VYPR

Vendor CVEs

Squidex

All CVEs

157 total · sorted by risk
  • CVE-2010-2951Oct 12, 2010
    risk 0.03cvss —epss 0.31

    dns_internal.cc in Squid 3.1.6, when IPv6 DNS resolution is not enabled, accesses an invalid socket during an IPv4 TCP DNS query, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via vectors that trigger an IPv4 DNS response with the…

  • CVE-2009-2855Aug 18, 2009
    risk 0.03cvss —epss 0.34

    The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.

  • CVE-2005-0446May 2, 2005
    risk 0.03cvss —epss 0.41

    Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Qualified Domain Names (FQDN) in fqdncache.c or (2) IP addresses in ipcache.c, which trigger an assertion failure.

  • CVE-2005-0175Feb 7, 2005
    risk 0.03cvss —epss 0.41

    Squid 2.5 up to 2.5.STABLE7 allows remote attackers to poison the cache via an HTTP response splitting attack.

  • CVE-1999-1481Dec 31, 1999
    risk 0.03cvss —epss 0.04

    Squid 2.2.STABLE5 and below, when using external authentication, allows attackers to bypass access controls via a newline in the user/password pair.

  • CVE-2015-5400Sep 28, 2015
    risk 0.02cvss —epss 0.21

    Squid before 3.5.6 does not properly handle CONNECT method peer responses when configured with cache_peer, which allows remote attackers to bypass intended restrictions and gain access to a backend proxy via a CONNECT request.

  • CVE-2014-7142Nov 26, 2014
    risk 0.02cvss —epss 0.25

    The pinger in Squid 3.x before 3.4.8 allows remote attackers to obtain sensitive information or cause a denial of service (crash) via a crafted (1) ICMP or (2) ICMP6 packet size.

  • CVE-2014-6270Sep 12, 2014
    risk 0.02cvss —epss 0.23

    Off-by-one error in the snmpHandleUdp function in snmp_core.cc in Squid 2.x and 3.x, when an SNMP port is configured, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted UDP SNMP request, which triggers a heap-based…

  • CVE-2013-0189Feb 8, 2013
    risk 0.02cvss —epss 0.23

    cachemgr.cgi in Squid 3.1.x and 3.2.x, possibly 3.1.22, 3.2.4, and other versions, allows remote attackers to cause a denial of service (resource consumption) via a crafted request. NOTE: this issue is due to an incorrect fix for CVE-2012-5643, possibly involving an incorrect…

  • CVE-2012-5643Dec 20, 2012
    risk 0.02cvss —epss 0.23

    Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and 3.x before 3.1.22, 3.2.x before 3.2.4, and 3.3.x before 3.3.0.2 allow remote attackers to cause a denial of service (memory consumption) via (1) invalid Content-Length headers, (2) long POST requests, or…

  • CVE-2011-3205Sep 6, 2011
    risk 0.02cvss —epss 0.27

    Buffer overflow in the gopherToHTML function in gopher.cc in the Gopher reply parser in Squid 3.0 before 3.0.STABLE26, 3.1 before 3.1.15, and 3.2 before 3.2.0.11 allows remote Gopher servers to cause a denial of service (memory corruption and daemon restart) or possibly have…

  • CVE-2010-0639Feb 15, 2010
    risk 0.02cvss —epss 0.31

    The htcpHandleTstRequest function in htcp.c in Squid 2.x before 2.6.STABLE24 and 2.7 before 2.7.STABLE8, and htcp.cc in 3.0 before 3.0.STABLE24, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via crafted packets to the HTCP port.

  • CVE-2010-0308Feb 3, 2010
    risk 0.02cvss —epss 0.28

    lib/rfc1035.c in Squid 2.x, 3.0 through 3.0.STABLE22, and 3.1 through 3.1.0.15 allows remote attackers to cause a denial of service (assertion failure) via a crafted DNS packet that only contains a header.

