Логотип exploitDog
bind:"CVE-2023-49286" OR bind:"CVE-2023-46728" OR bind:"CVE-2023-49285" OR bind:"CVE-2023-46724"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2023-49286" OR bind:"CVE-2023-46728" OR bind:"CVE-2023-49285" OR bind:"CVE-2023-46724"

Количество 34

Количество 34

ubuntu логотип

CVE-2023-49285

больше 1 года назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 8.6
EPSS: Низкий
redhat логотип

CVE-2023-49285

больше 1 года назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-49285

больше 1 года назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 8.6
EPSS: Низкий
debian логотип

CVE-2023-49285

больше 1 года назад

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and ...

CVSS3: 8.6
EPSS: Низкий
ubuntu логотип

CVE-2023-46724

больше 1 года назад

Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This bug is fixed in Squid version 6.4. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. Those who you use a prepackaged version of Squid should refer to the package vendor for availability information on updated packages.

CVSS3: 8.6
EPSS: Низкий
redhat логотип

CVE-2023-46724

больше 1 года назад

Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This bug is fixed in Squid version 6.4. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. Those who you use a prepackaged version of Squid should refer to the package vendor for availability information on updated packages.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-46724

больше 1 года назад

Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This bug is fixed in Squid version 6.4. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. Those who you use a prepackaged version of Squid should refer to the package vendor for availability information on updated packages.

CVSS3: 8.6
EPSS: Низкий
debian логотип

CVE-2023-46724

больше 1 года назад

Squid is a caching proxy for the Web. Due to an Improper Validation of ...

CVSS3: 8.6
EPSS: Низкий
fstec логотип

BDU:2023-08581

больше 1 года назад

Уязвимость прокси-сервера Squid, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.6
EPSS: Низкий
fstec логотип

BDU:2023-07699

больше 1 года назад

Уязвимость прокси-сервера Squid, связанная с ошибками при проверке сертификата SSL/TLS, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.6
EPSS: Низкий
redos логотип

ROS-20240725-02

11 месяцев назад

Уязвимость squid

CVSS3: 8.6
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4384-1

больше 1 года назад

Security update for squid

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4381-1

больше 1 года назад

Security update for squid

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:4380-1

больше 1 года назад

Security update for squid

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-49285

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 8.6
10%
Низкий
больше 1 года назад
redhat логотип
CVE-2023-49285

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 7.5
10%
Низкий
больше 1 года назад
nvd логотип
CVE-2023-49285

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and more. Due to a Buffer Overread bug Squid is vulnerable to a Denial of Service attack against Squid HTTP Message processing. This bug is fixed by Squid version 6.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS3: 8.6
10%
Низкий
больше 1 года назад
debian логотип
CVE-2023-49285

Squid is a caching proxy for the Web supporting HTTP, HTTPS, FTP, and ...

CVSS3: 8.6
10%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2023-46724

Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This bug is fixed in Squid version 6.4. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. Those who you use a prepackaged version of Squid should refer to the package vendor for availability information on updated packages.

CVSS3: 8.6
0%
Низкий
больше 1 года назад
redhat логотип
CVE-2023-46724

Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This bug is fixed in Squid version 6.4. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. Those who you use a prepackaged version of Squid should refer to the package vendor for availability information on updated packages.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2023-46724

Squid is a caching proxy for the Web. Due to an Improper Validation of Specified Index bug, Squid versions 3.3.0.1 through 5.9 and 6.0 prior to 6.4 compiled using `--with-openssl` are vulnerable to a Denial of Service attack against SSL Certificate validation. This problem allows a remote server to perform Denial of Service against Squid Proxy by initiating a TLS Handshake with a specially crafted SSL Certificate in a server certificate chain. This attack is limited to HTTPS and SSL-Bump. This bug is fixed in Squid version 6.4. In addition, patches addressing this problem for the stable releases can be found in Squid's patch archives. Those who you use a prepackaged version of Squid should refer to the package vendor for availability information on updated packages.

CVSS3: 8.6
0%
Низкий
больше 1 года назад
debian логотип
CVE-2023-46724

Squid is a caching proxy for the Web. Due to an Improper Validation of ...

CVSS3: 8.6
0%
Низкий
больше 1 года назад
fstec логотип
BDU:2023-08581

Уязвимость прокси-сервера Squid, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.6
10%
Низкий
больше 1 года назад
fstec логотип
BDU:2023-07699

Уязвимость прокси-сервера Squid, связанная с ошибками при проверке сертификата SSL/TLS, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 8.6
0%
Низкий
больше 1 года назад
redos логотип
ROS-20240725-02

Уязвимость squid

CVSS3: 8.6
0%
Низкий
11 месяцев назад
suse-cvrf логотип
SUSE-SU-2023:4384-1

Security update for squid

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2023:4381-1

Security update for squid

больше 1 года назад
suse-cvrf логотип
SUSE-SU-2023:4380-1

Security update for squid

больше 1 года назад

Уязвимостей на страницу