Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

189 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4)5.8%—Phpsquidpass31/12/200216/6/2026
phpSquidPass before 0.2 uses an incomplete regular expression to find a matching username in its database, which allows remote authenticated attackers to effectively delete other usernames via a short username that matches the end of the targeted username.
ModificadaAlta (7.5)2.9%—C-note Squid Auth LdapPadl Software NSS LdapPadl Software PAM Ldap12/8/200216/6/2026
Format string vulnerability in the logging() function in C-Note Squid LDAP authentication module (squid_auth_LDAP) 2.0.2 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code by triggering log messages.
ModificadaAlta (7.5)2.7%—Squid26/7/200216/6/2026
FTP proxy in Squid before 2.4.STABLE6 does not compare the IP addresses of control and data connections with the FTP server, which allows remote attackers to bypass firewall rules or spoof FTP server responses.
ModificadaAlta (7.5)5.5%—Squid26/7/200216/6/2026
Buffer overflows in Squid before 2.4.STABLE6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code (1) via the MSNT auth helper (msnt_auth) when using denyusers or allowusers files, (2) via the gopher client, or (3) via the FTP server directory listing parser when HTML output…
ModificadaMedia (5)2.3%—Squid26/7/200216/6/2026
Vulnerability in Squid before 2.4.STABLE6 related to proxy authentication credentials may allow remote web sites to obtain the user's proxy login and password.
ModificadaAlta (7.5)15%💥 ExploitSquid26/3/200216/6/2026
Heap-based buffer overflow in Squid before 2.4 STABLE4, and Squid 2.5 and 2.6 until March 12, 2002 distributions, allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via compressed DNS responses.
ModificadaAlta (7.5)3.7%—SquidRedhat Linux8/3/200216/6/2026
Squid 2.4 STABLE3 and earlier does not properly disable HTCP, even when "htcp_port 0" is specified in squid.conf, which could allow remote attackers to bypass intended access restrictions.
ModificadaBaja (2.6)2.8%—SquidRedhat Linux8/3/200216/6/2026
Memory leak in SNMP in Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service.
ModificadaAlta (7.5)9.4%💥 ExploitSquidRedhat Linux8/3/200216/6/2026
Squid 2.4 STABLE3 and earlier allows remote attackers to cause a denial of service (core dump) and possibly execute arbitrary code with an ftp:// URL with a larger number of special characters, which exceed the buffer when Squid URL-escapes the characters.
ModificadaMedia (5)2.8%—Squid WEB Proxy6/12/200116/6/2026
Squid proxy server 2.4 and earlier allows remote attackers to cause a denial of service (crash) via a mkdir-only FTP PUT request.
ModificadaAlta (7.5)2.0%—Caldera Openlinux ServerImmunixMandrakesoft Mandrake Single Network FirewallSquid WEB Proxy+418/7/200116/6/2026
Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpd_accel_host and http_accel_with_proxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning.
ModificadaBaja (1.2)0.30%—ImmunixNational Science Foundation Squid WEB ProxyMandrakesoft Mandrake LinuxRedhat Linux+112/3/200116/6/2026
squid 2.3 and earlier allows local users to overwrite arbitrary files via a symlink attack in some configurations.
ModificadaMedia (5)3.6%💥 ExploitNational Science Foundation Squid WEB Proxy31/12/199916/6/2026
Squid 2.2.STABLE5 and below, when using external authentication, allows attackers to bypass access controls via a newline in the user/password pair.
ModificadaAlta (7.5)1.3%—National Science Foundation Squid WEB Proxy20/2/199816/6/2026
Squid Internet Object Cache 1.1.20 allows users to bypass access control lists (ACLs) by encoding the URL with hexadecimal escape sequences.
Orbitaley — Vulnerabilidades