  • CVE-2009-2621Jul 28, 2009
    risk 0.02cvss —epss 0.23

    Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 does not properly enforce "buffer limits and related bound checks," which allows remote attackers to cause a denial of service via (1) an incomplete request or (2) a request with a large header size, related to (a)…

  • CVE-2007-6239Dec 4, 2007
    risk 0.02cvss —epss 0.27

    The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial of service (crash) via unknown vectors related to HTTP headers and an Array memory leak during requests for cached objects.

  • CVE-2007-1560Mar 21, 2007
    risk 0.02cvss —epss 0.27

    The clientProcessRequest() function in src/client_side.c in Squid 2.6 before 2.6.STABLE12 allows remote attackers to cause a denial of service (daemon crash) via crafted TRACE requests that trigger an assertion error.

  • CVE-2005-0211May 2, 2005
    risk 0.02cvss —epss 0.22

    Buffer overflow in wccp.c in Squid 2.5 before 2.5.STABLE7 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long WCCP packet, which is processed by a recvfrom function call that uses an incorrect length parameter.

  • CVE-2023-49286HigDec 4, 2023
    risk 0.01cvss 8.6epss 0.10

    Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to an Incorrect Check of Function Return Value bug Squid is vulnerable to a Denial of Service attack against its Helper process management. This bug is fixed by Squid version 6.5. Users are advised…

  • CVE-2014-9749Nov 6, 2015
    risk 0.01cvss —epss 0.11

    Squid 3.4.4 through 3.4.11 and 3.5.0.1 through 3.5.1, when Digest authentication is used, allow remote authenticated users to retain access by leveraging a stale nonce, aka "Nonce replay vulnerability."

  • CVE-2015-3455May 18, 2015
    risk 0.01cvss —epss 0.11

    Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers…

  • CVE-2013-1839Sep 30, 2013
    risk 0.01cvss —epss 0.18

    The strHdrAcptLangGetItem function in errorpage.cc in Squid 3.2.x before 3.2.9 and 3.3.x before 3.3.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a "," character in an Accept-Language header.

  • CVE-2012-2213Apr 28, 2012
    risk 0.01cvss —epss 0.12

    Squid 3.1.9 allows remote attackers to bypass the access configuration for the CONNECT method by providing an arbitrary allowed hostname in the Host HTTP header. NOTE: this issue might not be reproducible, because the researcher is unable to provide a squid.conf file for a…

  • CVE-2007-0248Jan 16, 2007
    risk 0.01cvss —epss 0.07

    The aclMatchExternal function in Squid before 2.6.STABLE7 allows remote attackers to cause a denial of service (crash) by causing an external_acl queue overload, which triggers an infinite loop.

  • CVE-2005-2796Sep 7, 2005
    risk 0.01cvss —epss 0.08

    The sslConnectTimeout function in ssl.c for Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (segmentation fault) via certain crafted requests.

  • CVE-2005-0718Apr 14, 2005
    risk 0.01cvss —epss 0.13

    Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (segmentation fault) by aborting the connection during a (1) PUT or (2) POST request, which causes Squid to access previously freed memory.

  • CVE-2004-0918Jan 27, 2005
    risk 0.01cvss —epss 0.16

    The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of service (server restart) via certain SNMP packets with negative length fields that trigger a memory allocation error.

  • CVE-2005-0096Jan 25, 2005
    risk 0.01cvss —epss 0.09

    Memory leak in the NTLM fakeauth_auth helper for Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (memory consumption).

  • CVE-2005-0094Jan 15, 2005
    risk 0.01cvss —epss 0.09

    Buffer overflow in the gopherToHTML function in the Gopher reply parser for Squid 2.5.STABLE7 and earlier allows remote malicious Gopher servers to cause a denial of service (crash) via crafted responses.

  • CVE-2005-0097Jan 11, 2005
    risk 0.01cvss —epss 0.11

    The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3 message that triggers a NULL dereference.

  • CVE-2004-0832Nov 3, 2004
    risk 0.01cvss —epss 0.10

    The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and earlier, with NTLM authentication enabled, allow remote attackers to cause a denial of service (application crash) via an NTLMSSP packet that causes a negative value to be passed to memcpy.

