Known vulnerabilities in Squid 4.1 - page 2

Software: Squid
Version: 4.1
Software CPE: cpe:2.3:a:squid-cache_org:squid:*:*:*:*:*:*:*:*
Website:
Total vulnerabilities: 54
Public exploits: 3
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Squid version 4.1 Squid 4.1 is affected by 54 vulnerabilities: 5 high, 41 medium, 8 low Critical High Medium Low

Vulnerabilities (54)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU113717 - Permissions, Privileges, and Access Controls
CVE-2019-12522
CWE-264 Low
No
No
- 06.08.2025 SB2020041542
#VU53599 - Resource Management Errors
CVE-2021-31807
CWE-399 Medium
Public exploit available
No
4.15, 5.0.6 26.05.2021 SB2021051025
SB2021052636
SB2021060215
and 6 more
#VU53022 - Improper input validation
CWE-20 Medium
No
No
4.15, 5.0.6 10.05.2021 SB2021051025
#VU53021 - Integer overflow
CVE-2021-31808
CWE-190 Medium
No
No
4.15, 5.0.6 10.05.2021 SB2021051025
SB2021052636
SB2021060215
and 7 more
#VU53020 - Improper input validation
CVE-2021-31806
CWE-20 Medium
Public exploit available
No
4.15, 5.0.6 10.05.2021 SB2021051025
SB2021052636
SB2021060215
and 9 more
#VU53019 - Missing release of memory after effective lifetime
CVE-2021-28652
CWE-401 Medium
No
No
4.15, 5.0.6 10.05.2021 SB2021051025
SB2021051925
SB2021052636
and 10 more
#VU51248 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2020-25097
CWE-444 Medium
No
No
4.14, 5.0.5 08.03.2021 SB2021030801
SB2021032504
SB2021041206
and 16 more
#VU50972 - Double Free
CWE-415 Low
No
No
- 28.02.2021 SB2021022801
#VU50456 - Use After Free
CWE-416 Medium
No
No
- 09.02.2021 SB2021020925
#VU46118 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2020-15811
CWE-113 Medium
No
No
4.13, 5.0.4 28.08.2020 SB2020082807
SB2020083119
SB2020090501
and 12 more
#VU46117 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2020-15810
CWE-444 Medium
No
No
4.13, 5.0.4 28.08.2020 SB2020082807
SB2020083119
SB2020090501
and 12 more
#VU45957 - Resource exhaustion
CVE-2020-24606
CWE-400 Low
No
No
4.13, 5.0.4 23.08.2020 SB2020082301
SB2020083119
SB2020090501
and 13 more
#VU29391 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2020-15049
CWE-444 Medium
No
No
4.12, 5.0.3 30.06.2020 SB2020063011
SB2020090501
SB2020090724
and 10 more
#VU29390 - Exposed Dangerous Method or Function
CVE-2020-14058
CWE-749 Medium
No
No
4.12, 5.0.3 30.06.2020 SB2020063011
SB2020110501
SB2023060671
and 3 more
#VU27677 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2019-18860
CWE-74 Low
No
No
4.9 11.05.2020 SB2020032011
SB2020051133
SB2020051324
and 4 more
#VU27667 - Out-of-bounds write
CVE-2019-12521
CWE-787 Medium
No
No
4.8, 5.0.2 11.05.2020 SB2020042377
SB2020051116
SB2020051133
and 7 more
#VU27666 - Integer overflow
CVE-2020-11945
CWE-190 High
No
No
4.11, 5.0.2 11.05.2020 SB2020042377
SB2020051112
SB2020051113
and 15 more
#VU27665 - Out-of-bounds write
CVE-2019-12519
CWE-787 High
No
No
4.11 11.05.2020 SB2020042377
SB2020051112
SB2020051113
and 12 more
#VU25020 - Memory corruption
CVE-2020-8517
CWE-119 Medium
No
No
4.10 07.02.2020 SB2020020702
SB2020022108
SB2020030601
and 6 more
#VU25019 - Out-of-bounds read
CVE-2019-12528
CWE-125 Medium
No
No
4.10 07.02.2020 SB2020020702
SB2020022108
SB2020030601
and 13 more


Showing elements 21 - 40 out of 54