Sarg is a web reporting and analysis tool for Squid proxy logs, with its vulnerability footprint centered on the core reporting application. The durable signal reflects application-layer weaknesses including buffer-boundary handling issues and cross-site scripting in report generation, which are characteristic of text-processing and HTML output routines. Current exploitation activity, severity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sarg over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-1167HIGH Stack-based buffer overflow in the useragent function in useragent.c in Squid Analysis Report Generator (Sarg) 2.2.3.1 allows remote attackers to execute arbitrary code via a long | Mar 5, 2008 | 10.0 | 27 | NO | NO |
CVE-2008-1922HIGH Multiple stack-based buffer overflows in Sarg might allow attackers to execute arbitrary code via unknown vectors, probably a crafted Squid log file. | May 13, 2008 | 10.0 | 26 | NO | NO |
CVE-2008-1168MEDIUM Cross-site scripting (XSS) vulnerability in Squid Analysis Report Generator (Sarg) 2.2.3.1 allows remote attackers to inject arbitrary web script or HTML via the User-Agent header, | Mar 5, 2008 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sarg.
Media articles that mention a CVE ID that affects a product developed by Sarg — matched by CVE ID, not by vendor name.