Search CVE reports
1 – 10 of 10 results
CVE-2021-38165
Medium prioritySome fixes available 3 of 4
Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.
1 affected package
lynx
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
lynx | Not affected | Not affected | Fixed | Fixed | Fixed |
CVE-2017-1000211
Medium prioritySome fixes available 1 of 2
Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself.
1 affected package
lynx
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
lynx | — | Not affected | Not affected | Not affected | Fixed |
CVE-2016-9179
Low prioritySome fixes available 1 of 5
lynx: It was found that Lynx doesn't parse the authority component of the URL correctly when the host name part ends with '?', and could instead be tricked into connecting to a different host.
2 affected packages
lynx, lynx-cur
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
lynx | — | Not affected | Not affected | Not affected | Fixed |
lynx-cur | — | Not in release | Not in release | Not in release | Not in release |
CVE-2012-5821
Medium prioritySome fixes available 4 of 6
Lynx does not verify that the server's certificate is signed by a trusted certification authority, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate, related to improper use of a...
2 affected packages
lynx, lynx-cur
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
lynx | — | — | — | — | — |
lynx-cur | — | — | — | — | — |
CVE-2010-2810
Low prioritySome fixes available 1 of 6
Heap-based buffer overflow in the convert_to_idna function in WWW/Library/Implementation/HTParse.c in Lynx 2.8.8dev.1 through 2.8.8dev.4 allows remote attackers to cause a denial of service (application crash) or possibly execute...
1 affected package
lynx-cur
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
lynx-cur | — | — | — | — | — |
CVE-2006-7234
Low priorityUntrusted search path vulnerability in Lynx before 2.8.6rel.4 allows local users to execute arbitrary code via malicious (1) .mailcap and (2) mime.types files in the current working directory.
1 affected package
lynx
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
lynx | — | — | — | — | — |
CVE-2008-4690
Low prioritylynx 2.8.6dev.15 and earlier, when advanced mode is enabled and lynx is configured as a URL handler, allows remote attackers to execute arbitrary commands via a crafted lynxcgi: URL, a related issue to CVE-2005-2929. NOTE: this...
1 affected package
lynx
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
lynx | — | — | — | — | — |
CVE-2005-2929
Unknown priorityLynx 2.8.5, and other versions before 2.8.6dev.15, allows remote attackers to execute arbitrary commands via (1) lynxcgi:, (2) lynxexec, and (3) lynxprog links, which are not properly restricted in the default configuration in...
1 affected package
lynx
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
lynx | — | — | — | — | — |
CVE-2005-3120
Unknown priorityStack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escape (ESC) characters.
2 affected packages
lynx, lynx-cur
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
lynx | — | — | — | — | — |
lynx-cur | — | — | — | — | — |
CVE-2004-1617
Unknown prioritySome fixes available 1 of 3
Lynx, lynx-ssl, and lynx-cur before 2.8.6dev.8 allow remote attackers to cause a denial of service (infinite loop) via a web page or HTML email that contains invalid HTML including (1) a TEXTAREA tag with a large COLS value and...
1 affected package
lynx
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
lynx | — | — | — | — | — |