Squid-cache

Squid

111 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 4.77%
  • Veröffentlicht 27.01.2017 17:59:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

Incorrect HTTP Request header comparison in Squid HTTP Proxy 3.5.0.1 through 3.5.22, and 4.0.1 through 4.0.16 results in Collapsed Forwarding feature mistakenly identifying some private responses as being suitable for delivery to multiple clients.

  • EPSS 23.11%
  • Veröffentlicht 10.05.2016 19:59:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via a crafted Edge Side Includes (ESI) response.

Exploit
  • EPSS 53.92%
  • Veröffentlicht 10.05.2016 19:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via crafted Edge Side Includes (ESI) responses.

  • EPSS 38.89%
  • Veröffentlicht 10.05.2016 19:59:01
  • Zuletzt bearbeitet 06.05.2026 22:30:45

mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crafted HTTP Host header, aka a "header smuggling" issue.

  • EPSS 79.97%
  • Veröffentlicht 10.05.2016 19:59:00
  • Zuletzt bearbeitet 06.05.2026 22:30:45

client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.

  • EPSS 77.56%
  • Veröffentlicht 25.04.2016 14:59:05
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Includes (ESI) responses.

  • EPSS 14.36%
  • Veröffentlicht 25.04.2016 14:59:04
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers to obtain sensitive stack layout information via crafted Edge Side Includes (ESI) responses, related to incorrect use of assert and compiler optimization.

  • EPSS 12.87%
  • Veröffentlicht 25.04.2016 14:59:03
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Multiple stack-based buffer overflows in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote HTTP servers to cause a denial of service or execute arbitrary code via crafted Edge Side Includes (ESI) responses.

  • EPSS 18.28%
  • Veröffentlicht 25.04.2016 14:59:02
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data.

  • EPSS 25.55%
  • Veröffentlicht 19.04.2016 21:59:07
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The FwdState::connectedToPeer method in FwdState.cc in Squid before 3.5.14 and 4.0.x before 4.0.6 does not properly handle SSL handshake errors when built with the --with-openssl option, which allows remote attackers to cause a denial of service (app...