Squid-cache

Squid

104 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 75.06%
  • Veröffentlicht 09.08.2013 22:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Buffer overflow in the idnsALookup function in dns_internal.cc in Squid 3.2 through 3.2.11 and 3.3 through 3.3.6 allows remote attackers to cause a denial of service (memory corruption and server termination) via a long name in a DNS lookup request.

  • EPSS 72.19%
  • Veröffentlicht 08.02.2013 20:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

cachemgr.cgi in Squid 3.1.x and 3.2.x, possibly 3.1.22, 3.2.4, and other versions, allows remote attackers to cause a denial of service (resource consumption) via a crafted request. NOTE: this issue is due to an incorrect fix for CVE-2012-5643, poss...

  • EPSS 35.41%
  • Veröffentlicht 20.12.2012 12:02:19
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and 3.x before 3.1.22, 3.2.x before 3.2.4, and 3.3.x before 3.3.0.2 allow remote attackers to cause a denial of service (memory consumption) via (1) invalid Content-Length header...

  • EPSS 2.12%
  • Veröffentlicht 28.04.2012 10:06:13
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Squid 3.1.9 allows remote attackers to bypass the access configuration for the CONNECT method by providing an arbitrary allowed hostname in the Host HTTP header. NOTE: this issue might not be reproducible, because the researcher is unable to provide...

  • EPSS 62.49%
  • Veröffentlicht 17.11.2011 19:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The idnsGrokReply function in Squid before 3.1.16 does not properly free memory, which allows remote attackers to cause a denial of service (daemon abort) via a DNS reply containing a CNAME record that references another CNAME record that contains an...

  • EPSS 76.04%
  • Veröffentlicht 06.09.2011 15:55:08
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Buffer overflow in the gopherToHTML function in gopher.cc in the Gopher reply parser in Squid 3.0 before 3.0.STABLE26, 3.1 before 3.1.15, and 3.2 before 3.2.0.11 allows remote Gopher servers to cause a denial of service (memory corruption and daemon ...

  • EPSS 55.18%
  • Veröffentlicht 12.10.2010 21:00:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

dns_internal.cc in Squid 3.1.6, when IPv6 DNS resolution is not enabled, accesses an invalid socket during an IPv4 TCP DNS query, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via vectors that trigger ...

  • EPSS 74.7%
  • Veröffentlicht 20.09.2010 21:00:02
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The string-comparison functions in String.cci in Squid 3.x before 3.1.8 and 3.2.x before 3.2.0.2 allow remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request.

  • EPSS 49.37%
  • Veröffentlicht 15.02.2010 18:30:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The htcpHandleTstRequest function in htcp.c in Squid 2.x before 2.6.STABLE24 and 2.7 before 2.7.STABLE8, and htcp.cc in 3.0 before 3.0.STABLE24, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via craf...

  • EPSS 16.82%
  • Veröffentlicht 03.02.2010 18:30:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

lib/rfc1035.c in Squid 2.x, 3.0 through 3.0.STABLE22, and 3.1 through 3.1.0.15 allows remote attackers to cause a denial of service (assertion failure) via a crafted DNS packet that only contains a header.