Squid-cache

Squid

106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 49.37%
  • Veröffentlicht 15.02.2010 18:30:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The htcpHandleTstRequest function in htcp.c in Squid 2.x before 2.6.STABLE24 and 2.7 before 2.7.STABLE8, and htcp.cc in 3.0 before 3.0.STABLE24, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via craf...

  • EPSS 16.82%
  • Veröffentlicht 03.02.2010 18:30:00
  • Zuletzt bearbeitet 11.04.2025 00:51:21

lib/rfc1035.c in Squid 2.x, 3.0 through 3.0.STABLE22, and 3.1 through 3.1.0.15 allows remote attackers to cause a denial of service (assertion failure) via a crafted DNS packet that only contains a header.

  • EPSS 60.66%
  • Veröffentlicht 18.08.2009 21:00:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.

  • EPSS 23.56%
  • Veröffentlicht 28.07.2009 17:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 does not properly enforce "buffer limits and related bound checks," which allows remote attackers to cause a denial of service via (1) an incomplete request or (2) a request with a large header ...

  • EPSS 26.19%
  • Veröffentlicht 28.07.2009 17:30:01
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 allows remote attackers to cause a denial of service via malformed requests including (1) "missing or mismatched protocol identifier," (2) missing or negative status value," (3) "missing version...

  • EPSS 41.52%
  • Veröffentlicht 02.05.2005 04:00:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Buffer overflow in wccp.c in Squid 2.5 before 2.5.STABLE7 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long WCCP packet, which is processed by a recvfrom function call that uses an incorrect length pa...