Vulnerabilities > Squid Cache > Squid

DATE CVE VULNERABILITY TITLE RISK
2010-02-03 CVE-2010-0308 Improper Input Validation vulnerability in Squid-Cache Squid
lib/rfc1035.c in Squid 2.x, 3.0 through 3.0.STABLE22, and 3.1 through 3.1.0.15 allows remote attackers to cause a denial of service (assertion failure) via a crafted DNS packet that only contains a header.
network
low complexity
squid-cache CWE-20
4.0
2009-07-28 CVE-2009-2622 Improper Input Validation vulnerability in Squid-Cache Squid
Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 allows remote attackers to cause a denial of service via malformed requests including (1) "missing or mismatched protocol identifier," (2) missing or negative status value," (3) "missing version," or (4) "missing or invalid status number," related to (a) HttpMsg.cc and (b) HttpReply.cc.
network
low complexity
squid-cache CWE-20
5.0
2009-07-28 CVE-2009-2621 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Squid-Cache Squid
Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 does not properly enforce "buffer limits and related bound checks," which allows remote attackers to cause a denial of service via (1) an incomplete request or (2) a request with a large header size, related to (a) HttpMsg.cc and (b) client_side.cc.
network
low complexity
squid-cache CWE-119
5.0
2005-05-02 CVE-2005-0211 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Buffer overflow in wccp.c in Squid 2.5 before 2.5.STABLE7 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long WCCP packet, which is processed by a recvfrom function call that uses an incorrect length parameter.
network
low complexity
squid-cache debian CWE-119
7.5