VDB

CVE-2009-2621

CVE-2009-2621 PUBLISHED CVSS 5 MEDIUM

Squid 3.0 through 3.0.STABLE16 and 3.1 through 3.1.0.11 does not properly enforce "buffer limits and related bound checks," which allows remote attackers to cause a denial of service via (1) an incomplete request or (2) a request with a large header size, related to (a) HttpMsg.cc and (b) client_side.cc.

EPSS 23.56% · 96.1th percentile

Risk Scores

CVSS 2.0
5
EPSS Score
23.56%
96.1th percentile

Affected Products

VendorProductVersions
n/an/an/a
squid-cachesquid3.0, 3.0, 3.0

Timeline

  • Jul 28, 2009 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Apr 3, 2023 EPSS Score
  • May 25, 2023 EPSS Score
  • Jul 17, 2023 EPSS Score
  • Sep 8, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›