Vulnerabilities (CVE)

Filtered by CWE-113
Total 83 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2015-1445 1 Fli4l 1 Fli4l 2026-06-17 9.0 HIGH 7.2 HIGH
HTTP header injection in the httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30.
CVE-2015-0733 1 Cisco 1 Headend Digital Broadband Delivery System 2026-06-17 4.3 MEDIUM N/A
CRLF injection vulnerability in the HTTP Header Handler in Digital Broadband Delivery System in Cisco Headend System Release allows remote attackers to inject arbitrary HTTP headers, and conduct HTTP response splitting attacks or cross-site scripting (XSS) attacks, via a crafted request, aka Bug ID CSCur25580.
CVE-2007-5595 1 Drupal 1 Drupal 2026-06-16 5.1 MEDIUM N/A
CRLF injection vulnerability in the drupal_goto function in includes/common.inc Drupal 4.7.x before 4.7.8 and 5.x before 5.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.