Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2021-38165
Disclosure Date: August 07, 2021 (last updated February 23, 2025)
Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.
0
Attacker Value
Unknown
CVE-2014-5002
Disclosure Date: January 10, 2018 (last updated November 26, 2024)
The lynx gem before 1.0.0 for Ruby places the configured password on command lines, which allows local users to obtain sensitive information by listing processes.
0
Attacker Value
Unknown
CVE-2017-1000211
Disclosure Date: November 17, 2017 (last updated November 26, 2024)
Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself.
0
Attacker Value
Unknown
CVE-1999-1549
Disclosure Date: November 16, 1999 (last updated February 22, 2025)
Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modify the user's configuration file and execute commands.
0