Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
squid-cache squid 3.0 vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2018-1000024
The Squid Software Foundation Squid HTTP Caching Proxy version 3.0 to 3.5.27, 4.0 to 4.0.22 contains a Incorrect Pointer Handling vulnerability in ESI Response Processing that can result in Denial of Service for all clients using the proxy.. This attack appear to be exploitable v...
Squid-cache Squid
Debian Debian Linux 8.0
Debian Debian Linux 7.0
Debian Debian Linux 9.0
Canonical Ubuntu Linux 16.04
Canonical Ubuntu Linux 14.04
Canonical Ubuntu Linux 17.10
7.5
CVSSv3
CVE-2016-2570
The Edge Side Includes (ESI) parser in Squid 3.x prior to 3.5.15 and 4.x prior to 4.0.7 does not check buffer limits during XML parsing, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a crafted XML document, related to esi/Cu...
Squid-cache Squid 3.2.0.18
Squid-cache Squid 3.1.0.18
Squid-cache Squid 3.0.stable13
Squid-cache Squid 3.3.3
Squid-cache Squid 3.2.0.9
Squid-cache Squid 3.3.11
Squid-cache Squid 3.0
Squid-cache Squid 4.0.5
Squid-cache Squid 3.0.stable9
Squid-cache Squid 3.1.13
Squid-cache Squid 4.0.3
Squid-cache Squid 3.3.5
Squid-cache Squid 3.2.0.1
Squid-cache Squid 3.0.stable20
Squid-cache Squid 3.3.0.3
Squid-cache Squid 3.0.stable14
Squid-cache Squid 3.3.13
Squid-cache Squid 3.2.2
Squid-cache Squid 3.0.stable3
Squid-cache Squid 3.2.4
Squid-cache Squid 3.2.0.6
Squid-cache Squid 3.1.0.7
NA
CVE-2014-6270
Off-by-one error in the snmpHandleUdp function in snmp_core.cc in Squid 2.x and 3.x, when an SNMP port is configured, allows remote malicious users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted UDP SNMP request, which triggers a heap-based ...
Squid-cache Squid 3.2.0.18
Squid-cache Squid 3.1.0.18
Squid-cache Squid 3.0.stable13
Squid-cache Squid 3.3.3
Squid-cache Squid 2.5.stable6
Squid-cache Squid 2.7.stable5
Squid-cache Squid 3.2.0.9
Squid-cache Squid 3.3.11
Squid-cache Squid 3.0
Squid-cache Squid 2.6.stable21
Squid-cache Squid 2.6.stable22
Squid-cache Squid 3.0.stable9
Squid-cache Squid 3.1.13
Squid-cache Squid 2.5.stable9
Squid-cache Squid 3.3.5
Squid-cache Squid 3.2.0.1
Squid-cache Squid 2.6.stable9
Squid-cache Squid 2.4.stable3
Squid-cache Squid 2.4.stable6
Squid-cache Squid 3.0.stable20
Squid-cache Squid 3.3.0.3
Squid-cache Squid 3.0.stable14
NA
CVE-2012-5643
Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and 3.x prior to 3.1.22, 3.2.x prior to 3.2.4, and 3.3.x prior to 3.3.0.2 allow remote malicious users to cause a denial of service (memory consumption) via (1) invalid Content-Length headers, (2) long POST r...
Squid-cache Squid 2.6
Squid-cache Squid 2.0
Squid-cache Squid 2.7
Squid-cache Squid 2.2
Squid-cache Squid 2.3
Squid-cache Squid 2.5
Squid-cache Squid 2.1
Squid-cache Squid 2.4
Squid-cache Squid 3.1.0.18
Squid-cache Squid 3.0.stable13
Squid-cache Squid 3.1.21
Squid-cache Squid 3.0
Squid-cache Squid 3.0.stable9
Squid-cache Squid 3.1.13
Squid-cache Squid 3.0.stable20
Squid-cache Squid 3.0.stable14
Squid-cache Squid 3.0.stable3
Squid-cache Squid 3.1.17
Squid-cache Squid 3.1.0.7
Squid-cache Squid 3.1.0.14
Squid-cache Squid 3.0.stable4
Squid-cache Squid 3.1.0.12
NA
CVE-2011-4096
The idnsGrokReply function in Squid prior to 3.1.16 does not properly free memory, which allows remote malicious users to cause a denial of service (daemon abort) via a DNS reply containing a CNAME record that references another CNAME record that contains an empty A record.
Squid-cache Squid 3.1.0.18
Squid-cache Squid 3.0.stable13
Squid-cache Squid 3.0
Squid-cache Squid 3.0.stable9
Squid-cache Squid 3.1.13
Squid-cache Squid 3.0.stable20
Squid-cache Squid 3.0.stable14
Squid-cache Squid 3.0.stable3
Squid-cache Squid 3.1.0.7
Squid-cache Squid 3.1.0.14
Squid-cache Squid 3.0.stable4
Squid-cache Squid 3.1.0.12
Squid-cache Squid 3.1.1
Squid-cache Squid 3.0.stable24
Squid-cache Squid 3.1.0.3
Squid-cache Squid 3.1.0.1
Squid-cache Squid 3.0.stable16
Squid-cache Squid 3.1.14
Squid-cache Squid 3.1.8
Squid-cache Squid 3.0.stable11
Squid-cache Squid 3.0.stable18
Squid-cache Squid 3.0.stable1
NA
CVE-2011-3205
Buffer overflow in the gopherToHTML function in gopher.cc in the Gopher reply parser in Squid 3.0 prior to 3.0.STABLE26, 3.1 prior to 3.1.15, and 3.2 prior to 3.2.0.11 allows remote Gopher servers to cause a denial of service (memory corruption and daemon restart) or possibly hav...
