Search CVE reports


Toggle filters

1 – 10 of 10 results


CVE-2021-38165

Medium priority

Some fixes available 3 of 4

Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.

1 affected package

lynx

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
lynx Not affected Not affected Fixed Fixed Fixed
Show less packages

CVE-2017-1000211

Medium priority

Some fixes available 1 of 2

Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself.

1 affected package

lynx

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
lynx Not affected Not affected Not affected Fixed
Show less packages

CVE-2016-9179

Low priority

Some fixes available 1 of 5

lynx: It was found that Lynx doesn't parse the authority component of the URL correctly when the host name part ends with '?', and could instead be tricked into connecting to a different host.

2 affected packages

lynx, lynx-cur

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
lynx Not affected Not affected Not affected Fixed
lynx-cur Not in release Not in release Not in release Not in release
Show less packages

CVE-2012-5821

Medium priority

Some fixes available 4 of 6

Lynx does not verify that the server's certificate is signed by a trusted certification authority, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate, related to improper use of a...

2 affected packages

lynx, lynx-cur

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
lynx
lynx-cur
Show less packages

CVE-2010-2810

Low priority

Some fixes available 1 of 6

Heap-based buffer overflow in the convert_to_idna function in WWW/Library/Implementation/HTParse.c in Lynx 2.8.8dev.1 through 2.8.8dev.4 allows remote attackers to cause a denial of service (application crash) or possibly execute...

1 affected package

lynx-cur

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
lynx-cur
Show less packages

CVE-2006-7234

Low priority
Ignored

Untrusted search path vulnerability in Lynx before 2.8.6rel.4 allows local users to execute arbitrary code via malicious (1) .mailcap and (2) mime.types files in the current working directory.

1 affected package

lynx

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
lynx
Show less packages

CVE-2008-4690

Low priority
Ignored

lynx 2.8.6dev.15 and earlier, when advanced mode is enabled and lynx is configured as a URL handler, allows remote attackers to execute arbitrary commands via a crafted lynxcgi: URL, a related issue to CVE-2005-2929. NOTE: this...

1 affected package

lynx

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
lynx
Show less packages

CVE-2005-2929

Unknown priority
Not affected

Lynx 2.8.5, and other versions before 2.8.6dev.15, allows remote attackers to execute arbitrary commands via (1) lynxcgi:, (2) lynxexec, and (3) lynxprog links, which are not properly restricted in the default configuration in...

1 affected package

lynx

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
lynx
Show less packages

CVE-2005-3120

Unknown priority
Fixed

Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escape (ESC) characters.

2 affected packages

lynx, lynx-cur

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
lynx
lynx-cur
Show less packages

CVE-2004-1617

Unknown priority

Some fixes available 1 of 3

Lynx, lynx-ssl, and lynx-cur before 2.8.6dev.8 allow remote attackers to cause a denial of service (infinite loop) via a web page or HTML email that contains invalid HTML including (1) a TEXTAREA tag with a large COLS value and...

1 affected package

lynx

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS 16.04 LTS
lynx
Show less packages