3 results (0.004 seconds)

CVSS: 7.5EPSS: 25%CPEs: 1EXPL: 0

06 Dec 2001 — Squid proxy server 2.4 and earlier allows remote attackers to cause a denial of service (crash) via a mkdir-only FTP PUT request. • http://archives.neohapsis.com/archives/linux/conectiva/2001-q3/0020.html •

CVSS: 9.1EPSS: 5%CPEs: 5EXPL: 2

31 Dec 1999 — Squid 2.2.STABLE5 and below, when using external authentication, allows attackers to bypass access controls via a newline in the user/password pair. • https://www.exploit-db.com/exploits/19567 •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 1

20 Feb 1998 — Squid Internet Object Cache 1.1.20 allows users to bypass access control lists (ACLs) by encoding the URL with hexadecimal escape sequences. • http://www.securityfocus.com/archive/1/8551 •