Vulnerabilities > Squid > Squid > 2.4.stable2

DATE CVE VULNERABILITY TITLE RISK
2005-10-20 CVE-2005-3258 Unspecified vulnerability in Squid
The rfc1738_do_escape function in ftp.c for Squid 2.5 STABLE11 and earlier allows remote FTP servers to cause a denial of service (segmentation fault) via certain "odd" responses.
network
low complexity
squid
5.0
2005-09-07 CVE-2005-2796 Remote Denial Of Service vulnerability in Squid Proxy SSLConnectTimeout
The sslConnectTimeout function in ssl.c for Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (segmentation fault) via certain crafted requests.
network
low complexity
squid
5.0
2005-09-07 CVE-2005-2794 Remote Denial Of Service vulnerability in Squid Proxy Aborted Requests
store.c in Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (crash) via certain aborted requests that trigger an assert error related to STORE_PENDING.
network
low complexity
squid
5.0
2005-05-02 CVE-2005-0446 Remote Denial Of Service vulnerability in Squid Proxy DNS Name Resolver
Squid 2.5.STABLE8 and earlier allows remote attackers to cause a denial of service (crash) via certain DNS responses regarding (1) Fully Qualified Domain Names (FQDN) in fqdncache.c or (2) IP addresses in ipcache.c, which trigger an assertion failure.
network
low complexity
squid
5.0
2005-05-02 CVE-2005-0194 Security Bypass vulnerability in Squid
Squid 2.5, when processing the configuration file, parses empty Access Control Lists (ACLs), including proxy_auth ACLs without defined auth schemes, in a way that effectively removes arguments, which could allow remote attackers to bypass intended ACLs if the administrator ignores the parser warnings.
network
low complexity
squid
critical
10.0
2005-05-02 CVE-2005-0173 Authentication Bypass vulnerability in Squid Proxy squid_ldap_auth
squid_ldap_auth in Squid 2.5 and earlier allows remote authenticated users to bypass username-based Access Control Lists (ACLs) via a username with a space at the beginning or end, which is ignored by the LDAP server.
network
low complexity
squid
7.5
2005-04-14 CVE-2005-0718 Remote Denial Of Service vulnerability in Squid Proxy Aborted Connection
Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (segmentation fault) by aborting the connection during a (1) PUT or (2) POST request, which causes Squid to access previously freed memory.
network
low complexity
squid
5.0
2005-01-27 CVE-2004-0918 Resource Management Errors vulnerability in multiple products
The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of service (server restart) via certain SNMP packets with negative length fields that trigger a memory allocation error.
network
low complexity
openpkg squid gentoo redhat trustix ubuntu CWE-399
5.0
2005-01-25 CVE-2005-0096 Remote Denial Of Service vulnerability in Squid Proxy NTLM Fakeauth_Auth Memory Leak
Memory leak in the NTLM fakeauth_auth helper for Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (memory consumption).
network
low complexity
squid
5.0
2005-01-15 CVE-2005-0095 Denial Of Service vulnerability in Squid Proxy Web Cache Communication Protocol
The WCCP message parsing code in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via malformed WCCP messages with source addresses that are spoofed to reference Squid's home router and invalid WCCP_I_SEE_YOU cache numbers.
network
low complexity
squid
5.0