📦

lynx

Vendor: university_of_kansas

Actively Exploited 0 CISA KEV List
PoC / Exploits 3 Code Available
Total RCEs 3 Remote Access
Total CVEs 15 Total Indexed
Avg. EPSS 3.86% Exploit Prob.
Latest CVE CVE-2021-38165 Aug 07

Security Vulnerability Index

Page 2 / 2
5.0 CVSS

Lynx, lynx-ssl, and lynx-cur before 2.8.6dev.8 allow remote attackers to cause a denial of service (infinite loop) via a web page or HTML email that contains invalid HTML including (1) a TEXTAREA tag with a large COLS value and (2) a large tag name in an element that is not terminated, as demonstrated by mangleme. NOTE: a followup suggests that the relevant trigger for this issue is the large COLS value.

EPSS: 3.75%
5.0 CVSS
CVE-2002-1405
Exploit Found

CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on the command line, via a URL containing encoded carriage return, line feed, and other whitespace characters.

EPSS: 5.04%
7.6 CVSS

Buffer overflow in Lynx 2.x allows remote attackers to crash Lynx and possibly execute commands via a long URL in a malicious web page.

EPSS: 2.08%
7.8 CVSS

Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modify the user's configuration file and execute commands.

EPSS: 0.58%
10.0 CVSS

Lynx WWW client allows a remote attacker to specify command-line parameters which Lynx uses when calling external programs to handle certain protocols, e.g. telnet.

EPSS: 3.10%
1.2 CVSS

Lynx allows a local user to overwrite sensitive files through /tmp symlinks.

EPSS: 0.30%