VendorsSquid-cachesquid2.6
Vulnerabilities

Squid-cache .org Squid 2.6

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2016-4051
Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data.
Published 2016-04-25 · Modified
8.8EPSS 0.183
CVE-2023-50269
SQUID-2023:10 Denial of Service in HTTP Request parsing
Published 2023-12-14 · Modified
8.6EPSS 0.576
CVE-2021-31807
An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to achieve Denial of Service when delivering responses to HTTP Range requests. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent.
Published 2021-06-08 · Modified
6.5EPSS 0.160
CVE-2010-0639
The htcpHandleTstRequest function in htcp.c in Squid 2.x before 2.6.STABLE24 and 2.7 before 2.7.STABLE8, and htcp.cc in 3.0 before 3.0.STABLE24, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via crafted packets to the HTCP port.
Published 2010-02-15 · Modified
5.0EPSS 0.306
CVE-2012-5643
Multiple memory leaks in tools/cachemgr.cc in cachemgr.cgi in Squid 2.x and 3.x before 3.1.22, 3.2.x before 3.2.4, and 3.3.x before 3.3.0.2 allow remote attackers to cause a denial of service (memory consumption) via (1) invalid Content-Length headers, (2) long POST requests, or (3) crafted authentication credentials.
Published 2012-12-20 · Modified
5.0EPSS 0.230
CVE-2010-0308
lib/rfc1035.c in Squid 2.x, 3.0 through 3.0.STABLE22, and 3.1 through 3.1.0.15 allows remote attackers to cause a denial of service (assertion failure) via a crafted DNS packet that only contains a header.
Published 2010-02-03 · Modified
4.0EPSS 0.273