Vulnerabilities > Improper Neutralization of CRLF Sequences ('CRLF Injection')

DATE CVE VULNERABILITY TITLE RISK
2019-08-26 CVE-2017-18587 CRLF Injection vulnerability in Hyper
An issue was discovered in the hyper crate before 0.9.18 for Rust.
network
low complexity
hyper CWE-93
5.3
2019-08-07 CVE-2016-10803 CRLF Injection vulnerability in Cpanel
cPanel before 57.9999.105 allows newline injection via LOC records (CPANEL-6923).
network
low complexity
cpanel CWE-93
7.5
2019-06-27 CVE-2018-6148 CRLF Injection vulnerability in Google Chrome
Incorrect implementation in Content Security Policy in Google Chrome prior to 67.0.3396.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
network
low complexity
google CWE-93
6.5
2019-05-17 CVE-2018-19585 CRLF Injection vulnerability in Gitlab
GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection in Project Mirroring when using the Git protocol.
network
low complexity
gitlab CWE-93
7.5
2019-04-30 CVE-2019-10272 CRLF Injection vulnerability in Weaver E-Cology 9.0
An issue was discovered in Weaver e-cology 9.0.
network
low complexity
weaver CWE-93
6.1
2019-04-15 CVE-2019-11236 CRLF Injection vulnerability in Python Urllib3
In the urllib3 library through 1.24.1 for Python, CRLF injection is possible if the attacker controls the request parameter.
network
low complexity
python CWE-93
6.1
2019-03-31 CVE-2019-10678 CRLF Injection vulnerability in Domoticz
Domoticz before 4.10579 neglects to categorize \n and \r as insecure argument options.
network
low complexity
domoticz CWE-93
7.5
2019-03-23 CVE-2019-9947 CRLF Injection vulnerability in Python
An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3.
network
low complexity
python CWE-93
6.1
2019-03-13 CVE-2019-9741 CRLF Injection vulnerability in multiple products
An issue was discovered in net/http in Go 1.11.5.
network
low complexity
golang debian fedoraproject redhat CWE-93
6.1
2019-03-13 CVE-2019-9740 CRLF Injection vulnerability in Python
An issue was discovered in urllib2 in Python 2.x through 2.7.16 and urllib in Python 3.x through 3.7.3.
network
low complexity
python CWE-93
6.1