Known vulnerabilities in squid - page 3
Vendor:
Fedoraproject
Software:
squid
Software CPE:
cpe:2.3:o:fedoraproject:squid:*:*:*:*:*:fedora:*:*
Website:
https://getfedora.org/
Total vulnerabilities:
67
Public exploits:
4
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.2
Breakdown by Severity Chart
7.6-1.fc44
7.5-3.fc45
7.5-1.fc44
7.5-1.fc43
7.2-1.fc43
6.14-1.fc41
6.14-1.fc42
4.13-1.fc33
4.13-1.fc32
4.13-1.fc31
4.12-1.fc31
4.11-1.fc31
4.11-1.fc32
4.11-1.fc30
4.10-3.fc30
4.10-3.fc31
4.9-2.fc31
4.9-2.fc30
4.8-2.fc29
4.8-1.fc29
4.8-1.fc30
4.4-2.fc29
4.4-1.fc28
4.4-1.fc29
4.0.23-1.fc26
4.0.23-2.fc27
3.5.23-1.fc24
4.0.17-1.fc25
3.5.19-2.fc24
3.5.19-1.fc24
3.5.10-4.fc22
3.5.10-4.fc23
3.5.17-1.fc24
3.5.10-3.fc23
3.5.10-3.fc22
3.5.16-1.fc24
3.5.10-2.fc22
3.5.10-2.fc23
3.5.10-1.fc22
3.5.10-1.fc23
3.5.9-7.fc23
3.5.9-6.fc23
3.4.13-3.fc22
3.4.13-2.fc22
3.4.13-1.fc22
3.4.13-1.fc21
3.4.7-2.fc21
3.4.7-1.fc21
5.7-1.fc35
5.7-1.fc36
5.7-1.fc37
5.6-1.fc36
5.6-1.fc35
5.2-1.fc33
5.2-1.fc34
5.2-1.fc35
5.0.6-1.fc34
4.15-1.fc33
4.14-1.fc33
4.14-1.fc34
4.14-1.fc32
6.12-2.fc39
6.12-2.fc41
6.12-2.fc40
6.10-1.fc40
6.10-1.fc39
6.9-1.fc39
6.9-1.fc38
6.6-1.fc39
6.6-1.fc38
6.4-1.fc39
6.4-1.fc38
6.4-1.fc37
Vulnerabilities (67)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU25019 - Out-of-bounds read CVE-2019-12528 |
CWE-125 | Medium | 4.10-3.fc30, 4.10-3.fc31 | 07.02.2020 |
SB2020020702 SB2020022108 SB2020030601 and 13 more |
||
| #VU25018 - Memory corruption CVE-2020-8450 |
CWE-119 | High | 4.10-3.fc30, 4.10-3.fc31 | 07.02.2020 |
SB2020020702 SB2020022108 SB2020030601 and 12 more |
||
| #VU25017 - Improper input validation CVE-2020-8449 |
CWE-20 | Medium | 4.10-3.fc30, 4.10-3.fc31 | 07.02.2020 |
SB2020020702 SB2020022108 SB2020030601 and 12 more |
||
| #VU22910 - Cross-Site Request Forgery (CSRF) CVE-2019-18677 |
CWE-352 | Medium | 4.9-2.fc30, 4.9-2.fc31 | 22.11.2019 |
SB2019110710 SB2019112201 SB2019112202 and 6 more |
||
| #VU22909 - Improper input validation CVE-2019-18676 |
CWE-20 | Medium | 4.9-2.fc30, 4.9-2.fc31 | 22.11.2019 |
SB2019110710 SB2019112201 SB2019112202 and 9 more |
||
| #VU22908 - Improper input validation CVE-2019-12523 |
CWE-20 | Medium | 4.9-2.fc30, 4.9-2.fc31 | 22.11.2019 |
SB2019110710 SB2019112201 SB2019112202 and 9 more |
||
| #VU22589 - Exposure of sensitive information to an unauthorized actor CVE-2019-18679 |
CWE-200 | Low | 4.9-2.fc30, 4.9-2.fc31 | 07.11.2019 |
SB2019110709 SB2019110710 SB2019112201 and 9 more |
||
| #VU22587 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2019-18678 |
CWE-444 | Medium | 4.9-2.fc30, 4.9-2.fc31 | 07.11.2019 |
SB2019110709 SB2019110710 SB2019112201 and 8 more |
||
| #VU22585 - Heap-based Buffer Overflow CVE-2019-12526 |
CWE-122 | High | 4.9-2.fc30, 4.9-2.fc31 | 07.11.2019 |
SB2019110709 SB2019110710 SB2019112201 and 9 more |
||
| #VU20461 - Out-of-bounds read CVE-2019-12854 |
CWE-125 | Medium | 4.8-1.fc29, 4.8-2.fc29 | 29.08.2019 |
SB2019082403 SB2019112201 SB2019112202 and 5 more |
||
| #VU20460 - Out-of-bounds read CVE-2019-12529 |
CWE-125 | Low | 4.8-1.fc29, 4.8-2.fc29 | 29.08.2019 |
SB2019082403 SB2019112201 SB2019112202 and 5 more |
||
| #VU20445 - Memory corruption CVE-2019-12525 |
CWE-119 | Medium | 4.8-1.fc29, 4.8-2.fc29 | 28.08.2019 |
SB2019082403 SB2019112201 SB2019112202 and 9 more |
||
| #VU19169 - Heap-based Buffer Overflow CVE-2019-12527 |
CWE-122 | High | 4.8-1.fc29, 4.8-2.fc29 | 15.07.2019 |
SB2019071101 SB2019071701 SB2019082403 and 5 more |
||
| #VU19140 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2019-13345 |
CWE-79 | Medium | 4.4-2.fc29, 4.8-1.fc29, 4.8-1.fc30, 4.8-2.fc29 | 11.07.2019 |
SB2019071101 SB2019071804 SB2019082010 and 12 more |
||
| #VU15903 - Missing release of memory after effective lifetime CVE-2018-19132 |
CWE-401 | Medium | 4.4-1.fc28, 4.4-1.fc29 | 15.11.2018 |
SB2018111415 SB2018112104 SB2018112108 and 3 more |
||
| #VU15896 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2018-19131 |
CWE-79 | Low | 4.4-1.fc28, 4.4-1.fc29 | 14.11.2018 |
SB2018111415 SB2018112104 SB2018112108 and 2 more |
||
| #VU10384 - Improper Access Control CVE-2018-1000027 |
CWE-284 | Low | 4.0.23-1.fc26, 4.0.23-2.fc27 | 06.02.2018 |
SB2018020610 SB2018022305 SB2018092106 and 6 more |
||
| #VU10383 - NULL Pointer Dereference CVE-2018-1000024 |
CWE-476 | Medium | 4.0.23-1.fc26, 4.0.23-2.fc27 | 06.02.2018 |
SB2018012312 SB2018020610 SB2018022305 and 7 more |
||
| #VU10164 - NULL Pointer Dereference CVE-2018-1000027 |
CWE-476 | Medium | 4.0.23-1.fc26, 4.0.23-2.fc27 | 23.01.2018 |
SB2018012312 SB2022121201 SB2018012336 and 1 more |
||
| #VU8428 - Exposure of sensitive information to an unauthorized actor CVE-2016-10003 |
CWE-200 | Medium | 3.5.23-1.fc24, 4.0.17-1.fc25 | 14.09.2017 |
SB2016121701 SB2017020602 SB2016122912 and 3 more |
Showing elements 41 - 60 out of 67