Debian Squid vulnerabilities
120 known vulnerabilities affecting debian/squid.
Total CVEs
120
CISA KEV
0
Public exploits
9
Exploited in wild
0
Severity breakdown
CRITICAL14HIGH39MEDIUM50LOW17
Vulnerabilities
Page 6 of 6
CVE-2015-0881P4LOWCVSS 4.3fixed in squid 4.1-1 (bookworm)2015
CVE-2015-0881 [MEDIUM] CVE-2015-0881: squid - CRLF injection vulnerability in Squid before 3.1.1 allows remote attackers to in...
CRLF injection vulnerability in Squid before 3.1.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted header in a response.
Scope: local
bookworm: resolved (fixed in 4.1-1)
bullseye: resolved (fixed in 4.1-1)
forky: resolved (fixed in 4.1-1)
sid: resolved (fixed in 4.1-1)
trixie: resolved (fixed in 4.1-1)
debian
CVE-2005-0718P4MEDIUMCVSS 5.0fixed in squid 2.5.8 (bookworm)2005
CVE-2005-0718 [MEDIUM] CVE-2005-0718: squid - Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of servi...
Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (segmentation fault) by aborting the connection during a (1) PUT or (2) POST request, which causes Squid to access previously freed memory.
Scope: local
bookworm: resolved (fixed in 2.5.8)
bullseye: resolved (fixed in 2.5.8)
forky: resolved (fixed in 2.5.8)
sid: resolved (fixed in 2.5.8
debian
CVE-2018-19131P4LOWCVSS 6.1fixed in squid 4.4-1 (bookworm)2018
CVE-2018-19131 [MEDIUM] CVE-2018-19131: squid - Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) error pa...
Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) error page generation for certificate errors.
Scope: local
bookworm: resolved (fixed in 4.4-1)
bullseye: resolved (fixed in 4.4-1)
forky: resolved (fixed in 4.4-1)
sid: resolved (fixed in 4.4-1)
trixie: resolved (fixed in 4.4-1)
debian
CVE-2005-1519P4MEDIUMCVSS 6.4fixed in squid 2.5.9-9 (bookworm)2005
CVE-2005-1519 [MEDIUM] CVE-2005-1519: squid - Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the en...
Squid 2.5 STABLE9 and earlier, when the DNS client port is unfiltered and the environment does not prevent IP spoofing, allows remote attackers to spoof DNS lookups.
Scope: local
bookworm: resolved (fixed in 2.5.9-9)
bullseye: resolved (fixed in 2.5.9-9)
forky: resolved (fixed in 2.5.9-9)
sid: resolved (fixed in 2.5.9-9)
trixie: resolved (fixed in 2.5.9-9)
debian
CVE-2004-0918P4MEDIUMCVSS 5.0fixed in squid 2.5.7 (bookworm)2004
CVE-2004-0918 [MEDIUM] CVE-2004-0918: squid - The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Ca...
The asn_parse_header function (asn1.c) in the SNMP module for Squid Web Proxy Cache before 2.4.STABLE7 allows remote attackers to cause a denial of service (server restart) via certain SNMP packets with negative length fields that trigger a memory allocation error.
Scope: local
bookworm: resolved (fixed in 2.5.7)
bullseye: resolved (fixed in 2.5.7)
forky: resolved (fi
debian
CVE-2005-0094P4MEDIUMCVSS 5.0fixed in squid 2.5.7-4 (bookworm)2005
CVE-2005-0094 [MEDIUM] CVE-2005-0094: squid - Buffer overflow in the gopherToHTML function in the Gopher reply parser for Squi...
Buffer overflow in the gopherToHTML function in the Gopher reply parser for Squid 2.5.STABLE7 and earlier allows remote malicious Gopher servers to cause a denial of service (crash) via crafted responses.
Scope: local
bookworm: resolved (fixed in 2.5.7-4)
bullseye: resolved (fixed in 2.5.7-4)
forky: resolved (fixed in 2.5.7-4)
sid: resolved (fixed in 2.5.7-4)
trixie:
debian
CVE-2005-2796P4MEDIUMCVSS 5.0fixed in squid 2.5.10-5 (bookworm)2005
CVE-2005-2796 [MEDIUM] CVE-2005-2796: squid - The sslConnectTimeout function in ssl.c for Squid 2.5.STABLE10 and earlier allow...
The sslConnectTimeout function in ssl.c for Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (segmentation fault) via certain crafted requests.
