CVE-2023-46847
Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary d
CVSS
8.6
High
EPSS
88.4%
p100
KEV
—
Exploit Today
30
0-100
Published: Nov 3, 2023 · Last modified: Aug 7, 2026 · CWE-120
88.4%EPSS · 30 days88.4%
2026-08-022026-08-31
Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2023:6266
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2023:6267
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2023:6268
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2023:6748
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2023:6801
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2023:6803
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2023:6804
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2023:6805
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2023:6810
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2023:6882
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2023:6884
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2023:7213
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2023:7576
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2023:7578
- access.redhat.comhttps://access.redhat.com/security/cve/CVE-2023-46847
- bugzilla.redhat.comhttps://bugzilla.redhat.com/show_bug.cgi?id=2245916
- github.comhttps://github.com/squid-cache/squid/security/advisories/GHSA-phqj-m8gv-cq4g
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2023:6266
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2023:6267
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2023:6268
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-8254210.0 CRI48.4%
——15A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.1dCVE-2026-824796.3 MED16.7%
——5A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is the function OS_read of the file modules/protocol/tcp/fsw/src/sbn_tcp_if.c of the component SBN TCP Module. Such manipulation of the argument MsgSz leads to buffer overflow. The attack must be carried out from within the local network. The vendor was contacted early about this disclosure but did not respond in any way.1dCVE-2026-823436.1 MED1.8%
——1A flaw was found in the file-psd plugin in GIMP. When processing a specially crafted PSD image file, the plugin does not properly validate the channel-count parameter. This incorrect validation leads to improper memory bounds checking, resulting in both a heap out-of-bounds read and a stack out-of-bounds access. This issue can result in an application crash, leading to a denial of service or a limited information disclosure of memory contents.3dCVE-2026-751247.5 HIG39.8%
——12PLANET GS-4210-16P2S firmware before 3.441b260626 contains a pre-authentication memory corruption vulnerability in the web management interface where the _readHttpParam function copies an oversized HTTP query string without guaranteeing NUL termination, allowing parse_query_string to process attacker-controlled data into a fixed-size stack buffer. An unauthenticated remote attacker can send an oversized GET request to dispatcher.cgi to cause denial of service of the web management interface and potentially trigger memory corruption.3dCVE-2026-801867.6 HIG33.7%
——10A stack-based buffer overflow vulnerability exists in BlueZ, the Linux Bluetooth protocol stack. A remote user within Bluetooth radio range can send a specially crafted Extended Inquiry Response (EIR) packet that causes a buffer overflow when the target device performs Bluetooth discovery. This vulnerability can lead to a Denial of Service (DoS) by crashing the bluetoothd service and may allow for arbitrary code execution.3dCVE-2026-647055.5 MED1.7%
——1A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7. An app may be able to cause unexpected system termination or write kernel memory.4d