0.71%
  • Published 27.10.2005 10:02:00
  • Last modified 03.04.2025 01:03:51

Unspecified vulnerability in Squid on SUSE Linux 9.0 allows remote attackers to cause a denial of service (crash) via HTTPs (SSL).

  • EPSS 24.1%
  • Published 20.10.2005 10:02:00
  • Last modified 03.04.2025 01:03:51

The rfc1738_do_escape function in ftp.c for Squid 2.5 STABLE11 and earlier allows remote FTP servers to cause a denial of service (segmentation fault) via certain "odd" responses.

  • EPSS 51.92%
  • Published 30.09.2005 18:05:00
  • Last modified 03.04.2025 01:03:51

Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart).

  • EPSS 15.1%
  • Published 07.09.2005 18:03:00
  • Last modified 03.04.2025 01:03:51

The sslConnectTimeout function in ssl.c for Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (segmentation fault) via certain crafted requests.

  • EPSS 12.52%
  • Published 07.09.2005 18:03:00
  • Last modified 03.04.2025 01:03:51

store.c in Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (crash) via certain aborted requests that trigger an assert error related to STORE_PENDING.