Vulnerabilities
Vulnerable Software
Lynx Project:  Security Vulnerabilities
Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.
CVSS Score
5.3
EPSS Score
0.029
Published
2021-08-07
The lynx gem before 1.0.0 for Ruby places the configured password on command lines, which allows local users to obtain sensitive information by listing processes.
CVSS Score
7.8
EPSS Score
0.001
Published
2018-01-10
Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself.
CVSS Score
5.3
EPSS Score
0.004
Published
2017-11-17
Lynx 2.x does not properly distinguish between internal and external HTML, which may allow a local attacker to read a "secure" hidden form value from a temporary file and craft a LYNXOPTIONS: URL that causes Lynx to modify the user's configuration file and execute commands.
CVSS Score
7.8
EPSS Score
0.002
Published
1999-11-16


Contact Us

Shodan ® - All rights reserved