Vulnerability Database

290,476

Total vulnerabilities in the database

CVE-2007-2404

CRLF injection vulnerability in CFNetwork on Apple Mac OS X 10.3.9 and 10.4.10 before 20070731 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in an unspecified context. NOTE: this can be leveraged for cross-site scripting (XSS) attacks.

  • Published: Aug 3, 2007
  • Updated: Apr 13, 2023
  • CVE: CVE-2007-2404
  • Severity: Medium
  • Exploit:

CVSS v2:

  • Severity: Medium
  • Score: 5
  • AV:N/AC:L/Au:N/C:N/I:P/A:N

No CWE or OWASP classifications available.

Software From Fixed in
apple / mac_os_x 10.4.3 10.4.3.x
apple / mac_os_x_server 10.4.3 10.4.3.x
apple / mac_os_x_server 10.3.2 10.3.2.x
apple / mac_os_x_server 10.4.10 10.4.10.x
apple / mac_os_x_server 10.4.9 10.4.9.x
apple / mac_os_x_server 10.3.7 10.3.7.x
apple / mac_os_x_server 10.3.5 10.3.5.x
apple / mac_os_x 10.3.1 10.3.1.x
apple / mac_os_x 10.3.5 10.3.5.x
apple / mac_os_x 10.4.1 10.4.1.x
apple / mac_os_x_server 10.4.2 10.4.2.x
apple / mac_os_x_server 10.3.3 10.3.3.x
apple / mac_os_x_server 10.4.4 10.4.4.x
apple / mac_os_x 10.4.10 10.4.10.x
apple / mac_os_x_server 10.4.1 10.4.1.x
apple / mac_os_x 10.4.9 10.4.9.x
apple / mac_os_x 10.4.7 10.4.7.x
apple / mac_os_x 10.4.4 10.4.4.x
apple / mac_os_x_server 10.3.4 10.3.4.x
apple / mac_os_x 10.3.2 10.3.2.x
apple / mac_os_x 10.3.7 10.3.7.x
apple / mac_os_x_server 10.4 10.4.x
apple / mac_os_x_server 10.4.5 10.4.5.x
apple / mac_os_x 10.3.6 10.3.6.x
apple / mac_os_x_server 10.3 10.3.x
apple / mac_os_x_server 10.3.8 10.3.8.x
apple / mac_os_x 10.4 10.4.x
apple / mac_os_x_server 10.4.6 10.4.6.x
apple / mac_os_x_server 10.3.9 10.3.9.x
apple / mac_os_x_server 10.4.8 10.4.8.x
apple / mac_os_x 10.4.6 10.4.6.x
apple / mac_os_x 10.3.8 10.3.8.x
apple / mac_os_x_server 10.3.1 10.3.1.x
apple / mac_os_x 10.4.5 10.4.5.x
apple / mac_os_x 10.3.9 10.3.9.x
apple / mac_os_x 10.3.4 10.3.4.x
apple / mac_os_x 10.4.8 10.4.8.x
apple / mac_os_x 10.3.3 10.3.3.x
apple / mac_os_x_server 10.4.7 10.4.7.x
apple / mac_os_x 10.4.2 10.4.2.x
apple / mac_os_x 10.3 10.3.x
apple / mac_os_x_server 10.3.6 10.3.6.x