ELinks 0.12 and Twibright Links 2.3 have Missing SSL Certificate Validation.
📦
links
Vendor: twibright
Actively Exploited
0
CISA KEV List
PoC / Exploits
0
Code Available
Total RCEs
0
Remote Access
Total CVEs
21
Total Indexed
Avg. EPSS
0.29%
Exploit Prob.
Security Vulnerability Index
Page 1 / 3
5.9
CVSS
Severity: MEDIUM
5.5
CVSS
The put_chars function in html_r.c in Twibright Links 2.14 allows remote attackers to cause a denial of service (buffer over-read) via a crafted HTML file.
Severity: MEDIUM
4.3
CVSS
Integer overflow in Links before 2.8 allows remote attackers to cause a denial of service (crash) via crafted HTML tables.
Severity: MEDIUM
9.3
CVSS
Unspecified vulnerability in Links before 2.1, when "only proxies" is enabled, has unknown impact and attack vectors related to providing "URLs to external programs."
Severity: HIGH