NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 26449 | CVE-2015-5245 | CRLF injection vulnerability in the Ceph Object Gateway (aka radosgw or RGW) in Ceph before 0.94.4 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted bucket name. | 2 | 4.3 | Medium | 2017-01-19 | 2015-12-04 | View | |
| 11533 | CVE-2011-5279 | CRLF injection vulnerability in the CGI implementation in Microsoft Internet Information Services (IIS) 4.x and 5.x on Windows NT and Windows 2000 allows remote attackers to modify arbitrary uppercase environment variables via a (newline) character in an HTTP header. | 2 | 6.4 | Medium | 2017-01-07 | 2016-09-09 | View | |
| 18224 | CVE-2016-1900 | CRLF injection vulnerability in the cgit_print_http_headers function in ui-shared.c in CGit before 0.12 allows remote attackers with permission to write to a repository to inject arbitrary HTTP headers and conduct HTTP response splitting attacks or cross-site scripting (XSS) attacks via newline characters in a filename. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 17151 | CVE-2016-0789 | CRLF injection vulnerability in the CLI command documentation in Jenkins before 1.650 and LTS before 1.642.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-19 | 2016-07-14 | View | |
| 66836 | CVE-2005-1087 | CRLF injection vulnerability in the cmdIS.DLL plugin for AN HTTPD Server 1.42n allows remote attackers to spoof or hide entries in the logfile, and possibly read files using an injected type command, via CRLF sequences in an HTTP request. | 2 | 6.4 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 2722 of 17672, showing 5 records out of 88360 total, starting on record 13606, ending on 13610