Search CVE reports


Toggle filters

121 – 130 of 147 results


CVE-2007-6239

Low priority
Fixed

The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial of service (crash) via unknown vectors related to HTTP headers and an Array memory leak...

2 affected packages

squid, squid3

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squid
squid3
Show less packages

CVE-2007-1560

Medium priority
Fixed

The clientProcessRequest() function in src/client_side.c in Squid 2.6 before 2.6.STABLE12 allows remote attackers to cause a denial of service (daemon crash) via crafted TRACE requests that trigger an assertion error.

1 affected package

squid

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squid
Show less packages

CVE-2007-0248

Medium priority
Fixed

The aclMatchExternal function in Squid before 2.6.STABLE7 allows remote attackers to cause a denial of service (crash) by causing an external_acl queue overload, which triggers an infinite loop.

1 affected package

squid

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squid
Show less packages

CVE-2007-0247

Medium priority

Some fixes available 2 of 3

squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory listing responses, possibly related to the (1) ftpListingFinish and (2) ftpHtmlifyListEntry functions.

1 affected package

squid

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squid
Show less packages

CVE-2005-3258

Medium priority
Not affected

The rfc1738_do_escape function in ftp.c for Squid 2.5 STABLE11 and earlier allows remote FTP servers to cause a denial of service (segmentation fault) via certain "odd" responses.

1 affected package

squid

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squid
Show less packages

CVE-2005-2917

Medium priority
Fixed

Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart).

1 affected package

squid

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squid
Show less packages

CVE-2005-2796

Medium priority
Not affected

The sslConnectTimeout function in ssl.c for Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (segmentation fault) via certain crafted requests.

1 affected package

squid

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squid
Show less packages

CVE-2005-2794

Medium priority
Not affected

store.c in Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (crash) via certain aborted requests that trigger an assert error related to STORE_PENDING.

1 affected package

squid

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squid
Show less packages

CVE-2005-1519

Medium priority
Not affected

Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attackers to spoof DNS lookups.

1 affected package

squid

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squid
Show less packages

CVE-2005-1345

Medium priority
Fixed

Squid 2.5.STABLE9 and earlier does not trigger a fatal error when it identifies missing or invalid ACLs in the http_access configuration, which could lead to less restrictive ACLs than intended by the administrator.

1 affected package

squid

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
squid
Show less packages