Squid-cache

Squid

109 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.45%
  • Veröffentlicht 01.11.2023 20:15:08
  • Zuletzt bearbeitet 13.02.2025 18:15:36

Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate v...

  • EPSS 1.75%
  • Veröffentlicht 25.12.2022 19:15:10
  • Zuletzt bearbeitet 14.04.2025 19:15:31

An issue was discovered in Squid 4.9 through 4.17 and 5.0.6 through 5.6. Due to inconsistent handling of internal URIs, there can be Exposure of Sensitive Information about clients using the proxy via an HTTPS request to an internal cache manager URL...

  • EPSS 0.12%
  • Veröffentlicht 25.12.2022 19:15:10
  • Zuletzt bearbeitet 14.04.2025 19:15:31

A buffer over-read was discovered in libntlmauth in Squid 2.5 through 5.6. Due to incorrect integer-overflow protection, the SSPI and SMB authentication helpers are vulnerable to reading unintended memory locations. In some configurations, cleartext ...

  • EPSS 16.36%
  • Veröffentlicht 17.07.2022 22:15:08
  • Zuletzt bearbeitet 21.11.2024 06:34:42

In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses.

  • EPSS 2.16%
  • Veröffentlicht 18.10.2021 09:15:08
  • Zuletzt bearbeitet 21.11.2024 06:26:31

An issue was discovered in Squid 5.0.6 through 5.1.x before 5.2. When validating an origin server or peer certificate, Squid may incorrectly classify certain certificates as trusted. This problem allows a remote server to obtain security trust well i...

  • EPSS 33.71%
  • Veröffentlicht 08.06.2021 20:15:09
  • Zuletzt bearbeitet 21.11.2024 06:06:15

An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to achieve Denial of Service when delivering responses to HTTP Range requests. The issue trigger is a header that can be expected to...

  • EPSS 9.64%
  • Veröffentlicht 28.05.2021 12:15:07
  • Zuletzt bearbeitet 21.11.2024 06:09:12

Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all clients) via an HTTP response. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious ...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 27.05.2021 14:15:07
  • Zuletzt bearbeitet 21.11.2024 06:06:16

An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to an input-validation bug, it is vulnerable to a Denial of Service attack (against all clients using the proxy). A client sends an HTTP Range request to trigger this.

  • EPSS 85.18%
  • Veröffentlicht 27.05.2021 13:15:08
  • Zuletzt bearbeitet 21.11.2024 06:06:15

An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a memory-management bug, it is vulnerable to a Denial of Service attack (against all clients using the proxy) via HTTP Range request processing.

Exploit
  • EPSS 6.13%
  • Veröffentlicht 27.05.2021 12:15:08
  • Zuletzt bearbeitet 21.11.2024 06:00:01

An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a buffer-management bug, it allows a denial of service. When resolving a request with the urn: scheme, the parser leaks a small amount of memory. However, there is an unspecifi...