Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

463 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)46%💥 ExploitMemcached6/1/201717/6/2026
An integer overflow in process_bin_sasl_auth function in Memcached, which is responsible for authentication commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.
ModificadaCrítica (9.8)20%—Memcached6/1/201717/6/2026
Multiple integer overflows in process_bin_update function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.
ModificadaCrítica (9.8)23%—Memcached6/1/201717/6/2026
An integer overflow in the process_bin_append_prepend function in Memcached, which is responsible for processing multiple commands of Memcached binary protocol, can be abused to cause heap overflow and lead to remote code execution.
ModificadaAlta (7.8)0.38%—Zend-cacheDebian LinuxDoctrine-project Object Relational MapperDoctrine-project Doctrinemongodbbundle+67/6/201617/6/2026
Doctrine Annotations before 1.2.7, Cache before 1.3.2 and 1.4.x before 1.4.2, Common before 2.4.3 and 2.5.x before 2.5.1, ORM before 2.4.8 or 2.5.x before 2.5.1, MongoDB ODM before 1.0.2, and MongoDB ODM Bundle before 3.0.1 use world-writable permissions for cache directories, which allows local users to execute…
ModificadaAlta (7.5)23%—Squid-cache SquidOracle LinuxCanonical Ubuntu Linux10/5/201617/6/2026
Double free vulnerability in Esi.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via a crafted Edge Side Includes (ESI) response.
ModificadaAlta (7.5)18%—Squid-cache SquidCanonical Ubuntu LinuxOracle Linux10/5/201617/6/2026
client_side_request.cc in Squid 3.x before 3.5.18 and 4.x before 4.0.10 allows remote servers to cause a denial of service (crash) via crafted Edge Side Includes (ESI) responses.
ModificadaAlta (8.6)39%—Oracle LinuxSquid-cache SquidCanonical Ubuntu Linux10/5/201617/6/2026
mime_header.cc in Squid before 3.5.18 allows remote attackers to bypass intended same-origin restrictions and possibly conduct cache-poisoning attacks via a crafted HTTP Host header, aka a "header smuggling" issue.
ModificadaAlta (8.6)80%—Canonical Ubuntu LinuxSquid-cache SquidOracle Linux10/5/201617/6/2026
client_side.cc in Squid before 3.5.18 and 4.x before 4.0.10 does not properly ignore the Host header when absolute-URI is provided, which allows remote attackers to conduct cache-poisoning attacks via an HTTP request.
ModificadaAlta (8.1)78%—Canonical Ubuntu LinuxSquid-cache SquidOracle Linux25/4/201617/6/2026
Buffer overflow in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allows remote attackers to execute arbitrary code via crafted Edge Side Includes (ESI) responses.
ModificadaBaja (3.7)14%—Squid-cache SquidOracle LinuxCanonical Ubuntu Linux25/4/201617/6/2026
Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers to obtain sensitive stack layout information via crafted Edge Side Includes (ESI) responses, related to incorrect use of assert and compiler optimization.
ModificadaAlta (8.1)13%—Canonical Ubuntu LinuxSquid-cache Squid25/4/201617/6/2026
Multiple stack-based buffer overflows in Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote HTTP servers to cause a denial of service or execute arbitrary code via crafted Edge Side Includes (ESI) responses.
ModificadaAlta (8.8)18%—Canonical Ubuntu LinuxOracle LinuxSquid-cache Squid25/4/201617/6/2026
Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data.
ModificadaAlta (7.5)3.5%—Varnish Cache Project Varnish CacheDebian Linux25/4/201617/6/2026
Varnish 3.x before 3.0.7, when used in certain stacked installations, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a header line terminated by a \r (carriage return) character in conjunction with multiple Content-Length headers in an HTTP request.
ModificadaMedia (5.9)26%—Squid-cache Squid19/4/201617/6/2026
The FwdState::connectedToPeer method in FwdState.cc in Squid before 3.5.14 and 4.0.x before 4.0.6 does not properly handle SSL handshake errors when built with the --with-openssl option, which allows remote attackers to cause a denial of service (application crash) via a plaintext HTTP message.
ModificadaAlta (7.5)35%—Squid-cache Squid7/4/201617/6/2026
Squid 3.x before 3.5.16 and 4.x before 4.0.8 improperly perform bounds checking, which allows remote attackers to cause a denial of service via a crafted HTTP response, related to Vary headers.
ModificadaAlta (8.2)15%—Squid-cache SquidCanonical Ubuntu Linux7/4/201617/6/2026
Heap-based buffer overflow in the Icmp6::Recv function in icmp/Icmp6.cc in the pinger utility in Squid before 3.5.16 and 4.x before 4.0.8 allows remote servers to cause a denial of service (performance degradation or transition failures) or write sensitive information to log files via an ICMPv6 packet.
ModificadaAlta (7.5)10%—Squid-cache Squid27/2/201617/6/2026
http.cc in Squid 4.x before 4.0.7 relies on the HTTP status code after a response-parsing failure, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a malformed response.
ModificadaAlta (7.5)9.3%—Squid-cache Squid27/2/201617/6/2026
http.cc in Squid 3.x before 3.5.15 and 4.x before 4.0.7 proceeds with the storage of certain data after a response-parsing failure, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a malformed response.
ModificadaAlta (7.5)9.0%—Squid-cache Squid27/2/201617/6/2026
The Edge Side Includes (ESI) parser in Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not check buffer limits during XML parsing, which allows remote HTTP servers to cause a denial of service (assertion failure and daemon exit) via a crafted XML document, related to esi/CustomParser.cc and esi/CustomParser.h.
ModificadaAlta (7.5)31%💥 PoCSquid-cache Squid27/2/201617/6/2026
Squid 3.x before 3.5.15 and 4.x before 4.0.7 does not properly append data to String objects, which allows remote servers to cause a denial of service (assertion failure and daemon exit) via a long string, as demonstrated by a crafted HTTP Vary header.
ModificadaMedia (4)11%—Squid-cache SquidOpensuse6/11/201517/6/2026
Squid 3.4.4 through 3.4.11 and 3.5.0.1 through 3.5.1, when Digest authentication is used, allow remote authenticated users to retain access by leveraging a stale nonce, aka "Nonce replay vulnerability."
ModificadaMedia (6.8)21%—Fedoraproject FedoraDebian LinuxSquid-cache Squid28/9/201517/6/2026
Squid before 3.5.6 does not properly handle CONNECT method peer responses when configured with cache_peer, which allows remote attackers to bypass intended restrictions and gain access to a backend proxy via a CONNECT request.
ModificadaMedia (5)1.3%—Pearson Proctorcache23/6/201517/6/2026
Pearson ProctorCache before 2015.1.17 uses the same hardcoded password across different customers' installations, which allows remote attackers to modify test metadata or cause a denial of service (test disruption) by leveraging knowledge of this password.
ModificadaBaja (2.6)11%—Oracle LinuxOracle SolarisSquid-cache SquidFedoraproject Fedora18/5/201517/6/2026
Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate.
ModificadaMedia (4.3)4.5%—Squid-cache Squid20/2/201517/6/2026
CRLF injection vulnerability in Squid before 3.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted header in a response.
Orbitaley — Vulnerabilidades