CVE-2023-46847High· 8.6▾ TwilightSquid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.3 · likelihood 17.7 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
88%
Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.
squid >= 3.2.0.1, < 6.4enterprise_linux = 8.0enterprise_linux = 9.0enterprise_linux_eus = 8.6enterprise_linux_eus = 8.8enterprise_linux_eus = 9.0enterprise_linux_eus = 9.2enterprise_linux_for_arm_64 = 8.0_aarch64enterprise_linux_for_ibm_z_systems = 8.0_s390xenterprise_linux_for_power_little_endian = 8.0_ppc64leenterprise_linux_server = 7.0enterprise_linux_server_aus = 8.2enterprise_linux_server_aus = 8.4enterprise_linux_server_aus = 8.6enterprise_linux_server_aus = 9.2enterprise_linux_server_tus = 8.2enterprise_linux_server_tus = 8.4enterprise_linux_server_tus = 8.6enterprise_linux_server_tus = 8.8enterprise_linux_server_tus = 9.2enterprise_linux_workstation = 7.0Upgrade past the affected range:
squid 6.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-50012Medium· 5.5Squid is a caching proxy for the Web
CVE-2026-47729Medium· 6.5Squid is a caching proxy for the Web
CVE-2024-5974High· 7.2A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary code with system privileges on the firewall. This issue affects Fireware OS: from 11.9.6 …
CVE-2026-30652High· 8.8A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras running firmware version FD8136-VVTK-0300a
CVE-2023-27972Critical· 9.8Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Remote Code Execution.
CVE-2023-27971Critical· 9.8Certain HP LaserJet Pro print products are potentially vulnerable to Buffer Overflow and/or Elevation of Privilege.