Known vulnerabilities in squid - page 3

Software: squid
Software CPE: cpe:2.3:o:fedoraproject:squid:*:*:*:*:*:fedora:*:*
Total vulnerabilities: 67
Public exploits: 4
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting squid squid is affected by 67 known vulnerabilities: 5 high, 51 medium, 11 low Critical High Medium Low

Vulnerabilities (67)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU25019 - Out-of-bounds read
CVE-2019-12528
CWE-125 Medium
No
No
4.10-3.fc30, 4.10-3.fc31 07.02.2020 SB2020020702
SB2020022108
SB2020030601
and 13 more
#VU25018 - Memory corruption
CVE-2020-8450
CWE-119 High
No
No
4.10-3.fc30, 4.10-3.fc31 07.02.2020 SB2020020702
SB2020022108
SB2020030601
and 12 more
#VU25017 - Improper input validation
CVE-2020-8449
CWE-20 Medium
No
No
4.10-3.fc30, 4.10-3.fc31 07.02.2020 SB2020020702
SB2020022108
SB2020030601
and 12 more
#VU22910 - Cross-Site Request Forgery (CSRF)
CVE-2019-18677
CWE-352 Medium
No
No
4.9-2.fc30, 4.9-2.fc31 22.11.2019 SB2019110710
SB2019112201
SB2019112202
and 6 more
#VU22909 - Improper input validation
CVE-2019-18676
CWE-20 Medium
No
No
4.9-2.fc30, 4.9-2.fc31 22.11.2019 SB2019110710
SB2019112201
SB2019112202
and 9 more
#VU22908 - Improper input validation
CVE-2019-12523
CWE-20 Medium
No
No
4.9-2.fc30, 4.9-2.fc31 22.11.2019 SB2019110710
SB2019112201
SB2019112202
and 9 more
#VU22589 - Exposure of sensitive information to an unauthorized actor
CVE-2019-18679
CWE-200 Low
No
No
4.9-2.fc30, 4.9-2.fc31 07.11.2019 SB2019110709
SB2019110710
SB2019112201
and 9 more
#VU22587 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2019-18678
CWE-444 Medium
No
No
4.9-2.fc30, 4.9-2.fc31 07.11.2019 SB2019110709
SB2019110710
SB2019112201
and 8 more
#VU22585 - Heap-based Buffer Overflow
CVE-2019-12526
CWE-122 High
No
No
4.9-2.fc30, 4.9-2.fc31 07.11.2019 SB2019110709
SB2019110710
SB2019112201
and 9 more
#VU20461 - Out-of-bounds read
CVE-2019-12854
CWE-125 Medium
No
No
4.8-1.fc29, 4.8-2.fc29 29.08.2019 SB2019082403
SB2019112201
SB2019112202
and 5 more
#VU20460 - Out-of-bounds read
CVE-2019-12529
CWE-125 Low
No
No
4.8-1.fc29, 4.8-2.fc29 29.08.2019 SB2019082403
SB2019112201
SB2019112202
and 5 more
#VU20445 - Memory corruption
CVE-2019-12525
CWE-119 Medium
No
No
4.8-1.fc29, 4.8-2.fc29 28.08.2019 SB2019082403
SB2019112201
SB2019112202
and 9 more
#VU19169 - Heap-based Buffer Overflow
CVE-2019-12527
CWE-122 High
No
No
4.8-1.fc29, 4.8-2.fc29 15.07.2019 SB2019071101
SB2019071701
SB2019082403
and 5 more
#VU19140 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2019-13345
CWE-79 Medium
No
No
4.4-2.fc29, 4.8-1.fc29, 4.8-1.fc30, 4.8-2.fc29 11.07.2019 SB2019071101
SB2019071804
SB2019082010
and 12 more
#VU15903 - Missing release of memory after effective lifetime
CVE-2018-19132
CWE-401 Medium
No
No
4.4-1.fc28, 4.4-1.fc29 15.11.2018 SB2018111415
SB2018112104
SB2018112108
and 3 more
#VU15896 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2018-19131
CWE-79 Low
Available
No
4.4-1.fc28, 4.4-1.fc29 14.11.2018 SB2018111415
SB2018112104
SB2018112108
and 2 more
#VU10384 - Improper Access Control
CVE-2018-1000027
CWE-284 Low
No
No
4.0.23-1.fc26, 4.0.23-2.fc27 06.02.2018 SB2018020610
SB2018022305
SB2018092106
and 6 more
#VU10383 - NULL Pointer Dereference
CVE-2018-1000024
CWE-476 Medium
No
No
4.0.23-1.fc26, 4.0.23-2.fc27 06.02.2018 SB2018012312
SB2018020610
SB2018022305
and 7 more
#VU10164 - NULL Pointer Dereference
CVE-2018-1000027
CWE-476 Medium
No
No
4.0.23-1.fc26, 4.0.23-2.fc27 23.01.2018 SB2018012312
SB2022121201
SB2018012336
and 1 more
#VU8428 - Exposure of sensitive information to an unauthorized actor
CVE-2016-10003
CWE-200 Medium
No
No
3.5.23-1.fc24, 4.0.17-1.fc25 14.09.2017 SB2016121701
SB2017020602
SB2016122912
and 3 more


Showing elements 41 - 60 out of 67