Squidex
by Squidex
Source repositories
CVEs (157)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2005-2796 | 0.01 | — | 0.08 | Sep 7, 2005 | The sslConnectTimeout function in ssl.c for Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (segmentation fault) via certain crafted requests. | |||
| CVE-2005-0718 | 0.01 | — | 0.13 | Apr 14, 2005 | Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (segmentation fault) by aborting the connection during a (1) PUT or (2) POST request, which causes Squid to access previously freed memory. | |||
| CVE-2004-0918 | 0.01 | — | 0.16 | Jan 27, 2005 | The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of service (server restart) via certain SNMP packets with negative length fields that trigger a memory allocation error. | |||
| CVE-2005-0096 | 0.01 | — | 0.09 | Jan 25, 2005 | Memory leak in the NTLM fakeauth_auth helper for Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (memory consumption). | |||
| CVE-2005-0094 | 0.01 | — | 0.09 | Jan 15, 2005 | Buffer overflow in the gopherToHTML function in the Gopher reply parser for Squid 2.5.STABLE7 and earlier allows remote malicious Gopher servers to cause a denial of service (crash) via crafted responses. | |||
| CVE-2005-0097 | 0.01 | — | 0.11 | Jan 11, 2005 | The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3 message that triggers a NULL dereference. | |||
| CVE-2004-0832 | 0.01 | — | 0.11 | Nov 3, 2004 | The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and earlier, with NTLM authentication enabled, allow remote attackers to cause a denial of service (application crash) via an NTLMSSP packet that causes a negative value to be passed to memcpy. | |||
| CVE-2026-31016 | Med | 0.00 | 6.5 | 0.00 | Jun 29, 2026 | Cross Site Request Forgery vulnerability in Squidex.io Squidex CMS v.7.21.0 and before allows a remote attacker to escalate privileges via the IdentityServer account profile endpoint | ||
| CVE-2023-46728 | Hig | 0.00 | 7.5 | 0.06 | Nov 6, 2023 | Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of Service attack against Squid's Gopher gateway. The gopher protocol is always available and enabled in Squid prior to Squid 6.0.1.… | ||
| CVE-2023-46724 | Hig | 0.00 | 8.6 | 0.04 | Nov 1, 2023 | Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem… | ||
| CVE-2023-3580 | Med | 0.00 | 4.3 | 0.01 | Jul 10, 2023 | Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0. | ||
| CVE-2023-0643 | Med | 0.00 | 6.1 | 0.01 | Feb 2, 2023 | Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0. | ||
| CVE-2023-0642 | Med | 0.00 | 6.5 | 0.00 | Feb 2, 2023 | Cross-Site Request Forgery (CSRF) in GitHub repository squidex/squidex prior to 7.4.0. | ||
| CVE-2021-46784 | Med | 0.00 | 6.5 | 0.05 | Jul 17, 2022 | In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses. | ||
| CVE-2019-18860 | Med | 0.00 | 6.1 | 0.06 | Mar 20, 2020 | Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi. | ||
| CVE-2018-19132 | Med | 0.00 | 5.9 | 0.06 | Nov 9, 2018 | Squid before 4.4, when SNMP is enabled, allows a denial of service (Memory Leak) via an SNMP packet. | ||
| CVE-2018-19131 | Med | 0.00 | 6.1 | 0.03 | Nov 9, 2018 | Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) error page generation for certificate errors. | ||
| CVE-2015-0881 | 0.00 | — | 0.05 | Feb 20, 2015 | CRLF injection vulnerability in Squid before 3.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted header in a response. | |||
| CVE-2009-0801 | 0.00 | — | 0.03 | Mar 4, 2009 | Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted… | |||
| CVE-2008-1612 | 0.00 | — | 0.02 | Apr 1, 2008 | The arrayShrink function (lib/Array.c) in Squid 2.6.STABLE17 allows attackers to cause a denial of service (process exit) via unknown vectors that cause an array to shrink to 0 entries, which triggers an assert error. NOTE: this issue is due to an incorrect fix for… |
- CVE-2005-2796Sep 7, 2005risk 0.01cvss —epss 0.08
The sslConnectTimeout function in ssl.c for Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (segmentation fault) via certain crafted requests.
- CVE-2005-0718Apr 14, 2005risk 0.01cvss —epss 0.13
Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (segmentation fault) by aborting the connection during a (1) PUT or (2) POST request, which causes Squid to access previously freed memory.
- CVE-2004-0918Jan 27, 2005risk 0.01cvss —epss 0.16
The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of service (server restart) via certain SNMP packets with negative length fields that trigger a memory allocation error.
- CVE-2005-0096Jan 25, 2005risk 0.01cvss —epss 0.09
Memory leak in the NTLM fakeauth_auth helper for Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (memory consumption).
- CVE-2005-0094Jan 15, 2005risk 0.01cvss —epss 0.09
Buffer overflow in the gopherToHTML function in the Gopher reply parser for Squid 2.5.STABLE7 and earlier allows remote malicious Gopher servers to cause a denial of service (crash) via crafted responses.
- CVE-2005-0097Jan 11, 2005risk 0.01cvss —epss 0.11
The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3 message that triggers a NULL dereference.
- CVE-2004-0832Nov 3, 2004risk 0.01cvss —epss 0.11
The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and earlier, with NTLM authentication enabled, allow remote attackers to cause a denial of service (application crash) via an NTLMSSP packet that causes a negative value to be passed to memcpy.
- risk 0.00cvss 6.5epss 0.00
Cross Site Request Forgery vulnerability in Squidex.io Squidex CMS v.7.21.0 and before allows a remote attacker to escalate privileges via the IdentityServer account profile endpoint
- risk 0.00cvss 7.5epss 0.06
Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of Service attack against Squid's Gopher gateway. The gopher protocol is always available and enabled in Squid prior to Squid 6.0.1.…
- risk 0.00cvss 8.6epss 0.04
Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem…
- risk 0.00cvss 4.3epss 0.01
Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.
- risk 0.00cvss 6.1epss 0.01
Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.
- risk 0.00cvss 6.5epss 0.00
Cross-Site Request Forgery (CSRF) in GitHub repository squidex/squidex prior to 7.4.0.
- risk 0.00cvss 6.5epss 0.05
In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses.
- risk 0.00cvss 6.1epss 0.06
Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi.
- risk 0.00cvss 5.9epss 0.06
Squid before 4.4, when SNMP is enabled, allows a denial of service (Memory Leak) via an SNMP packet.
- risk 0.00cvss 6.1epss 0.03
Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) error page generation for certificate errors.
- CVE-2015-0881Feb 20, 2015risk 0.00cvss —epss 0.05
CRLF injection vulnerability in Squid before 3.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted header in a response.
- CVE-2009-0801Mar 4, 2009risk 0.00cvss —epss 0.03
Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted…
- CVE-2008-1612Apr 1, 2008risk 0.00cvss —epss 0.02
The arrayShrink function (lib/Array.c) in Squid 2.6.STABLE17 allows attackers to cause a denial of service (process exit) via unknown vectors that cause an array to shrink to 0 entries, which triggers an assert error. NOTE: this issue is due to an incorrect fix for…
Page 7 of 8