Scope: local
bookworm: resolved (fixed in 2.5.10-5)
bullseye: resolved (fixed in 2.5.10-5)
forky: resolved (fixed in 2.5.10-5)
sid: resolved (fixed in 2.5.10-5)
trixie: resolved (fixed in 2.5
debian
CVE-2005-0096P4MEDIUMCVSS 5.0fixed in squid 2.5.7-4 (bookworm)2005
CVE-2005-0096 [MEDIUM] CVE-2005-0096: squid - Memory leak in the NTLM fakeauth_auth helper for Squid 2.5.STABLE7 and earlier a...
Memory leak in the NTLM fakeauth_auth helper for Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (memory consumption).
Scope: local
bookworm: resolved (fixed in 2.5.7-4)
bullseye: resolved (fixed in 2.5.7-4)
forky: resolved (fixed in 2.5.7-4)
sid: resolved (fixed in 2.5.7-4)
trixie: resolved (fixed in 2.5.7-4)
debian
CVE-2007-0248P4LOWCVSS 5.0fixed in squid 2.6.5-4 (bookworm)2007
CVE-2007-0248 [MEDIUM] CVE-2007-0248: squid - The aclMatchExternal function in Squid before 2.6.STABLE7 allows remote attacker...
The aclMatchExternal function in Squid before 2.6.STABLE7 allows remote attackers to cause a denial of service (crash) by causing an external_acl queue overload, which triggers an infinite loop.
Scope: local
bookworm: resolved (fixed in 2.6.5-4)
bullseye: resolved (fixed in 2.6.5-4)
forky: resolved (fixed in 2.6.5-4)
sid: resolved (fixed in 2.6.5-4)
trixie: resolved (
debian
CVE-2005-0097P4MEDIUMCVSS 5.0fixed in squid 2.5.7-4 (bookworm)2005
CVE-2005-0097 [MEDIUM] CVE-2005-0097: squid - The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to c...
The NTLM component in Squid 2.5.STABLE7 and earlier allows remote attackers to cause a denial of service (crash) via a malformed NTLM type 3 message that triggers a NULL dereference.
Scope: local
bookworm: resolved (fixed in 2.5.7-4)
bullseye: resolved (fixed in 2.5.7-4)
forky: resolved (fixed in 2.5.7-4)
sid: resolved (fixed in 2.5.7-4)
trixie: resolved (fixed in 2.5
debian
CVE-2005-2917P4MEDIUMCVSS 5.0fixed in squid 2.5.10-7 (bookworm)2005
CVE-2005-2917 [MEDIUM] CVE-2005-2917: squid - Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not p...
Squid 2.5.STABLE10 and earlier, while performing NTLM authentication, does not properly handle certain request sequences, which allows attackers to cause a denial of service (daemon restart).
Scope: local
bookworm: resolved (fixed in 2.5.10-7)
bullseye: resolved (fixed in 2.5.10-7)
forky: resolved (fixed in 2.5.10-7)
sid: resolved (fixed in 2.5.10-7)
trixie: resolved
debian
CVE-2004-0832P4MEDIUMCVSS 5.0fixed in squid 2.5.6-8 (bookworm)2004
CVE-2004-0832 [MEDIUM] CVE-2004-0832: squid - The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and e...
The (1) ntlm_fetch_string and (2) ntlm_get_string functions in Squid 2.5.6 and earlier, with NTLM authentication enabled, allow remote attackers to cause a denial of service (application crash) via an NTLMSSP packet that causes a negative value to be passed to memcpy.
Scope: local
bookworm: resolved (fixed in 2.5.6-8)
bullseye: resolved (fixed in 2.5.6-8)
forky: resol
debian
CVE-2002-0715P4MEDIUMCVSS 5.0fixed in squid 2.4.6-2 (bookworm)2002
CVE-2002-0715 [MEDIUM] CVE-2002-0715: squid - Vulnerability in Squid before 2.4.STABLE6 related to proxy authentication creden...
Vulnerability in Squid before 2.4.STABLE6 related to proxy authentication credentials may allow remote web sites to obtain the user's proxy login and password.
Scope: local
bookworm: resolved (fixed in 2.4.6-2)
bullseye: resolved (fixed in 2.4.6-2)
forky: resolved (fixed in 2.4.6-2)
sid: resolved (fixed in 2.4.6-2)
trixie: resolved (fixed in 2.4.6-2)
debian
CVE-2015-3455P4LOWCVSS 2.6fixed in squid 4.1-1 (bookworm)2015
CVE-2015-3455 [LOW] CVE-2015-3455: squid - Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x b...
Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate.
Scope: local
bookworm: resolved (fixed in 4.1-1)
bullseye: resolved (fi
debian
CVE-2005-2794P4MEDIUMCVSS 5.0fixed in squid 2.5.10-5 (bookworm)2005
CVE-2005-2794 [MEDIUM] CVE-2005-2794: squid - store.c in Squid 2.5.STABLE10 and earlier allows remote attackers to cause a den...
store.c in Squid 2.5.STABLE10 and earlier allows remote attackers to cause a denial of service (crash) via certain aborted requests that trigger an assert error related to STORE_PENDING.
Scope: local
bookworm: resolved (fixed in 2.5.10-5)
bullseye: resolved (fixed in 2.5.10-5)
forky: resolved (fixed in 2.5.10-5)
sid: resolved (fixed in 2.5.10-5)
trixie: resolved (fixe
debian
CVE-2004-2654P4MEDIUMCVSS 5.0fixed in squid 2.5.6 (bookworm)2004
CVE-2004-2654 [MEDIUM] CVE-2004-2654: squid - The clientAbortBody function in client_side.c in Squid Web Proxy Cache before 2....
The clientAbortBody function in client_side.c in Squid Web Proxy Cache before 2.6 STABLE6 allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors that trigger a null dereference. NOTE: in a followup advisory, a researcher claimed that the issue was a buffer overflow that was not fixed in STABLE6. However, the vendor's bug repo
debian
CVE-2025-59362P4MEDIUMCVSS 4.0fixed in squid 5.7-2+deb12u5 (bookworm)2025
CVE-2025-59362 [MEDIUM] CVE-2025-59362: squid - Squid through 7.1 mishandles ASN.1 encoding of long SNMP OIDs. This occurs in as...
Squid through 7.1 mishandles ASN.1 encoding of long SNMP OIDs. This occurs in asn_build_objid in lib/snmplib/asn1.c.
Scope: local
bookworm: resolved (fixed in 5.7-2+deb12u5)
bullseye: resolved (fixed in 4.13-10+deb11u6)
forky: resolved (fixed in 7.2-1)
sid: resolved (fixed in 7.2-1)
trixie: resolved (fixed in 6.13-2+deb13u1)
debian
CVE-2004-2479P4MEDIUMCVSS 5.0fixed in squid 2.5.8 (bookworm)2004
CVE-2004-2479 [MEDIUM] CVE-2004-2479: squid - Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive infor...
Squid Web Proxy Cache 2.5 might allow remote attackers to obtain sensitive information via URLs containing invalid hostnames that cause DNS operations to fail, which results in references to previously used error messages.
Scope: local
bookworm: resolved (fixed in 2.5.8)
bullseye: resolved (fixed in 2.5.8)
forky: resolved (fixed in 2.5.8)
sid: resolved (fixed in 2.5.8
debian
CVE-2008-1612P4MEDIUMCVSS 5.0fixed in squid 2.6.18-1 (bookworm)2008
CVE-2008-1612 [MEDIUM] CVE-2008-1612: squid - The arrayShrink function (lib/Array.c) in Squid 2.6.STABLE17 allows attackers to...
The arrayShrink function (lib/Array.c) in Squid 2.6.STABLE17 allows attackers to cause a denial of service (process exit) via unknown vectors that cause an array to shrink to 0 entries, which triggers an assert error. NOTE: this issue is due to an incorrect fix for CVE-2007-6239.
Scope: local
bookworm: resolved (fixed in 2.6.18-1)
bullseye: resolved (fixed in 2.6.18-1
debian
CVE-2005-0626P4LOWCVSS 2.6fixed in squid 2.5.9-2 (bookworm)2005
CVE-2005-0626 [LOW] CVE-2005-0626: squid - Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-...
Race condition in Squid 2.5.STABLE7 to 2.5.STABLE9, when using the Netscape Set-Cookie recommendations for handling cookies in caches, may cause Set-Cookie headers to be sent to other users, which allows attackers to steal the related cookies.
Scope: local
bookworm: resolved (fixed in 2.5.9-2)
bullseye: resolved (fixed in 2.5.9-2)
forky: resolved (fixed in 2.5.9-2)
sid:
debian
← Previous6 / 6