Known vulnerabilities in squid - page 2
Vendor:
Fedoraproject
Software:
squid
Software CPE:
cpe:2.3:o:fedoraproject:squid:*:*:*:*:*:fedora:*:*
Website:
https://getfedora.org/
Total vulnerabilities:
67
Public exploits:
4
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.2
Breakdown by Severity Chart
7.6-1.fc44
7.5-3.fc45
7.5-1.fc44
7.5-1.fc43
7.2-1.fc43
6.14-1.fc41
6.14-1.fc42
4.13-1.fc33
4.13-1.fc32
4.13-1.fc31
4.12-1.fc31
4.11-1.fc31
4.11-1.fc32
4.11-1.fc30
4.10-3.fc30
4.10-3.fc31
4.9-2.fc31
4.9-2.fc30
4.8-2.fc29
4.8-1.fc29
4.8-1.fc30
4.4-2.fc29
4.4-1.fc28
4.4-1.fc29
4.0.23-1.fc26
4.0.23-2.fc27
3.5.23-1.fc24
4.0.17-1.fc25
3.5.19-2.fc24
3.5.19-1.fc24
3.5.10-4.fc22
3.5.10-4.fc23
3.5.17-1.fc24
3.5.10-3.fc23
3.5.10-3.fc22
3.5.16-1.fc24
3.5.10-2.fc22
3.5.10-2.fc23
3.5.10-1.fc22
3.5.10-1.fc23
3.5.9-7.fc23
3.5.9-6.fc23
3.4.13-3.fc22
3.4.13-2.fc22
3.4.13-1.fc22
3.4.13-1.fc21
3.4.7-2.fc21
3.4.7-1.fc21
5.7-1.fc35
5.7-1.fc36
5.7-1.fc37
5.6-1.fc36
5.6-1.fc35
5.2-1.fc33
5.2-1.fc34
5.2-1.fc35
5.0.6-1.fc34
4.15-1.fc33
4.14-1.fc33
4.14-1.fc34
4.14-1.fc32
6.12-2.fc39
6.12-2.fc41
6.12-2.fc40
6.10-1.fc40
6.10-1.fc39
6.9-1.fc39
6.9-1.fc38
6.6-1.fc39
6.6-1.fc38
6.4-1.fc39
6.4-1.fc38
6.4-1.fc37
Vulnerabilities (67)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU82316 - Improper Handling of Structural Elements CVE-2023-5824 |
CWE-237 | Medium | 6.4-1.fc37, 6.4-1.fc38, 6.4-1.fc39 | 24.10.2023 |
SB2023102416 SB2023110745 SB2023110746 and 21 more |
||
| #VU67609 - Out-of-bounds read CVE-2022-41318 |
CWE-125 | Medium | 5.7-1.fc35, 5.7-1.fc36, 5.7-1.fc37 | 23.09.2022 |
SB2022092322 SB2022092651 SB2022100537 and 20 more |
||
| #VU67604 - Improper Access Control CVE-2022-41317 |
CWE-284 | Low | 5.7-1.fc35, 5.7-1.fc36, 5.7-1.fc37 | 23.09.2022 |
SB2022092311 SB2022092651 SB2022100635 and 9 more |
||
| #VU65362 - Improper input validation CVE-2021-33620 |
CWE-20 | Medium | 4.15-1.fc33, 5.0.6-1.fc34 | 15.07.2022 |
SB2022071601 SB2022072641 SB2023022337 and 6 more |
||
| #VU64484 - Reachable Assertion CVE-2021-46784 |
CWE-617 | Medium | 5.6-1.fc35, 5.6-1.fc36 | 18.06.2022 |
SB2022061801 SB2022062237 SB2022062908 and 20 more |
||
| #VU57025 - Improper Certificate Validation CVE-2021-41611 |
CWE-295 | Medium | 5.2-1.fc33, 5.2-1.fc34, 5.2-1.fc35 | 04.10.2021 |
SB2021100402 SB2021100531 SB2021100532 and 1 more |
||
| #VU53599 - Resource Management Errors CVE-2021-31807 |
CWE-399 | Medium | 4.15-1.fc33, 5.0.6-1.fc34 | 26.05.2021 |
SB2021051025 SB2021052636 SB2021060215 and 6 more |
||
| #VU53021 - Integer overflow CVE-2021-31808 |
CWE-190 | Medium | 4.15-1.fc33, 5.0.6-1.fc34 | 10.05.2021 |
SB2021051025 SB2021052636 SB2021060215 and 7 more |
||
| #VU53020 - Improper input validation CVE-2021-31806 |
CWE-20 | Medium | 4.15-1.fc33, 5.0.6-1.fc34 | 10.05.2021 |
SB2021051025 SB2021052636 SB2021060215 and 9 more |
||
| #VU53019 - Missing release of memory after effective lifetime CVE-2021-28652 |
CWE-401 | Medium | 4.15-1.fc33, 5.0.6-1.fc34 | 10.05.2021 |
SB2021051025 SB2021051925 SB2021052636 and 10 more |
||
| #VU53018 - Improper input validation CVE-2021-28662 |
CWE-20 | Medium | 4.15-1.fc33, 5.0.6-1.fc34 | 10.05.2021 |
SB2021051025 SB2021051925 SB2021052636 and 9 more |
||
| #VU53017 - Improper input validation CVE-2021-28651 |
CWE-20 | Medium | 4.15-1.fc33, 5.0.6-1.fc34 | 10.05.2021 |
SB2021051025 SB2021051925 SB2021052636 and 14 more |
||
| #VU51248 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2020-25097 |
CWE-444 | Medium | 4.14-1.fc32, 4.14-1.fc33, 4.14-1.fc34 | 08.03.2021 |
SB2021030801 SB2021032504 SB2021041206 and 16 more |
||
| #VU50457 - Out-of-bounds read CVE-2021-28116 |
CWE-125 | Medium | 4.15-1.fc33, 5.0.6-1.fc34 | 09.02.2021 |
SB2021100402 SB2022051154 SB2021101120 and 7 more |
||
| #VU46118 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') CVE-2020-15811 |
CWE-113 | Medium | 4.13-1.fc31, 4.13-1.fc32, 4.13-1.fc33 | 28.08.2020 |
SB2020082807 SB2020083119 SB2020090501 and 12 more |
||
| #VU46117 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2020-15810 |
CWE-444 | Medium | 4.13-1.fc31, 4.13-1.fc32, 4.13-1.fc33 | 28.08.2020 |
SB2020082807 SB2020083119 SB2020090501 and 12 more |
||
| #VU45957 - Resource exhaustion CVE-2020-24606 |
CWE-400 | Low | 4.13-1.fc31, 4.13-1.fc32, 4.13-1.fc33 | 23.08.2020 |
SB2020082301 SB2020083119 SB2020090501 and 13 more |
||
| #VU29391 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2020-15049 |
CWE-444 | Medium | 4.12-1.fc31 | 30.06.2020 |
SB2020063011 SB2020090501 SB2020090724 and 10 more |
||
| #VU29390 - Exposed Dangerous Method or Function CVE-2020-14058 |
CWE-749 | Medium | 4.12-1.fc31 | 30.06.2020 |
SB2020063011 SB2020110501 SB2023060671 and 3 more |
||
| #VU27666 - Integer overflow CVE-2020-11945 |
CWE-190 | High | 4.11-1.fc30, 4.11-1.fc31, 4.11-1.fc32 | 11.05.2020 |
SB2020042377 SB2020051112 SB2020051113 and 15 more |
Showing elements 21 - 40 out of 67