Known vulnerabilities in squid (Debian package)

Vendor: Debian
Software CPE: cpe:2.3:o:debian:squid_debian_package:*:*:*:*:*:debian_linux:*:*
Total vulnerabilities: 55
Public exploits: 3
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting squid (Debian package) squid (Debian package) is affected by 55 known vulnerabilities: 5 high, 40 medium, 10 low Critical High Medium Low

Vulnerabilities (55)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU135132 - Out-of-bounds read
CVE-2026-47729
CWE-125 Low
No
No
6.13-2+deb13u2 24.06.2026 SB2026062448
SB2026062453
SB20260624111
and 1 more
#VU135131 - Heap-based Buffer Overflow
CVE-2026-50012
CWE-122 Low
No
No
6.13-2+deb13u2 24.06.2026 SB2026062448
SB2026062453
SB20260624111
and 1 more
#VU124611 - Out-of-bounds read
CVE-2026-33515
CWE-125 Medium
No
No
6.13-2+deb13u2 25.03.2026 SB20260325206
SB2026040350
SB2026040351
and 6 more
#VU124610 - Use After Free
CVE-2026-33526
CWE-416 Medium
No
No
6.13-2+deb13u2 25.03.2026 SB20260325206
SB2026033197
SB2026040350
and 18 more
#VU117357 - Externally-generated error message containing sensitive information
CVE-2025-62168
CWE-211 Low
Available
No
5.7-2+deb12u4, 6.13-2+deb13u1 17.10.2025 SB2025101757
SB2025101803
SB2025101804
and 26 more
#VU113574 - Buffer over-read
CVE-2025-54574
CWE-126 Medium
No
No
5.7-2+deb12u3 01.08.2025 SB2023102416
SB2025082141
SB2025082502
and 5 more
#VU93235 - Out-of-bounds write
CVE-2024-37894
CWE-787 Medium
No
No
5.7-2+deb12u2 25.06.2024 SB2024062519
SB2024070286
SB2024070287
and 11 more
#VU87680 - Uncontrolled Recursion
CVE-2024-25111
CWE-674 Medium
No
No
4.13-10+deb11u3, 5.7-2+deb12u1 20.03.2024 SB2024032067
SB2024032078
SB2024032634
and 24 more
#VU86547 - Improper input validation
CVE-2024-25617
CWE-20 Medium
No
No
4.13-10+deb11u3, 5.7-2+deb12u1 15.02.2024 SB2024021536
SB2024030157
SB2024030601
and 20 more
#VU85722 - Expired pointer dereference
CVE-2024-23638
CWE-825 Medium
No
No
4.13-10+deb11u3, 5.7-2+deb12u1 23.01.2024 SB2024012343
SB2024020237
SB2024020238
and 14 more
#VU84442 - Uncontrolled Recursion
CVE-2023-50269
CWE-674 Medium
No
No
4.13-10+deb11u3, 5.7-2+deb12u1 15.12.2023 SB2023121502
SB2023122042
SB2023122043
and 20 more
#VU83629 - Out-of-bounds read
CVE-2023-49285
CWE-125 Medium
No
No
4.13-10+deb11u3, 5.7-2+deb12u1 03.12.2023 SB2023120303
SB2023121253
SB2023121254
and 22 more
#VU83628 - Unchecked Return Value
CVE-2023-49286
CWE-252 Medium
No
No
4.13-10+deb11u3, 5.7-2+deb12u1 03.12.2023 SB2023120303
SB2023121253
SB2023121254
and 20 more
#VU83379 - NULL Pointer Dereference
CVE-2023-46728
CWE-476 Medium
No
No
4.13-10+deb11u3, 5.7-2+deb12u1 21.11.2023 SB2023090612
SB2023112157
SB2023112458
and 21 more
#VU82907 - Improper input validation
CVE-2023-46848
CWE-20 Medium
No
No
4.13-10+deb11u3, 5.7-2+deb12u1 08.11.2023 SB2023102416
SB2023110805
SB2023110806
and 6 more
#VU82906 - Improper Certificate Validation
CVE-2023-46724
CWE-295 Medium
No
No
4.13-10+deb11u3, 5.7-2+deb12u1 08.11.2023 SB2023102416
SB2023110805
SB2023110806
and 21 more
#VU82316 - Improper Handling of Structural Elements
CVE-2023-5824
CWE-237 Medium
No
No
5.7-2+deb12u3 24.10.2023 SB2023102416
SB2023110745
SB2023110746
and 21 more
#VU82315 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2023-46846
CWE-444 Medium
No
No
4.13-10+deb11u3, 5.7-2+deb12u1 24.10.2023 SB2023102416
SB2023110745
SB2023110746
and 25 more
#VU82313 - Memory corruption
CVE-2023-46847
CWE-119 Medium
No
No
4.13-10+deb11u3, 5.7-2+deb12u1 24.10.2023 SB2023102416
SB2023110745
SB2023110746
and 30 more
#VU80476 - Buffer overflow
CVE-2023-46724
CWE-120 Medium
No
No
4.13-10+deb11u3, 5.7-2+deb12u1 06.09.2023 SB2023090612
SB2023112157
SB2023120441
and 10 more


Showing elements 1 - 20 out of 55