CVE-2019-12523
- EPSS 0.56%
- Published 26.11.2019 17:15:10
- Last modified 21.11.2024 04:23:01
An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTTP request doesn't go through the access checks that incoming HTTP requests go through. This causes all access checks to be bypasse...
CVE-2019-12526
- EPSS 33.64%
- Published 26.11.2019 17:15:10
- Last modified 21.11.2024 04:23:02
An issue was discovered in Squid before 4.9. URN response handling in Squid suffers from a heap-based buffer overflow. When receiving data from a remote server in response to an URN request, Squid fails to ensure that the response can fit within the ...
CVE-2019-12854
- EPSS 44.49%
- Published 15.08.2019 17:15:12
- Last modified 21.11.2024 04:23:43
Due to incorrect string termination, Squid cachemgr.cgi 4.0 through 4.7 may access unallocated memory. On systems with memory access protections, this can cause the CGI process to terminate unexpectedly, resulting in a denial of service for all clien...
CVE-2019-12525
- EPSS 55.25%
- Published 11.07.2019 19:15:13
- Last modified 21.11.2024 04:23:02
An issue was discovered in Squid 3.3.9 through 3.5.28 and 4.x through 4.7. When Squid is configured to use Digest authentication, it parses the header Proxy-Authorization. It searches for certain tokens such as domain, uri, and qop. Squid checks if t...
CVE-2019-12527
- EPSS 15.91%
- Published 11.07.2019 19:15:13
- Last modified 21.11.2024 04:23:02
An issue was discovered in Squid 4.0.23 through 4.7. When checking Basic Authentication with HttpHeader::getAuth, Squid uses a global buffer to store the decoded data. Squid does not check that the decoded length isn't greater than the buffer, leadin...
CVE-2019-12529
- EPSS 16.21%
- Published 11.07.2019 19:15:13
- Last modified 21.11.2024 04:23:02
An issue was discovered in Squid 2.x through 2.7.STABLE9, 3.x through 3.5.28, and 4.x through 4.7. When Squid is configured to use Basic Authentication, the Proxy-Authorization header is parsed via uudecode. uudecode determines how many bytes will be...
CVE-2019-13345
- EPSS 81.22%
- Published 05.07.2019 16:15:11
- Last modified 21.11.2024 04:24:45
The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.
CVE-2018-19131
- EPSS 6.83%
- Published 09.11.2018 11:29:03
- Last modified 21.11.2024 03:57:23
Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) error page generation for certificate errors.
CVE-2018-19132
- EPSS 11.35%
- Published 09.11.2018 11:29:03
- Last modified 21.11.2024 03:57:23
Squid before 4.4, when SNMP is enabled, allows a denial of service (Memory Leak) via an SNMP packet.
CVE-2018-1172
- EPSS 11.21%
- Published 16.05.2018 21:29:00
- Last modified 21.11.2024 03:59:19
This vulnerability allows remote attackers to deny service on vulnerable installations of The Squid Software Foundation Squid 3.5.27-20180318. Authentication is not required to exploit this vulnerability. The specific flaw exists within ClientRequest...