CVE-2005-0095 describes a denial-of-service vulnerability in Squid 2.5.STABLE7 and earlier, stemming from improper parsing of malformed WCCP messages. Attackers can exploit this by sending specially crafted WCCP messages with spoofed source addresses and invalid cache numbers, causing the Squid proxy server to crash. Rated with a CVSS score of 5.0, this vulnerability is easily exploitable over the network without authentication (AV:N/AC:L/Au:N), leading to a partial denial of service (A:P). Its high EPSS score of 0.758 and FAUCET Risk Score of 98/100 indicate a significant likelihood of exploitation. While there is no known public exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered substantial community attention with 10 mentions, suggesting ongoing discussion or interest. However, there is no indication of active exploitation or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0_patch2CPE matchmatch criteria | cpe:2.3:a:squid:squid:2.0_patch2:*:*:*:*:*:*:* | ||
2.1_patch2CPE matchmatch criteria | cpe:2.3:a:squid:squid:2.1_patch2:*:*:*:*:*:*:* | ||
2.3_.stable4CPE matchmatch criteria | cpe:2.3:a:squid:squid:2.3_.stable4:*:*:*:*:*:*:* | ||
2.3_.stable5CPE matchmatch criteria | cpe:2.3:a:squid:squid:2.3_.stable5:*:*:*:*:*:*:* | ||
2.3_stable5CPE matchmatch criteria | cpe:2.3:a:squid:squid:2.3_stable5:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.