VYPR

Squidex

by Squidex

Source repositories

CVEs (157)

  • CVE-2016-2390MedApr 19, 2016
    risk 0.40cvss 5.9epss 0.26

    The FwdState::connectedToPeer method in FwdState.cc in Squid before 3.5.14 and 4.0.x before 4.0.6 does not properly handle SSL handshake errors when built with the --with-openssl option, which allows remote attackers to cause a denial of service (application crash) via a…

  • CVE-2019-12521MedApr 15, 2020
    risk 0.39cvss 5.9epss 0.06

    An issue was discovered in Squid through 4.7. When Squid is parsing ESI, it keeps the ESI elements in ESIContext. ESIContext contains a buffer for holding a stack of ESIElements. When a new ESIElement is parsed, it is added via addStackElement. addStackElement has a check for…

  • CVE-2019-12529MedJul 11, 2019
    risk 0.39cvss 5.9epss 0.08

    An issue was discovered in Squid 2.x through 2.7.STABLE9, 3.x through 3.5.28, and 4.x through 4.7. When Squid is configured to use Basic Authentication, the Proxy-Authorization header is parsed via uudecode. uudecode determines how many bytes will be decoded by iterating over…

  • CVE-2026-33515MedMar 26, 2026
    risk 0.35cvss 6.5epss 0.01

    Squid is a caching proxy for the Web. Prior to version 7.5, due to improper input validation, Squid is vulnerable to out of bounds read when handling ICP traffic. This problem allows a remote attacker to receive small amounts of memory potentially containing sensitive…

  • CVE-2023-46857MedDec 7, 2023
    risk 0.35cvss 5.4epss 0.01

    Squidex before 7.9.0 allows XSS via an SVG document to the Upload Assets feature. This occurs because there is an incomplete blacklist in the SVG inspection, allowing JavaScript in the SRC attribute of an IFRAME element. An authenticated attack with assets.create permission is…

  • CVE-2023-46744MedNov 7, 2023
    risk 0.35cvss 5.4epss 0.01

    Squidex is an open source headless CMS and content management hub. In affected versions a stored Cross-Site Scripting (XSS) vulnerability enables privilege escalation of authenticated users. The SVG element filtering mechanism intended to stop XSS attacks through uploaded SVG…

  • CVE-2019-18677MedNov 26, 2019
    risk 0.33cvss 6.1epss 0.07

    An issue was discovered in Squid 3.x and 4.x through 4.8 when the append_domain setting is used (because the appended characters do not properly interact with hostname length restrictions). Due to incorrect message processing, it can inappropriately redirect traffic to origins…

  • CVE-2021-28652MedMay 27, 2021
    risk 0.32cvss 4.9epss 0.04

    An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to incorrect parser validation, it allows a Denial of Service attack against the Cache Manager API. This allows a trusted client to trigger memory leaks that. over time, lead to a Denial of Service via an…

  • CVE-2026-41177MedApr 22, 2026
    risk 0.29cvss 5.5epss 0.00

    Squidex is an open source headless content management system and content management hub. Prior to version 7.23.0, the Squidex Restore API is vulnerable to Blind Server-Side Request Forgery (SSRF). The application fails to validate the URI scheme of the user-supplied `Url`…

  • CVE-2019-12522MedApr 15, 2020
    risk 0.29cvss 4.5epss 0.00

    An issue was discovered in Squid through 4.7. When Squid is run as root, it spawns its child processes as a lesser user, by default the user nobody. This is done via the leave_suid call. leave_suid leaves the Saved UID as 0. This makes it trivial for an attacker who has…

  • CVE-2019-18678MedNov 26, 2019
    risk 0.28cvss 5.3epss 0.11

    An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend software to a Squid instance that splits the HTTP Request pipeline differently. The resulting Response messages corrupt caches (between a client and Squid)…

  • CVE-2021-28116LowMar 9, 2021
    risk 0.25cvss 3.7epss 0.13

    Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as part of a chain for remote code execution as nobody.

  • CVE-2016-4053LowApr 25, 2016
    risk 0.25cvss 3.7epss 0.14

    Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers to obtain sensitive stack layout information via crafted Edge Side Includes (ESI) responses, related to incorrect use of assert and compiler optimization.

  • CVE-2013-4123Sep 16, 2013
    risk 0.09cvss epss 0.80

    client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of service via a crafted port number in a HTTP Host header.

  • CVE-2009-0478Feb 8, 2009
    risk 0.09cvss epss 0.72

    Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request with an invalid version number, which triggers a reachable assertion in (1) HttpMsg.c and (2) HttpStatusLine.c.

  • CVE-2024-25617MedFeb 14, 2024
    risk 0.07cvss 5.3epss 0.89

    Squid is an open source caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Collapse of Data into Unsafe Value bug ,Squid may be vulnerable to a Denial of Service attack against HTTP header parsing. This problem allows a remote client or a remote server to…

  • CVE-2023-49285HigDec 4, 2023
    risk 0.07cvss 8.6epss 0.89

    Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no…

  • CVE-2021-28662MedMay 27, 2021
    risk 0.06cvss 6.5epss 0.72

    An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6. If a remote server sends a certain response header over HTTP or HTTPS, there is a denial of service. This header can plausibly occur in benign network traffic.

  • CVE-2019-13345MedJul 5, 2019
    risk 0.06cvss 6.1epss 0.74

    The cachemgr.cgi web module of Squid through 4.7 has XSS via the user_name or auth parameter.

  • CVE-2014-7141Nov 26, 2014
    risk 0.06cvss epss 0.76

    The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (out-of-bounds read and crash) via a crafted type in an (1) ICMP or (2) ICMP6 packet.

Page 4 of 8