Squid-cache

Squid

106 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 79.92%
  • Veröffentlicht 25.04.2016 14:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Includes (ESI) responses.

  • EPSS 9.51%
  • Veröffentlicht 25.04.2016 14:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers to obtain sensitive stack layout information via crafted Edge Side Includes (ESI) responses, related to incorrect use of assert and compiler optimization.

  • EPSS 12.51%
  • Veröffentlicht 25.04.2016 14:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple stack-based buffer overflows in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote HTTP servers to cause a denial of service or execute arbitrary code via crafted Edge Side Includes (ESI) responses.

  • EPSS 3.67%
  • Veröffentlicht 25.04.2016 14:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data.

  • EPSS 21.28%
  • Veröffentlicht 19.04.2016 21:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The FwdState::connectedToPeer method in FwdState.cc in Squid before 3.5.14 and 4.0.x before 4.0.6 does not properly handle SSL handshake errors when built with the --with-openssl option, which allows remote attackers to cause a denial of service (app...

  • EPSS 50.79%
  • Veröffentlicht 07.04.2016 18:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Squid 3.x before 3.5.16 and 4.x before 4.0.8 improperly perform bounds checking, which allows remote attackers to cause a denial of service via a crafted HTTP response, related to Vary headers.

  • EPSS 78.81%
  • Veröffentlicht 07.04.2016 18:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.cc in the pinger utility in Squid before 3.5.16 and 4.x before 4.0.8 allows remote servers to cause a denial of service (performance degradation or transition failures) or write sen...

  • EPSS 15.16%
  • Veröffentlicht 27.02.2016 05:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

http.cc in Squid 4.x before 4.0.7 relies on the HTTP status code after a response-parsing failure, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a malformed response.

  • EPSS 13.93%
  • Veröffentlicht 27.02.2016 05:59:05
  • Zuletzt bearbeitet 12.04.2025 10:46:40

http.cc in Squid 3.x before 3.5.15 and 4.x before 4.0.7 proceeds with the storage of certain data after a response-parsing failure, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a malformed resp...

  • EPSS 9.55%
  • Veröffentlicht 27.02.2016 05:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The Edge Side Includes (ESI) parser in Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not check buffer limits during XML parsing, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a crafted XML d...