Squid-cache

Squid

109 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 74.96%
  • Veröffentlicht 06.09.2011 15:55:08
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Buffer overflow in the gopherToHTML function in gopher.cc in the Gopher reply parser in Squid 3.0 before 3.0.STABLE26, 3.1 before 3.1.15, and 3.2 before 3.2.0.11 allows remote Gopher servers to cause a denial of service (memory corruption and daemon ...

  • EPSS 55.18%
  • Veröffentlicht 12.10.2010 21:00:01
  • Zuletzt bearbeitet 29.04.2026 01:13:23

dns_internal.cc in Squid 3.1.6, when IPv6 DNS resolution is not enabled, accesses an invalid socket during an IPv4 TCP DNS query, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via vectors that trigger ...

  • EPSS 72.51%
  • Veröffentlicht 20.09.2010 21:00:02
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The string-comparison functions in String.cci in Squid 3.x before 3.1.8 and 3.2.x before 3.2.0.2 allow remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request.

  • EPSS 49.37%
  • Veröffentlicht 15.02.2010 18:30:00
  • Zuletzt bearbeitet 29.04.2026 01:13:23

The htcpHandleTstRequest function in htcp.c in Squid 2.x before 2.6.STABLE24 and 2.7 before 2.7.STABLE8, and htcp.cc in 3.0 before 3.0.STABLE24, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via craf...

  • EPSS 11.3%
  • Veröffentlicht 03.02.2010 18:30:00
  • Zuletzt bearbeitet 29.04.2026 01:13:23

lib/rfc1035.c in Squid 2.x, 3.0 through 3.0.STABLE22, and 3.1 through 3.1.0.15 allows remote attackers to cause a denial of service (assertion failure) via a crafted DNS packet that only contains a header.

  • EPSS 60.66%
  • Veröffentlicht 18.08.2009 21:00:00
  • Zuletzt bearbeitet 23.04.2026 00:35:47

The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.

  • EPSS 23.56%
  • Veröffentlicht 28.07.2009 17:30:01
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 does not properly enforce "buffer limits and related bound checks," which allows remote attackers to cause a denial of service via (1) an incomplete request or (2) a request with a large header ...

  • EPSS 26.19%
  • Veröffentlicht 28.07.2009 17:30:01
  • Zuletzt bearbeitet 23.04.2026 00:35:47

Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 allows remote attackers to cause a denial of service via malformed requests including (1) "missing or mismatched protocol identifier," (2) missing or negative status value," (3) "missing version...

  • EPSS 45.32%
  • Veröffentlicht 02.05.2005 04:00:00
  • Zuletzt bearbeitet 16.04.2026 00:27:16

Buffer overflow in wccp.c in Squid 2.5 before 2.5.STABLE7 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long WCCP packet, which is processed by a recvfrom function call that uses an incorrect length pa...