CVE-2005-0174 describes a cache poisoning vulnerability affecting Squid proxy versions up to 2.5.STABLE7. This flaw allows remote attackers to manipulate cached content or launch other attacks by sending malformed HTTP headers, such as multiple Content-Length headers, lone carriage returns, or header names with whitespace. With a CVSS score of 5.0, this vulnerability is easily exploitable over the network without authentication, potentially leading to data integrity issues. Despite its age and high FAUCET Risk Score of 98/100, there is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.5.6CPE matchmatch criteria | cpe:2.3:a:squid:squid:2.5.6:*:*:*:*:*:*:* | ||
2.5.stable1CPE matchmatch criteria | cpe:2.3:a:squid:squid:2.5.stable1:*:*:*:*:*:*:* | ||
2.5.stable2CPE matchmatch criteria | cpe:2.3:a:squid:squid:2.5.stable2:*:*:*:*:*:*:* | ||
2.5.stable3CPE matchmatch criteria | cpe:2.3:a:squid:squid:2.5.stable3:*:*:*:*:*:*:* | ||
2.5.stable4CPE matchmatch criteria | cpe:2.3:a:squid:squid:2.5.stable4:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:P/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.