← Back

Lynx Project

lynx_project

4 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Lynx
lynx

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
FedoraprojectLynx Project
3Debian Linux
FedoraLynx
Jun 17, 2026
Aug 7, 2021
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.
1Lynx Project
1Lynx
Nov 21, 2024
Jan 10, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
The lynx gem before 1.0.0 for Ruby places the configured password on command lines, which allows local users to obtain sensitive information by listing processes.
1Lynx Project
1Lynx
May 13, 2026
Nov 17, 2017
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself.
1Lynx Project
1Lynx
Apr 16, 2026
Nov 16, 1999
N/A· v4
7.8 HIGH· v3
5.0 MEDIUM· v2
Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modi...Show more
Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modify the user's configuration file and execute commands.Show less