← Back

Lynx

lynx

Vendor: Lynx • 5 CVEs

CVEs (5)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Lynx
1Lynx
May 6, 2026
Dec 22, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
lynx: It was found that Lynx doesn't parse the authority component of the URL correctly when the host name part ends with '?', and could instead be tricked into connecting to a different host.
2Canonical
Lynx
2Lynx
Ubuntu Linux
Apr 29, 2026
Nov 4, 2012
N/A· v4
5.9 MEDIUM· v3
5.8 MEDIUM· v2
Lynx does not verify that the server's certificate is signed by a trusted certification authority, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate, related to improper use of a cer...Show more
Lynx does not verify that the server's certificate is signed by a trusted certification authority, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate, related to improper use of a certain GnuTLS function.Show less
1Lynx
1Lynx
Apr 29, 2026
Aug 20, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in the convert_to_idna function in WWW/Library/Implementation/HTParse.c in Lynx 2.8.8dev.1 through 2.8.8dev.4 allows remote attackers to cause a denial of service (application crash) or possibl...Show more
Heap-based buffer overflow in the convert_to_idna function in WWW/Library/Implementation/HTParse.c in Lynx 2.8.8dev.1 through 2.8.8dev.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed URL containing a % (percent) character in the domain name.Show less
1Lynx
1Lynx
Apr 23, 2026
Oct 27, 2008
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Untrusted search path vulnerability in Lynx before 2.8.6rel.4 allows local users to execute arbitrary code via malicious (1) .mailcap and (2) mime.types files in the current working directory.
1Lynx
1Lynx
Apr 23, 2026
Oct 22, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
lynx 2.8.6dev.15 and earlier, when advanced mode is enabled and lynx is configured as a URL handler, allows remote attackers to execute arbitrary commands via a crafted lynxcgi: URL, a related issue to CVE-2005-2929. NO...Show more
lynx 2.8.6dev.15 and earlier, when advanced mode is enabled and lynx is configured as a URL handler, allows remote attackers to execute arbitrary commands via a crafted lynxcgi: URL, a related issue to CVE-2005-2929. NOTE: this might only be a vulnerability in limited deployments that have defined a lynxcgi: handler.Show less