Known vulnerabilities in squid - page 2

Software: squid
Software CPE: cpe:2.3:o:fedoraproject:squid:*:*:*:*:*:fedora:*:*
Total vulnerabilities: 67
Public exploits: 4
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting squid squid is affected by 67 known vulnerabilities: 5 high, 51 medium, 11 low Critical High Medium Low

Vulnerabilities (67)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU82316 - Improper Handling of Structural Elements
CVE-2023-5824
CWE-237 Medium
No
No
6.4-1.fc37, 6.4-1.fc38, 6.4-1.fc39 24.10.2023 SB2023102416
SB2023110745
SB2023110746
and 21 more
#VU67609 - Out-of-bounds read
CVE-2022-41318
CWE-125 Medium
No
No
5.7-1.fc35, 5.7-1.fc36, 5.7-1.fc37 23.09.2022 SB2022092322
SB2022092651
SB2022100537
and 20 more
#VU67604 - Improper Access Control
CVE-2022-41317
CWE-284 Low
No
No
5.7-1.fc35, 5.7-1.fc36, 5.7-1.fc37 23.09.2022 SB2022092311
SB2022092651
SB2022100635
and 9 more
#VU65362 - Improper input validation
CVE-2021-33620
CWE-20 Medium
No
No
4.15-1.fc33, 5.0.6-1.fc34 15.07.2022 SB2022071601
SB2022072641
SB2023022337
and 6 more
#VU64484 - Reachable Assertion
CVE-2021-46784
CWE-617 Medium
No
No
5.6-1.fc35, 5.6-1.fc36 18.06.2022 SB2022061801
SB2022062237
SB2022062908
and 20 more
#VU57025 - Improper Certificate Validation
CVE-2021-41611
CWE-295 Medium
No
No
5.2-1.fc33, 5.2-1.fc34, 5.2-1.fc35 04.10.2021 SB2021100402
SB2021100531
SB2021100532
and 1 more
#VU53599 - Resource Management Errors
CVE-2021-31807
CWE-399 Medium
Available
No
4.15-1.fc33, 5.0.6-1.fc34 26.05.2021 SB2021051025
SB2021052636
SB2021060215
and 6 more
#VU53021 - Integer overflow
CVE-2021-31808
CWE-190 Medium
No
No
4.15-1.fc33, 5.0.6-1.fc34 10.05.2021 SB2021051025
SB2021052636
SB2021060215
and 7 more
#VU53020 - Improper input validation
CVE-2021-31806
CWE-20 Medium
Available
No
4.15-1.fc33, 5.0.6-1.fc34 10.05.2021 SB2021051025
SB2021052636
SB2021060215
and 9 more
#VU53019 - Missing release of memory after effective lifetime
CVE-2021-28652
CWE-401 Medium
No
No
4.15-1.fc33, 5.0.6-1.fc34 10.05.2021 SB2021051025
SB2021051925
SB2021052636
and 10 more
#VU53018 - Improper input validation
CVE-2021-28662
CWE-20 Medium
No
No
4.15-1.fc33, 5.0.6-1.fc34 10.05.2021 SB2021051025
SB2021051925
SB2021052636
and 9 more
#VU53017 - Improper input validation
CVE-2021-28651
CWE-20 Medium
No
No
4.15-1.fc33, 5.0.6-1.fc34 10.05.2021 SB2021051025
SB2021051925
SB2021052636
and 14 more
#VU51248 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2020-25097
CWE-444 Medium
No
No
4.14-1.fc32, 4.14-1.fc33, 4.14-1.fc34 08.03.2021 SB2021030801
SB2021032504
SB2021041206
and 16 more
#VU50457 - Out-of-bounds read
CVE-2021-28116
CWE-125 Medium
No
No
4.15-1.fc33, 5.0.6-1.fc34 09.02.2021 SB2021100402
SB2022051154
SB2021101120
and 7 more
#VU46118 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2020-15811
CWE-113 Medium
No
No
4.13-1.fc31, 4.13-1.fc32, 4.13-1.fc33 28.08.2020 SB2020082807
SB2020083119
SB2020090501
and 12 more
#VU46117 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2020-15810
CWE-444 Medium
No
No
4.13-1.fc31, 4.13-1.fc32, 4.13-1.fc33 28.08.2020 SB2020082807
SB2020083119
SB2020090501
and 12 more
#VU45957 - Resource exhaustion
CVE-2020-24606
CWE-400 Low
No
No
4.13-1.fc31, 4.13-1.fc32, 4.13-1.fc33 23.08.2020 SB2020082301
SB2020083119
SB2020090501
and 13 more
#VU29391 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2020-15049
CWE-444 Medium
No
No
4.12-1.fc31 30.06.2020 SB2020063011
SB2020090501
SB2020090724
and 10 more
#VU29390 - Exposed Dangerous Method or Function
CVE-2020-14058
CWE-749 Medium
No
No
4.12-1.fc31 30.06.2020 SB2020063011
SB2020110501
SB2023060671
and 3 more
#VU27666 - Integer overflow
CVE-2020-11945
CWE-190 High
No
No
4.11-1.fc30, 4.11-1.fc31, 4.11-1.fc32 11.05.2020 SB2020042377
SB2020051112
SB2020051113
and 15 more


Showing elements 21 - 40 out of 67