Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
463 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 37% | — | Squid-cache Squid | 17/11/2011 | 16/6/2026 | The idnsGrokReply function in Squid before 3.1.16 does not properly free memory, which allows remote attackers to cause a denial of service (daemon abort) via a DNS reply containing a CNAME record that references another CNAME record that contains an empty A record. | |
| Modificada | Media (6.8) | 27% | — | Squid-cache Squid | 6/9/2011 | 16/6/2026 | Buffer overflow in the gopherToHTML function in gopher.cc in the Gopher reply parser in Squid 3.0 before 3.0.STABLE26, 3.1 before 3.1.15, and 3.2 before 3.2.0.11 allows remote Gopher servers to cause a denial of service (memory corruption and daemon restart) or possibly have unspecified other impact via a long line in… | |
| Modificada | Media (5) | 31% | — | Squid-cache Squid | 12/10/2010 | 16/6/2026 | dns_internal.cc in Squid 3.1.6, when IPv6 DNS resolution is not enabled, accesses an invalid socket during an IPv4 TCP DNS query, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via vectors that trigger an IPv4 DNS response with the TC bit set. | |
| Modificada | Media (4.3) | 1.9% | — | Pecl-php Alternative PHP Cache | 24/9/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in apc.php in the Alternative PHP Cache (APC) extension before 3.1.4 for PHP allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 60% | — | Squid-cache Squid | 20/9/2010 | 16/6/2026 | The string-comparison functions in String.cci in Squid 3.x before 3.1.8 and 3.2.x before 3.2.0.2 allow remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request. | |
| Modificada | Media (5) | 10% | 💥 Exploit | Memcachedb Memcached | 12/4/2010 | 16/6/2026 | memcached.c in memcached before 1.4.3 allows remote attackers to cause a denial of service (daemon hang or crash) via a long line that triggers excessive memory allocation. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 31% | — | Squid-cache Squid | 15/2/2010 | 16/6/2026 | The htcpHandleTstRequest function in htcp.c in Squid 2.x before 2.6.STABLE24 and 2.7 before 2.7.STABLE8, and htcp.cc in 3.0 before 3.0.STABLE24, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via crafted packets to the HTCP port. | |
| Modificada | Media (4) | 28% | — | Squid-cache Squid | 3/2/2010 | 16/6/2026 | lib/rfc1035.c in Squid 2.x, 3.0 through 3.0.STABLE22, and 3.1 through 3.1.0.15 allows remote attackers to cause a denial of service (assertion failure) via a crafted DNS packet that only contains a header. | |
| Modificada | Baja (3.3) | 0.57% | 💥 Exploit | Saini Videocache | 29/12/2009 | 16/6/2026 | vccleaner in VideoCache 1.9.2 allows local users with Squid proxy user privileges to overwrite arbitrary files via a symlink attack on /var/log/videocache/vccleaner.log. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Joomlacache COM Cbresumebuilder | 9/10/2009 | 16/6/2026 | SQL injection vulnerability in the JoomlaCache CB Resume Builder (com_cbresumebuilder) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the group_id parameter in a group_members action to index.php. | |
| Modificada | Media (6.8) | 1.5% | — | Drewish Imagecache | 16/9/2009 | 16/6/2026 | The ImageCache module 5.x before 5.x-2.5 and 6.x before 6.x-2.0-beta10, a module for Drupal, when the private file system is used, does not properly perform access control for derivative images, which allows remote attackers to view arbitrary images via a request that specifies an image's filename. | |
| Modificada | Baja (3.5) | 0.83% | — | Drewish Imagecache | 16/9/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the ImageCache module 5.x before 5.x-2.5 and 6.x before 6.x-2.0-beta10, a module for Drupal, allow remote authenticated users, with "administer imagecache" permissions, to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 34% | — | Squid-cache Squid | 18/8/2009 | 16/6/2026 | The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function. | |
| Modificada | Alta (10) | 6.6% | — | Memcachedb Memcached | 10/8/2009 | 16/6/2026 | Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers to execute arbitrary code via vectors involving length attributes that trigger heap-based buffer overflows. | |
| Modificada | Media (5) | 57% | — | Squid-cache Squid | 28/7/2009 | 16/6/2026 | Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 allows remote attackers to cause a denial of service via malformed requests including (1) "missing or mismatched protocol identifier," (2) missing or negative status value," (3) "missing version," or (4) "missing or invalid status number," related to (a)… | |
| Modificada | Media (5) | 23% | — | Squid-cache Squid | 28/7/2009 | 16/6/2026 | Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 does not properly enforce "buffer limits and related bound checks," which allows remote attackers to cause a denial of service via (1) an incomplete request or (2) a request with a large header size, related to (a) HttpMsg.cc and (b) client_side.cc. | |
| Modificada | Media (5) | 1.5% | — | Memcachedb Memcached | 30/4/2009 | 16/6/2026 | The process_stat function in Memcached 1.2.8 discloses memory-allocation statistics in response to a stats malloc command, which allows remote attackers to obtain potentially sensitive information by sending this command to the daemon's TCP port. | |
| Modificada | Media (5) | 2.3% | — | Memcachedb Memcached | 30/4/2009 | 16/6/2026 | The process_stat function in (1) Memcached before 1.2.8 and (2) MemcacheDB 1.2.0 discloses (a) the contents of /proc/self/maps in response to a stats maps command and (b) memory-allocation statistics in response to a stats malloc command, which allows remote attackers to obtain sensitive information such as the… | |
| Modificada | Media (5.4) | 3.1% | — | Squid WEB Proxy Cache | 4/3/2009 | 16/6/2026 | Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that… | |
| Modificada | Media (6.8) | 7.8% | 💥 Exploit | Pecl-php Alternative PHP Cache | 24/3/2008 | 16/6/2026 | Stack-based buffer overflow in apc.c in Alternative PHP Cache (APC) 3.0.11 through 3.0.16 allows remote attackers to execute arbitrary code via a long filename. | |
| Modificada | Media (5) | 27% | — | Squid WEB Proxy Cache | 4/12/2007 | 16/6/2026 | The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial of service (crash) via unknown vectors related to HTTP headers and an Array memory leak during requests for cached objects. | |
| Modificada | Baja (3.5) | 0.86% | — | Intersystems Cache Database | 20/8/2007 | 16/6/2026 | Unspecified vulnerability in the login page redirection logic in the Cache' Server Page (CSP) implementation in InterSystems Cache' 2007.1.0.369.0 and 2007.1.1.420.0 allows remote authenticated users to modify data on a server, related to encoding of certain parameter values by this redirection logic, aka MAK2116. | |
| Modificada | Baja (3.5) | 0.83% | — | Intersystems Cache Database | 20/8/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the sample Cache' Server Page (CSP) scripts in InterSystems Cache' allow remote attackers to inject arbitrary web script or HTML via (1) the TO parameter to loop.csp, (2) the VALUE parameter to cookie.csp, and (3) the PAGE parameter to showsource.csp in… | |
| Modificada | Alta (7.5) | 2.1% | — | Debian Apt-cacher | 5/8/2005 | 16/6/2026 | Unknown vulnerability in apt-cacher in Debian 3.1, related to "missing input sanitising," allows remote attackers to execute arbitrary commands on the caching server. | |
| Modificada | Media (5) | 7.0% | 💥 Exploit | Oracle Application Server WEB Cache | 3/5/2005 | 16/6/2026 | The webcacheadmin module in Oracle Webcache 9i allows remote attackers to corrupt arbitrary files via a full pathname in the cache_dump_file parameter. |