Squid
32 CVEs tracked since 2002. Since Jun 2002, none of them reached CISA KEV.
Squid CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2002-06 | 1 | 0 |
| 2002-07 | 2 | 0 |
| 2002-08 | null or fewer | |
| 2002-09 | null or fewer | |
| 2002-10 | null or fewer | |
| 2002-11 | null or fewer | |
| 2002-12 | null or fewer | |
| 2003-01 | null or fewer | |
| 2003-02 | null or fewer | |
| 2003-03 | null or fewer | |
| 2003-04 | 5 | 0 |
| 2003-05 | null or fewer | |
| 2003-06 | null or fewer | |
| 2003-07 | null or fewer | |
| 2003-08 | null or fewer | |
| 2003-09 | null or fewer | |
| 2003-10 | null or fewer | |
| 2003-11 | null or fewer | |
| 2003-12 | null or fewer | |
| 2004-01 | null or fewer | |
| 2004-02 | null or fewer | |
| 2004-03 | null or fewer | |
| 2004-04 | null or fewer | |
| 2004-05 | null or fewer | |
| 2004-06 | null or fewer | |
| 2004-07 | null or fewer | |
| 2004-08 | null or fewer | |
| 2004-09 | 2 | 0 |
| 2004-10 | 1 | 0 |
| 2004-11 | null or fewer | |
| 2004-12 | null or fewer | |
| 2005-01 | 4 | 0 |
| 2005-02 | 6 | 0 |
| 2005-03 | 2 | 0 |
| 2005-04 | null or fewer | |
| 2005-05 | 2 | 0 |
| 2005-06 | null or fewer | |
| 2005-07 | null or fewer | |
| 2005-08 | null or fewer | |
| 2005-09 | 3 | 0 |
| 2005-10 | 2 | 0 |
| 2005-11 | null or fewer | |
| 2005-12 | null or fewer | |
| 2006-01 | null or fewer | |
| 2006-02 | null or fewer | |
| 2006-03 | null or fewer | |
| 2006-04 | null or fewer | |
| 2006-05 | null or fewer | |
| 2006-06 | null or fewer | |
| 2006-07 | null or fewer | |
| 2006-08 | null or fewer | |
| 2006-09 | null or fewer | |
| 2006-10 | null or fewer | |
| 2006-11 | null or fewer | |
| 2006-12 | null or fewer | |
| 2007-01 | 2 | 0 |
Products
The products that kept showing up in Squid's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Squid.
- CVE-2009-0801Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverligh...5.4
- CVE-2009-0478Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request with an invalid version number, which triggers a reachable...5.0
- CVE-2008-1612The arrayShrink function (lib/Array.c) in Squid 2.6.STABLE17 allows attackers to cause a denial of service (process exit) via unknown vectors that cause an array to shrink to 0 entries, which trigg...4.3
- CVE-2007-6239The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial of service (crash) via unknown vectors related to HTTP hea...5.0
- CVE-2002-2414Opera 6.0.3, when using Squid 2.4 for HTTPS proxying, does not properly handle when accepting a non-global certificate authority (CA) certificate from a site and establishing a subsequent HTTPS con...4.3
- CVE-2007-1560The clientProcessRequest() function in src/client_side.c in Squid 2.6 before 2.6.STABLE12 allows remote attackers to cause a denial of service (daemon crash) via crafted TRACE requests that trigger...5.0
- CVE-2007-0247squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory listing responses, possibly related to the (1) ftpListingFin...5.0
- CVE-2007-0248The aclMatchExternal function in Squid before 2.6.STABLE7 allows remote attackers to cause a denial of service (crash) by causing an external_acl queue overload, which triggers an infinite loop.5.0
- CVE-2004-2654The clientAbortBody function in client_side.c in Squid Web Proxy Cache before 2.6 STABLE6 allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors that trig...5.0
- CVE-2005-3322Unspecified vulnerability in Squid on SUSE Linux 9.0 allows remote attackers to cause a denial of service (crash) via HTTPs (SSL).5.0
- CVE-2005-3258The rfc1738_do_escape function in ftp.c for Squid 2.5 STABLE11 and earlier allows remote FTP servers to cause a denial of service (segmentation fault) via certain "odd" responses.5.0
- CVE-2005-2917Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart).5.0
- CVE-2005-2796The sslConnectTimeout function in ssl.c for Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (segmentation fault) via certain crafted requests.5.0
- CVE-2005-2794store.c in Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (crash) via certain aborted requests that trigger an assert error related to STORE_PENDING.5.0
- CVE-2005-1711Gibraltar Firewall 2.2 and earlier, when using the ClamAV update to 0.81 for Squid, uses a defunct ClamAV method to scan memory for viruses, which does not return an error code and prevents viruses...7.5
The record
- Peak rank
- #19 in Jan 2005
- Busiest month shown
- Feb 2005, 6 CVEs
- Months with a KEV entry
- 0 since Jun 2002
- Monthly snapshots
- 12 since 2002