Записи elinks
7 опубликованных записей вендора elinks.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-134 Use of Externally-Controlled Format String1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-287 Improper Authentication1
- CWE-295 Improper Certificate Validation1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
7 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
32Наблюдать | CVE-2006-5925Proof of concept | Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharacelinks · elinks | Высокая7,5 | — | 8,3 % | 15 нояб. 2006 г. |
32Наблюдать | CVE-2008-7224Эксплойта нет | Buffer overflow in entity_cache in ELinks before 0.11.4rc0 allows remote attackers to cause a denial of service (crash) via a crafted link.elinks · elinks · CWE-119 | Высокая7,8 | — | 2,8 % | 14 сент. 2009 г. |
23Наблюдать | CVE-2012-6709Эксплойта нет | ELinks 0.12 and Twibright Links 2.3 have Missing SSL Certificate Validation.elinks · elinks · CWE-295 | Средняя5,9 | — | 0,6 % | 23 февр. 2018 г. |
22Наблюдать | CVE-2002-1405Proof of concept | CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is proelinks · elinks | Средняя5,0 | — | 5,0 % | 19 февр. 2003 г. |
21Наблюдать | CVE-2012-4545Эксплойта нет | The http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GSelinks · elinks · CWE-287 | Средняя5,1 | — | 1,9 % | 2 янв. 2013 г. |
18Наблюдать | CVE-2007-5034Эксплойта нет | ELinks before 0.11.3, when sending a POST request for an https URL, appends the body and content headers of the POST request to the CONNECT elinks · elinks · CWE-200 | Средняя4,3 | — | 2,6 % | 21 сент. 2007 г. |
17Наблюдать | CVE-2007-2027Proof of concept | Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local userselinks · elinks · CWE-134 | Средняя4,4 | — | 0,8 % | 13 апр. 2007 г. |
- CVE-2006-592532Наблюдать
Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharac
ВысокаяCVSS 7,5Proof of conceptEPSS 8 %elinks · elinks15 нояб. 2006 г.
- CVE-2008-722432Наблюдать
Buffer overflow in entity_cache in ELinks before 0.11.4rc0 allows remote attackers to cause a denial of service (crash) via a crafted link.
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %elinks · elinks14 сент. 2009 г.
- CVE-2012-670923Наблюдать
ELinks 0.12 and Twibright Links 2.3 have Missing SSL Certificate Validation.
СредняяCVSS 5,9Эксплойта нетEPSS 1 %elinks · elinks23 февр. 2018 г.
- CVE-2002-140522Наблюдать
CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is pro
СредняяCVSS 5,0Proof of conceptEPSS 5 %elinks · elinks19 февр. 2003 г.
- CVE-2012-454521Наблюдать
The http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GS
СредняяCVSS 5,1Эксплойта нетEPSS 2 %elinks · elinks2 янв. 2013 г.
- CVE-2007-503418Наблюдать
ELinks before 0.11.3, when sending a POST request for an https URL, appends the body and content headers of the POST request to the CONNECT
СредняяCVSS 4,3Эксплойта нетEPSS 3 %elinks · elinks21 сент. 2007 г.
- CVE-2007-202717Наблюдать
Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local users
СредняяCVSS 4,4Proof of conceptEPSS 1 %elinks · elinks13 апр. 2007 г.