Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
189 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 60% | — | Squid-cache Squid | 20/9/2010 | 16/6/2026 | The string-comparison functions in String.cci in Squid 3.x before 3.1.8 and 3.2.x before 3.2.0.2 allow remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request. | |
| Modificada | Media (5) | 31% | — | Squid-cache Squid | 15/2/2010 | 16/6/2026 | The htcpHandleTstRequest function in htcp.c in Squid 2.x before 2.6.STABLE24 and 2.7 before 2.7.STABLE8, and htcp.cc in 3.0 before 3.0.STABLE24, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via crafted packets to the HTCP port. | |
| Modificada | Media (4) | 28% | — | Squid-cache Squid | 3/2/2010 | 16/6/2026 | lib/rfc1035.c in Squid 2.x, 3.0 through 3.0.STABLE22, and 3.1 through 3.1.0.15 allows remote attackers to cause a denial of service (assertion failure) via a crafted DNS packet that only contains a header. | |
| Modificada | Media (5) | 3.8% | — | Squidguard | 28/10/2009 | 16/6/2026 | Multiple buffer overflows in squidGuard 1.4 allow remote attackers to bypass intended URL blocking via a long URL, related to (1) the relationship between a certain buffer size in squidGuard and a certain buffer size in Squid and (2) a redirect URL that contains information about the originally requested URL. | |
| Modificada | Media (5) | 3.8% | — | Squidguard | 28/10/2009 | 16/6/2026 | Buffer overflow in sgLog.c in squidGuard 1.3 and 1.4 allows remote attackers to cause a denial of service (application hang or loss of blocking functionality) via a long URL with many / (slash) characters, related to "emergency mode." | |
| Modificada | Media (5) | 34% | — | Squid-cache Squid | 18/8/2009 | 16/6/2026 | The strListGetItem function in src/HttpHeaderTools.c in Squid 2.7 allows remote attackers to cause a denial of service via a crafted auth header with certain comma delimiters that trigger an infinite loop of calls to the strcspn function. | |
| Modificada | Media (5) | 57% | — | Squid-cache Squid | 28/7/2009 | 16/6/2026 | Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 allows remote attackers to cause a denial of service via malformed requests including (1) "missing or mismatched protocol identifier," (2) missing or negative status value," (3) "missing version," or (4) "missing or invalid status number," related to (a)… | |
| Modificada | Media (5) | 23% | — | Squid-cache Squid | 28/7/2009 | 16/6/2026 | Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 does not properly enforce "buffer limits and related bound checks," which allows remote attackers to cause a denial of service via (1) an incomplete request or (2) a request with a large header size, related to (a) HttpMsg.cc and (b) client_side.cc. | |
| Modificada | Media (5.4) | 3.1% | — | Squid WEB Proxy Cache | 4/3/2009 | 16/6/2026 | Squid, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that… | |
| Modificada | Media (5) | 72% | 💥 Exploit | Squid | 8/2/2009 | 16/6/2026 | Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service via an HTTP request with an invalid version number, which triggers a reachable assertion in (1) HttpMsg.c and (2) HttpStatusLine.c. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Pagesquid CMS | 27/6/2008 | 16/6/2026 | SQL injection vulnerability in index.php in PageSquid CMS 0.3 Beta allows remote attackers to execute arbitrary SQL commands via the page parameter. | |
| Modificada | Alta (10) | 3.8% | — | Sarg Squid Analysis Report Generator | 13/5/2008 | 16/6/2026 | Multiple stack-based buffer overflows in Sarg might allow attackers to execute arbitrary code via unknown vectors, probably a crafted Squid log file. | |
| Modificada | Media (4.3) | 2.2% | — | Squid | 1/4/2008 | 16/6/2026 | The arrayShrink function (lib/Array.c) in Squid 2.6.STABLE17 allows attackers to cause a denial of service (process exit) via unknown vectors that cause an array to shrink to 0 entries, which triggers an assert error. NOTE: this issue is due to an incorrect fix for CVE-2007-6239. | |
| Modificada | Alta (10) | 6.7% | — | Sarg Squid Analysis Report Generator | 5/3/2008 | 16/6/2026 | Stack-based buffer overflow in the useragent function in useragent.c in Squid Analysis Report Generator (Sarg) 2.2.3.1 allows remote attackers to execute arbitrary code via a long Squid proxy server User-Agent header. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (4.3) | 1.6% | — | Sarg Squid Analysis Report Generator | 5/3/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Squid Analysis Report Generator (Sarg) 2.2.3.1 allows remote attackers to inject arbitrary web script or HTML via the User-Agent header, which is not properly handled when displaying the Squid proxy log. NOTE: the provenance of this information is unknown; the details are… | |
| Modificada | Media (5) | 27% | — | Squid WEB Proxy Cache | 4/12/2007 | 16/6/2026 | The "cache update reply processing" functionality in Squid 2.x before 2.6.STABLE17 and Squid 3.0 allows remote attackers to cause a denial of service (crash) via unknown vectors related to HTTP headers and an Array memory leak during requests for cached objects. | |
| Modificada | Alta (7.5) | 1.3% | — | Office Efficiencies Safesquid | 18/9/2007 | 16/6/2026 | Unspecified vulnerability in Office Efficiencies SafeSquid 4.1.x has unknown impact and attack vectors, related to a "serious security flaw," possibly specific to Linux. | |
| Modificada | Media (5) | 27% | — | Squid | 21/3/2007 | 16/6/2026 | The clientProcessRequest() function in src/client_side.c in Squid 2.6 before 2.6.STABLE12 allows remote attackers to cause a denial of service (daemon crash) via crafted TRACE requests that trigger an assertion error. | |
| Modificada | Media (5) | 20% | 💥 Exploit | Squid | 16/1/2007 | 16/6/2026 | squid/src/ftp.c in Squid before 2.6.STABLE7 allows remote FTP servers to cause a denial of service (core dump) via crafted FTP directory listing responses, possibly related to the (1) ftpListingFinish and (2) ftpHtmlifyListEntry functions. | |
| Modificada | Media (5) | 6.9% | — | Squid | 16/1/2007 | 16/6/2026 | The aclMatchExternal function in Squid before 2.6.STABLE7 allows remote attackers to cause a denial of service (crash) by causing an external_acl queue overload, which triggers an infinite loop. | |
| Modificada | Media (5) | 2.6% | — | SquidSuse Linux | 27/10/2005 | 16/6/2026 | Unspecified vulnerability in Squid on SUSE Linux 9.0 allows remote attackers to cause a denial of service (crash) via HTTPs (SSL). | |
| Modificada | Media (5) | 2.1% | — | Squid | 20/10/2005 | 16/6/2026 | The rfc1738_do_escape function in ftp.c for Squid 2.5 STABLE11 and earlier allows remote FTP servers to cause a denial of service (segmentation fault) via certain "odd" responses. | |
| Modificada | Media (5) | 3.4% | — | Squid | 30/9/2005 | 16/6/2026 | Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart). | |
| Modificada | Media (5) | 3.1% | — | Squid | 7/9/2005 | 16/6/2026 | store.c in Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (crash) via certain aborted requests that trigger an assert error related to STORE_PENDING. | |
| Modificada | Media (5) | 7.8% | — | Squid | 7/9/2005 | 16/6/2026 | The sslConnectTimeout function in ssl.c for Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (segmentation fault) via certain crafted requests. |