Squid before 2.3STABLE5 in HTTP accelerator mode does not enable access control lists (ACLs) when the httpdaccelhost and httpaccelwithproxy off settings are used, which allows attackers to bypass the ACLs and conduct unauthorized activities such as port scanning.
Squid proxy server 2.4 and earlier allows remote attackers to cause a denial of service (crash) via a mkdir-only FTP PUT request.