Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2004-0918

25
FAUCET Score

CVE-2004-0918 is a denial-of-service vulnerability in the SNMP module of Squid Web Proxy Cache versions prior to 2.4.STABLE7, affecting products like Gentoo, Red Hat, and Ubuntu. Attackers can exploit this remotely with low complexity by sending specially crafted SNMP packets containing negative length fields, leading to a server restart due to a memory allocation error. While there is no known active exploitation or public exploit code, the vulnerability has a high EPSS score and significant community discussion, indicating potential interest despite its age.

Impacted Technologies

VendorProductVersion(s)CPE
2.1CPE matchmatch criteria
cpe:2.3:a:openpkg:openpkg:2.1:*:*:*:*:*:*:*
2.2CPE matchmatch criteria
cpe:2.3:a:openpkg:openpkg:2.2:*:*:*:*:*:*:*
currentCPE matchmatch criteria
cpe:2.3:a:openpkg:openpkg:current:*:*:*:*:*:*:*
2.0_patch2CPE matchmatch criteria
cpe:2.3:a:squid:squid:2.0_patch2:*:*:*:*:*:*:*
2.1_patch2CPE matchmatch criteria
cpe:2.3:a:squid:squid:2.1_patch2:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.0MEDIUM

AV:N/AC:L/Au:N/C:N/I:N/A:P

Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
16.03%
Probability of exploitation in next 30 days
EPSS Percentile
96.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.1603 is in the 96th percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: squid-7:2.5.STABLE3-6.3E.2
View patch

Vendor Advisories (1)

redhatCVE-2004-0918Important

Squid SNMP DoS

Oct 11, 2004

References

ftp.sco.com / pub/updates/UnixWare/SCOSA-2005.16/SCOSA-2005.16.txt
distro.conectiva.com.br / atualizacoes
fedoranews.org / updates/FEDORA--.shtml
lists.opensuse.org / opensuse-security-announce/2008-07/msg00001.html
marc.info
secunia.com / advisories/30914
Vendor Advisory
secunia.com / advisories/30967
Vendor Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/17688
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10931
redhat.com / archives/fedora-package-announce/2008-July/msg00122.html
gentoo.org / security/en/glsa/glsa-200410-15.xml
idefense.com / application/poi/display
redhat.com / support/errata/RHSA-2004-591.html
PatchVendor Advisory
securityfocus.com / bid/11385
PatchVendor Advisory
squid-cache.org / Advisories/SQUID-2004_3.txt
squid-cache.org / Advisories/SQUID-2008_1.txt
vupen.com / english/advisories/2008/1969/references
Vendor Advisory