elinks records
7 published records for vendor elinks.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-134 Use of Externally-Controlled Format String1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-287 Improper Authentication1
- CWE-295 Improper Certificate Validation1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2006-5925Proof of concept | Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharacelinks · elinks | High7.5 | — | 8.3% | Nov 15, 2006 |
32Monitor | CVE-2008-7224No exploit | Buffer overflow in entity_cache in ELinks before 0.11.4rc0 allows remote attackers to cause a denial of service (crash) via a crafted link.elinks · elinks · CWE-119 | High7.8 | — | 2.8% | Sep 14, 2009 |
23Monitor | CVE-2012-6709No exploit | ELinks 0.12 and Twibright Links 2.3 have Missing SSL Certificate Validation.elinks · elinks · CWE-295 | Medium5.9 | — | 0.6% | Feb 23, 2018 |
22Monitor | CVE-2002-1405Proof of concept | CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is proelinks · elinks | Medium5.0 | — | 5.0% | Feb 19, 2003 |
21Monitor | CVE-2012-4545No exploit | The http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GSelinks · elinks · CWE-287 | Medium5.1 | — | 1.9% | Jan 2, 2013 |
18Monitor | CVE-2007-5034No exploit | ELinks before 0.11.3, when sending a POST request for an https URL, appends the body and content headers of the POST request to the CONNECT elinks · elinks · CWE-200 | Medium4.3 | — | 2.6% | Sep 21, 2007 |
17Monitor | CVE-2007-2027Proof of concept | Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local userselinks · elinks · CWE-134 | Medium4.4 | — | 0.8% | Apr 13, 2007 |
- CVE-2006-592532Monitor
Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharac
HighCVSS 7.5Proof of conceptEPSS 8%elinks · elinksNov 15, 2006
- CVE-2008-722432Monitor
Buffer overflow in entity_cache in ELinks before 0.11.4rc0 allows remote attackers to cause a denial of service (crash) via a crafted link.
HighCVSS 7.8No exploitEPSS 3%elinks · elinksSep 14, 2009
- CVE-2012-670923Monitor
ELinks 0.12 and Twibright Links 2.3 have Missing SSL Certificate Validation.
MediumCVSS 5.9No exploitEPSS 1%elinks · elinksFeb 23, 2018
- CVE-2002-140522Monitor
CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is pro
MediumCVSS 5.0Proof of conceptEPSS 5%elinks · elinksFeb 19, 2003
- CVE-2012-454521Monitor
The http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GS
MediumCVSS 5.1No exploitEPSS 2%elinks · elinksJan 2, 2013
- CVE-2007-503418Monitor
ELinks before 0.11.3, when sending a POST request for an https URL, appends the body and content headers of the POST request to the CONNECT
MediumCVSS 4.3No exploitEPSS 3%elinks · elinksSep 21, 2007
- CVE-2007-202717Monitor
Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local users
MediumCVSS 4.4Proof of conceptEPSS 1%elinks · elinksApr 13, 2007