  • CVE-2026-31016MedJun 29, 2026
    risk 0.00cvss 6.5epss 0.00

    Cross Site Request Forgery vulnerability in Squidex.io Squidex CMS v.7.21.0 and before allows a remote attacker to escalate privileges via the IdentityServer account profile endpoint

  • CVE-2023-46728HigNov 6, 2023
    risk 0.00cvss 7.5epss 0.06

    Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a NULL pointer dereference bug Squid is vulnerable to a Denial of Service attack against Squid's Gopher gateway. The gopher protocol is always available and enabled in Squid prior to Squid 6.0.1.…

  • CVE-2023-46724HigNov 1, 2023
    risk 0.00cvss 8.6epss 0.04

    Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem…

  • CVE-2023-3580MedJul 10, 2023
    risk 0.00cvss 4.3epss 0.01

    Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.

  • CVE-2023-0643MedFeb 2, 2023
    risk 0.00cvss 6.1epss 0.01

    Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.

  • CVE-2023-0642MedFeb 2, 2023
    risk 0.00cvss 6.5epss 0.00

    Cross-Site Request Forgery (CSRF) in GitHub repository squidex/squidex prior to 7.4.0.

  • CVE-2021-46784MedJul 17, 2022
    risk 0.00cvss 6.5epss 0.05

    In Squid 3.x through 3.5.28, 4.x through 4.17, and 5.x before 5.6, due to improper buffer management, a Denial of Service can occur when processing long Gopher server responses.

  • CVE-2015-0881Feb 20, 2015
    risk 0.00cvss —epss 0.05

    CRLF injection vulnerability in Squid before 3.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted header in a response.

  • CVE-2009-0801Mar 4, 2009
    risk 0.00cvss —epss 0.03

    Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted…

  • CVE-2008-1612Apr 1, 2008
    risk 0.00cvss —epss 0.02

    The arrayShrink function (lib/Array.c) in Squid 2.6.STABLE17 allows attackers to cause a denial of service (process exit) via unknown vectors that cause an array to shrink to 0 entries, which triggers an assert error. NOTE: this issue is due to an incorrect fix for…

  • CVE-2005-3258Oct 20, 2005
    risk 0.00cvss —epss 0.02

    The rfc1738_do_escape function in ftp.c for Squid 2.5 STABLE11 and earlier allows remote FTP servers to cause a denial of service (segmentation fault) via certain "odd" responses.

  • CVE-2005-2917Sep 30, 2005
    risk 0.00cvss —epss 0.03

    Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart).

  • CVE-2005-2794Sep 7, 2005
    risk 0.00cvss —epss 0.03

    store.c in Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (crash) via certain aborted requests that trigger an assert error related to STORE_PENDING.

  • CVE-2005-1519May 11, 2005
    risk 0.00cvss —epss 0.02

    Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attackers to spoof DNS lookups.

  • CVE-2005-0194May 2, 2005
    risk 0.00cvss —epss 0.05

    Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator…

  • CVE-2005-1345May 2, 2005
    risk 0.00cvss —epss 0.02

    Squid 2.5.STABLE9 and earlier does not trigger a fatal error when it identifies missing or invalid ACLs in the http_access configuration, which could lead to less restrictive ACLs than intended by the administrator.

  • CVE-2005-0626Mar 8, 2005
    risk 0.00cvss —epss 0.01

    Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-Cookie recommendations for handling cookies in caches, may cause Set-Cookie headers to be sent to other users, which allows attackers to steal the related cookies.

  • CVE-2004-2654Dec 31, 2004
    risk 0.00cvss —epss 0.02

    The clientAbortBody function in client_side.c in Squid Web Proxy Cache before 2.6 STABLE6 allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors that trigger a null dereference. NOTE: in a followup advisory, a researcher claimed that…

  • CVE-2002-0715Jul 26, 2002
    risk 0.00cvss —epss 0.02

    Vulnerability in Squid before 2.4.STABLE6 related to proxy authentication credentials may allow remote web sites to obtain the user's proxy login and password.

  • CVE-2002-0714Jul 26, 2002
    risk 0.00cvss —epss 0.03

    FTP proxy in Squid before 2.4.STABLE6 does not compare the IP addresses of control and data connections with the FTP server, which allows remote attackers to bypass firewall rules or spoof FTP server responses.