VYPR
Unrated severityNVD Advisory· Published Feb 7, 2005· Updated Jun 16, 2026

CVE-2005-0174

CVE-2005-0174

Description

Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache or conduct certain attacks via headers that do not follow the HTTP specification, including (1) multiple Content-Length headers, (2) carriage return (CR) characters that are not part of a CRLF pair, and (3) header names containing whitespace characters.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

17
  • Squid Cache/Squid16 versions
    cpe:2.3:a:squid:squid:2.5.6:*:*:*:*:*:*:*+ 15 more
    • cpe:2.3:a:squid:squid:2.5.6:*:*:*:*:*:*:*
    • cpe:2.3:a:squid:squid:2.5.stable1:*:*:*:*:*:*:*
    • cpe:2.3:a:squid:squid:2.5_.stable1:*:*:*:*:*:*:*
    • cpe:2.3:a:squid:squid:2.5.stable2:*:*:*:*:*:*:*
    • cpe:2.3:a:squid:squid:2.5.stable3:*:*:*:*:*:*:*
    • cpe:2.3:a:squid:squid:2.5_stable3:*:*:*:*:*:*:*
    • cpe:2.3:a:squid:squid:2.5_.stable3:*:*:*:*:*:*:*
    • cpe:2.3:a:squid:squid:2.5.stable4:*:*:*:*:*:*:*
    • cpe:2.3:a:squid:squid:2.5_stable4:*:*:*:*:*:*:*
    • cpe:2.3:a:squid:squid:2.5_.stable4:*:*:*:*:*:*:*
    • cpe:2.3:a:squid:squid:2.5.stable5:*:*:*:*:*:*:*
    • cpe:2.3:a:squid:squid:2.5_.stable5:*:*:*:*:*:*:*
    • cpe:2.3:a:squid:squid:2.5.stable6:*:*:*:*:*:*:*
    • cpe:2.3:a:squid:squid:2.5_.stable6:*:*:*:*:*:*:*
    • cpe:2.3:a:squid:squid:2.5.stable7:*:*:*:*:*:*:*
    • cpe:2.3:a:squid:squid:2.5_stable9:*:*:*:*:*:*:*
  • Squidex/Squidexllm-fuzzy
    Range: <=2.5.STABLE7

Patches

Vulnerability mechanics

References

13

News mentions

0

No linked articles in our index yet.