Squid-cache Squid 3.0.stable13
Squid-cache Squid 3.0.stable9
Squid-cache Squid 3.0.stable20
Squid-cache Squid 3.0.stable14
Squid-cache Squid 3.0.stable3
Squid-cache Squid 3.0.stable4
Squid-cache Squid 3.0.stable24
Squid-cache Squid 3.0.stable16
Squid-cache Squid 3.0.stable11
Squid-cache Squid 3.0.stable18
Squid-cache Squid 3.0.stable1
Squid-cache Squid 3.0.stable6
Squid-cache Squid 3.0.stable15
Squid-cache Squid 3.0.stable5
Squid-cache Squid 3.0.stable21
Squid-cache Squid 3.0.stable17
Squid-cache Squid 3.0.stable10
Squid-cache Squid 3.0.stable8
Squid-cache Squid 3.0.stable12
Squid-cache Squid 3.0.stable25
Squid-cache Squid 3.0.stable23
Squid-cache Squid 3.0.stable22
NA
CVE-2010-3072
The string-comparison functions in String.cci in Squid 3.x prior to 3.1.8 and 3.2.x prior to 3.2.0.2 allow remote malicious users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request.
Squid-cache Squid 3.1.0.18
Squid-cache Squid 3.0.stable13
Squid-cache Squid 3.0.stable9
Squid-cache Squid 3.0.stable20
Squid-cache Squid 3.0.stable14
Squid-cache Squid 3.0.stable3
Squid-cache Squid 3.1.0.7
Squid-cache Squid 3.1.0.14
Squid-cache Squid 3.0.stable4
Squid-cache Squid 3.1.0.12
Squid-cache Squid 3.1.1
Squid-cache Squid 3.0.stable24
Squid-cache Squid 3.1.0.3
Squid-cache Squid 3.1.0.1
Squid-cache Squid 3.0.stable16
Squid-cache Squid 3.0.stable11
Squid-cache Squid 3.0.stable18
Squid-cache Squid 3.0.stable1
Squid-cache Squid 3.1.6
Squid-cache Squid 3.1.0.9
Squid-cache Squid 3.1.0.15
Squid-cache Squid 3.0.stable6
NA
CVE-2010-0639
The htcpHandleTstRequest function in htcp.c in Squid 2.x prior to 2.6.STABLE24 and 2.7 prior to 2.7.STABLE8, and htcp.cc in 3.0 prior to 3.0.STABLE24, allows remote malicious users to cause a denial of service (NULL pointer dereference and daemon crash) via crafted packets to the...
Squid-cache Squid 3.0.stable13
Squid-cache Squid 2.6
Squid-cache Squid 3.0.stable9
Squid-cache Squid 2.0
Squid-cache Squid 3.0.stable20
Squid-cache Squid 3.0.stable14
Squid-cache Squid 3.0.stable3
Squid-cache Squid 3.0.stable4
Squid-cache Squid 2.7
Squid-cache Squid 2.2
Squid-cache Squid 3.0.stable16
Squid-cache Squid 2.3
Squid-cache Squid 3.0.stable18
Squid-cache Squid 3.0.stable1
Squid-cache Squid 3.0.stable6
Squid-cache Squid 3.0.stable15
Squid-cache Squid 2.5
Squid-cache Squid 3.0.stable5
Squid-cache Squid 3.0.stable21
Squid-cache Squid 3.0.stable17
Squid-cache Squid 3.0.stable11
Squid-cache Squid 2.1
NA
CVE-2010-0308
lib/rfc1035.c in Squid 2.x, 3.0 up to and including 3.0.STABLE22, and 3.1 up to and including 3.1.0.15 allows remote malicious users to cause a denial of service (assertion failure) via a crafted DNS packet that only contains a header.
Squid-cache Squid 3.0.stable13
Squid-cache Squid 2.6
Squid-cache Squid 3.0.stable9
Squid-cache Squid 2.0
Squid-cache Squid 3.0.stable20
Squid-cache Squid 3.0.stable14
Squid-cache Squid 3.0.stable3
Squid-cache Squid 3.1.0.7
Squid-cache Squid 3.1.0.14
Squid-cache Squid 3.0.stable4
Squid-cache Squid 3.1.0.12
Squid-cache Squid 2.2
Squid-cache Squid 3.1.0.3
Squid-cache Squid 3.1.0.1
Squid-cache Squid 3.0.stable16
Squid-cache Squid 2.3
Squid-cache Squid 3.0.stable18
Squid-cache Squid 3.0.stable1
Squid-cache Squid 3.1.0.9
Squid-cache Squid 3.1.0.15
Squid-cache Squid 3.0.stable6
Squid-cache Squid 3.1.0.13
NA
CVE-2009-2855
The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote malicious users to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function.
Squid-cache Squid 2.7
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
type confusion
IMAP
CVE-2024-36103
CVE-2024-28995
CVE-2024-37325
CVE-2024-30078
CVE-2024-30082
SQL injection
CVE-2024-30052
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »