Show filters
27 Total Results
Displaying 11-20 of 27
Sort by:
Attacker Value
Unknown
CVE-2016-8361
Disclosure Date: February 13, 2017 (last updated November 26, 2024)
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application uses a hard-coded username with no password allowing an attacker into the system without authentication.
0
Attacker Value
Unknown
CVE-2016-8369
Disclosure Date: February 13, 2017 (last updated November 26, 2024)
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application does not sufficiently verify if a request was intentionally provided by the user who submitted the request (CROSS-SITE REQUEST FORGERY).
0
Attacker Value
Unknown
CVE-2016-9179
Disclosure Date: December 22, 2016 (last updated November 25, 2024)
lynx: It was found that Lynx doesn't parse the authority component of the URL correctly when the host name part ends with '?', and could instead be tricked into connecting to a different host.
0
Attacker Value
Unknown
CVE-2012-5821
Disclosure Date: November 04, 2012 (last updated February 09, 2024)
Lynx does not verify that the server's certificate is signed by a trusted certification authority, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate, related to improper use of a certain GnuTLS function.
0
Attacker Value
Unknown
CVE-2010-2810
Disclosure Date: August 20, 2010 (last updated October 04, 2023)
Heap-based buffer overflow in the convert_to_idna function in WWW/Library/Implementation/HTParse.c in Lynx 2.8.8dev.1 through 2.8.8dev.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed URL containing a % (percent) character in the domain name.
0
Attacker Value
Unknown
CVE-2006-7234
Disclosure Date: October 27, 2008 (last updated October 04, 2023)
Untrusted search path vulnerability in Lynx before 2.8.6rel.4 allows local users to execute arbitrary code via malicious (1) .mailcap and (2) mime.types files in the current working directory.
0
Attacker Value
Unknown
CVE-2008-4690
Disclosure Date: October 22, 2008 (last updated October 04, 2023)
lynx 2.8.6dev.15 and earlier, when advanced mode is enabled and lynx is configured as a URL handler, allows remote attackers to execute arbitrary commands via a crafted lynxcgi: URL, a related issue to CVE-2005-2929. NOTE: this might only be a vulnerability in limited deployments that have defined a lynxcgi: handler.
0
Attacker Value
Unknown
CVE-2006-6207
Disclosure Date: December 01, 2006 (last updated November 08, 2023)
SQL injection vulnerability in products.asp in Evolve shopping cart (aka Evolve Merchant) allows remote attackers to execute arbitrary SQL commands via the partno parameter. NOTE: the vendor disputes this issue, stating that it is a forced SQL error
0
Attacker Value
Unknown
CVE-2006-5953
Disclosure Date: November 17, 2006 (last updated October 04, 2023)
SQL injection vulnerability in viewcart.asp in Evolve shopping cart (aka Evolve Merchant) allows remote attackers to execute arbitrary SQL commands via the zoneid parameter.
0
Attacker Value
Unknown
CVE-2005-0657
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Directory traversal vulnerability in Computalynx CProxy 3.3.x and 3.4.x through 3.4.4 allows remote attackers to read arbitrary files or cause a denial of service (application crash) via a .. (dot dot) in an HTTP request.
0