NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
66836  CVE-2005-1087  CRLF injection vulnerability in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to spoof or hide entries in the logfile, and possibly read files using an injected type command, via CRLF sequences in an HTTP request.    6.4  Medium  2017-07-18  2017-07-10  View
17151  CVE-2016-0789  CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.    4.3  Medium  2017-01-19  2016-07-14  View
18224  CVE-2016-1900  CRLF injection vulnerability in the cgit_print_http_headers function in ui-shared.c in CGit before 0.12 allows remote attackers with permission to write to a repository to inject arbitrary HTTP headers and conduct HTTP response splitting attacks or cross-site scripting (XSS) attacks via newline characters in a filename.    4.3  Medium  2017-01-19  2016-12-07  View
11533  CVE-2011-5279  CRLF injection vulnerability in the CGI implementation in Microsoft Internet Information Services (IIS) 4.x and 5.x on Windows NT and Windows 2000 allows remote attackers to modify arbitrary uppercase environment variables via a (newline) character in an HTTP header.    6.4  Medium  2017-01-07  2016-09-09  View
26449  CVE-2015-5245  CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or RGW) in Ceph before 0.94.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted bucket name.    4.3  Medium  2017-01-19  2015-12-04  View

Page 14951 of 17672, showing 5 records out of 88360 total, starting on record 74751, ending on 74755

Actions