CVE Tools

Squid

32 CVEs tracked since 2002. Since Jun 2002, none of them reached CISA KEV.

Squid CVEs per month

Jun 2002 to Jan 2007. Point at a month, or focus the strip and use the arrow keys.
Squid CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2002-0610
2002-0720
2002-08null or fewer
2002-09null or fewer
2002-10null or fewer
2002-11null or fewer
2002-12null or fewer
2003-01null or fewer
2003-02null or fewer
2003-03null or fewer
2003-0450
2003-05null or fewer
2003-06null or fewer
2003-07null or fewer
2003-08null or fewer
2003-09null or fewer
2003-10null or fewer
2003-11null or fewer
2003-12null or fewer
2004-01null or fewer
2004-02null or fewer
2004-03null or fewer
2004-04null or fewer
2004-05null or fewer
2004-06null or fewer
2004-07null or fewer
2004-08null or fewer
2004-0920
2004-1010
2004-11null or fewer
2004-12null or fewer
2005-0140
2005-0260
2005-0320
2005-04null or fewer
2005-0520
2005-06null or fewer
2005-07null or fewer
2005-08null or fewer
2005-0930
2005-1020
2005-11null or fewer
2005-12null or fewer
2006-01null or fewer
2006-02null or fewer
2006-03null or fewer
2006-04null or fewer
2006-05null or fewer
2006-06null or fewer
2006-07null or fewer
2006-08null or fewer
2006-09null or fewer
2006-10null or fewer
2006-11null or fewer
2006-12null or fewer
2007-0120

Products

The products that kept showing up in Squid's monthly top three, with their CVEs summed over those months.

  1. Squid3111 months
  2. Squid Web Proxy11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Squid.

  1. CVE-2009-0801Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverligh...5.4
  2. CVE-2009-0478Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request with an invalid version number, which triggers a reachable...5.0
  3. CVE-2008-1612The arrayShrink function (lib/Array.c) in Squid 2.6.STABLE17 allows attackers to cause a denial of service (process exit) via unknown vectors that cause an array to shrink to 0 entries, which trigg...4.3
  4. CVE-2007-6239The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial of service (crash) via unknown vectors related to HTTP hea...5.0
  5. CVE-2002-2414Opera 6.0.3, when using Squid 2.4 for HTTPS proxying, does not properly handle when accepting a non-global certificate authority (CA) certificate from a site and establishing a subsequent HTTPS con...4.3
  6. CVE-2007-1560The clientProcessRequest() function in src/client_side.c in Squid 2.6 before 2.6.STABLE12 allows remote attackers to cause a denial of service (daemon crash) via crafted TRACE requests that trigger...5.0
  7. CVE-2007-0247squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory listing responses, possibly related to the (1) ftpListingFin...5.0
  8. CVE-2007-0248The aclMatchExternal function in Squid before 2.6.STABLE7 allows remote attackers to cause a denial of service (crash) by causing an external_acl queue overload, which triggers an infinite loop.5.0
  9. CVE-2004-2654The clientAbortBody function in client_side.c in Squid Web Proxy Cache before 2.6 STABLE6 allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors that trig...5.0
  10. CVE-2005-3322Unspecified vulnerability in Squid on SUSE Linux 9.0 allows remote attackers to cause a denial of service (crash) via HTTPs (SSL).5.0
  11. CVE-2005-3258The rfc1738_do_escape function in ftp.c for Squid 2.5 STABLE11 and earlier allows remote FTP servers to cause a denial of service (segmentation fault) via certain "odd" responses.5.0
  12. CVE-2005-2917Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart).5.0
  13. CVE-2005-2796The sslConnectTimeout function in ssl.c for Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (segmentation fault) via certain crafted requests.5.0
  14. CVE-2005-2794store.c in Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (crash) via certain aborted requests that trigger an assert error related to STORE_PENDING.5.0
  15. CVE-2005-1711Gibraltar Firewall 2.2 and earlier, when using the ClamAV update to 0.81 for Squid, uses a defunct ClamAV method to scan memory for viruses, which does not return an error code and prevents viruses...7.5

The record

Peak rank
#19 in Jan 2005
Busiest month shown
Feb 2005, 6 CVEs
Months with a KEV entry
0 since Jun 2002
Monthly snapshots
12 since 2002
Squid's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store