Squid-Cache / Squid
111 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-46784 | squid: DoS when processing gopher server responses | HIGH | 7.5 | Jul 17, 2022 |
| CVE-2021-41611 | squid: improper certificate validation | HIGH | 8.1 | Oct 18, 2021 |
| CVE-2021-31807 | squid: incorrect memory management in HTTP Range header | MEDIUM | 6.5 | Jun 8, 2021 |
| CVE-2021-33620 | squid: denial of service in HTTP response processing | MEDIUM | 6.5 | May 28, 2021 |
| CVE-2021-31808 | squid: integer overflow in HTTP Range header | MEDIUM | 6.5 | May 27, 2021 |
| CVE-2021-31806 | squid: improper input validation in HTTP Range header | MEDIUM | 6.5 | May 27, 2021 |
| CVE-2021-28662 | squid: denial of service in HTTP response processing | MEDIUM | 6.5 | May 27, 2021 |
| CVE-2021-28652 | squid: denial of service issue in Cache Manager | MEDIUM | 6.8 | May 27, 2021 |
| CVE-2021-28651 | squid: denial of service in URN processing | HIGH | 7.5 | May 27, 2021 |
| CVE-2020-25097 | squid: improper input validation may allow a trusted client to perform HTTP request smuggling | HIGH | 8.6 | Mar 19, 2021 |
| CVE-2021-28116 | squid: out-of-bounds read in WCCP protocol data may lead to information disclosure | MEDIUM | 5.3 | Mar 9, 2021 |
| CVE-2020-15811 | squid: HTTP Request Splitting could result in cache poisoning | CRITICAL | 9.6 | Sep 2, 2020 |
| CVE-2020-15810 | squid: HTTP Request Smuggling could result in cache poisoning | CRITICAL | 9.6 | Sep 2, 2020 |
| CVE-2020-24606 | squid: Improper input validation could result in a DoS | HIGH | 8.6 | Aug 24, 2020 |
| CVE-2020-14058 | squid: DoS in TLS handshake | HIGH | 7.7 | Jun 30, 2020 |
| CVE-2020-14059 | squid: DoS when processing objects in an SMP cache due to an incorrect synchronization | MEDIUM | 6.5 | Jun 30, 2020 |
| CVE-2020-15049 | squid: Request smuggling and poisoning attack against the HTTP cache | CRITICAL | 9.9 | Jun 30, 2020 |
| CVE-2020-11945 | squid: improper access restriction upon Digest Authentication nonce replay could lead to remote code execution | CRITICAL | 9.8 | Apr 23, 2020 |
| CVE-2019-12519 | squid: improper check for new member in ESIExpression::Evaluate allows for stack buffer overflow | CRITICAL | 9.8 | Apr 15, 2020 |
| CVE-2019-12520 | squid: Improper input validation in request allows for proxy manipulation | HIGH | 7.5 | Apr 15, 2020 |
| CVE-2019-12522 | squid: lack of UID assignment in child process spawning could lead to privileges escalation | MEDIUM | 4.5 | Apr 15, 2020 |
| CVE-2019-12521 | squid: Off-by-one error in addStackElement allows for heap buffer overflow and crash | MEDIUM | 5.9 | Apr 15, 2020 |
| CVE-2019-12524 | squid: Improper access restriction in url_regex may lead to security bypass | CRITICAL | 9.8 | Apr 15, 2020 |
| CVE-2019-18860 | squid: Mishandled HTML in the host parameter to cachemgr.cgi results in insecure behaviour | MEDIUM | 6.1 | Mar 20, 2020 |
| CVE-2019-12528 | squid: Information Disclosure issue in FTP Gateway | HIGH | 7.5 | Feb 4, 2020 |
Showing 26 to 50 of 111 CVEs