CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.0. It may be remotely exploitable.
CVE
CVE-2007-2404
Severity
MEDIUM
CVSS
5
EPSS
1.40%
Original NVD Description
CRLF injection vulnerability in CFNetwork on Apple Mac OS X 10.3.9 and 10.4.10 before 20070731 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in an unspecified context. NOTE: this can be leveraged for cross-site scripting (XSS) attacks.