Логотип exploitDog
bind:"CVE-2023-46724" OR bind:"CVE-2023-49285" OR bind:"CVE-2023-46728" OR bind:"CVE-2023-49286"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2023-46724" OR bind:"CVE-2023-49285" OR bind:"CVE-2023-46728" OR bind:"CVE-2023-49286"

Количество 34

Количество 34

oracle-oval логотип

ELSA-2024-0071

больше 1 года назад

ELSA-2024-0071: squid security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-0046

больше 1 года назад

ELSA-2024-0046: squid:4 security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2024-1787

около 1 года назад

ELSA-2024-1787: squid security update (IMPORTANT)

EPSS: Низкий
ubuntu логотип

CVE-2023-46724

больше 1 года назад

Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This bug is fixed in Squid version 6.4. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. Those who you use a prepackaged version of Squid should refer to the package vendor for availability information on updated packages.

CVSS3: 8.6
EPSS: Низкий
redhat логотип

CVE-2023-46724

больше 1 года назад

Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This bug is fixed in Squid version 6.4. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. Those who you use a prepackaged version of Squid should refer to the package vendor for availability information on updated packages.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-46724

больше 1 года назад

Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This bug is fixed in Squid version 6.4. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. Those who you use a prepackaged version of Squid should refer to the package vendor for availability information on updated packages.

CVSS3: 8.6
EPSS: Низкий
debian логотип

CVE-2023-46724

больше 1 года назад

Squid is a caching proxy for the Web. Due to an Improper Validation of ...

CVSS3: 8.6
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4825-1

больше 1 года назад

Security update for squid

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4724-1

больше 1 года назад

Security update for squid

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4698-1

больше 1 года назад

Security update for squid

EPSS: Низкий
fstec логотип

BDU:2023-07699

больше 1 года назад

Уязвимость прокси-сервера Squid, связанная с ошибками при проверке сертификата SSL/TLS, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.6
EPSS: Низкий
redos логотип

ROS-20240812-04

11 месяцев назад

Множественные уязвимости squid

CVSS3: 8.6
EPSS: Низкий
redos логотип

ROS-20240725-02

11 месяцев назад

Уязвимость squid

CVSS3: 8.6
EPSS: Низкий
ubuntu логотип

CVE-2023-49285

больше 1 года назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 8.6
EPSS: Низкий
redhat логотип

CVE-2023-49285

больше 1 года назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-49285

больше 1 года назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 8.6
EPSS: Низкий
debian логотип

CVE-2023-49285

больше 1 года назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and ...

CVSS3: 8.6
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4384-1

больше 1 года назад

Security update for squid

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4381-1

больше 1 года назад

Security update for squid

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4380-1

больше 1 года назад

Security update for squid

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2024-0071

ELSA-2024-0071: squid security update (IMPORTANT)

больше 1 года назад
oracle-oval логотип
ELSA-2024-0046

ELSA-2024-0046: squid:4 security update (IMPORTANT)

больше 1 года назад
oracle-oval логотип
ELSA-2024-1787

ELSA-2024-1787: squid security update (IMPORTANT)

около 1 года назад
ubuntu логотип
CVE-2023-46724

Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This bug is fixed in Squid version 6.4. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. Those who you use a prepackaged version of Squid should refer to the package vendor for availability information on updated packages.

CVSS3: 8.6
0%
Низкий
больше 1 года назад
redhat логотип
CVE-2023-46724

Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This bug is fixed in Squid version 6.4. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. Those who you use a prepackaged version of Squid should refer to the package vendor for availability information on updated packages.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2023-46724

Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This bug is fixed in Squid version 6.4. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. Those who you use a prepackaged version of Squid should refer to the package vendor for availability information on updated packages.

CVSS3: 8.6
0%
Низкий
больше 1 года назад
debian логотип
CVE-2023-46724

Squid is a caching proxy for the Web. Due to an Improper Validation of ...

CVSS3: 8.6
0%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2023:4825-1

Security update for squid

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2023:4724-1

Security update for squid

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2023:4698-1

Security update for squid

больше 1 года назад
fstec логотип
BDU:2023-07699

Уязвимость прокси-сервера Squid, связанная с ошибками при проверке сертификата SSL/TLS, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.6
0%
Низкий
больше 1 года назад
redos логотип
ROS-20240812-04

Множественные уязвимости squid

CVSS3: 8.6
11 месяцев назад
redos логотип
ROS-20240725-02

Уязвимость squid

CVSS3: 8.6
0%
Низкий
11 месяцев назад
ubuntu логотип
CVE-2023-49285

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 8.6
10%
Низкий
больше 1 года назад
redhat логотип
CVE-2023-49285

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 7.5
10%
Низкий
больше 1 года назад
nvd логотип
CVE-2023-49285

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 8.6
10%
Низкий
больше 1 года назад
debian логотип
CVE-2023-49285

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and ...

CVSS3: 8.6
10%
Низкий
больше 1 года назад
suse-cvrf логотип
SUSE-SU-2023:4384-1

Security update for squid

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2023:4381-1

Security update for squid

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2023:4380-1

Security update for squid

больше 1 года назад

Уязвимостей на страницу