VDB

CVE-2004-0541

CVE-2004-0541 PUBLISHED CVSS 10 CRITICAL

Buffer overflow in the ntlm_check_auth (NTLM authentication) function for Squid Web Proxy Cache 2.5.x and 3.x, when compiled with NTLM handlers enabled, allows remote attackers to execute arbitrary code via a long password ("pass" variable).

EPSS 71.07% · 99.3th percentile

Risk Scores

CVSS 2.0
10
EPSS Score
71.07%
99.3th percentile

Affected Products

VendorProductVersions
national_science_foundationsquid_web_proxy_cache2.5_stable, *
n/an/a*

Timeline

  • Jun 10, 2004 CVE Published
  • Apr 30, 2010 PoC Published
  • May 29, 2018 PoC Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Oct 27, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Apr 3, 2023 EPSS Score
  • May 26, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›