elinks kayıtları
elinks üreticisine ait 7 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-134 Use of Externally-Controlled Format String1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-287 Improper Authentication1
- CWE-295 Improper Certificate Validation1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
7 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
32İzleyin | CVE-2006-5925Kavram kanıtı | Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharacelinks · elinks | Yüksek7,5 | — | %8,3 | 15 Kas 2006 |
32İzleyin | CVE-2008-7224İstismar yok | Buffer overflow in entity_cache in ELinks before 0.11.4rc0 allows remote attackers to cause a denial of service (crash) via a crafted link.elinks · elinks · CWE-119 | Yüksek7,8 | — | %2,8 | 14 Eyl 2009 |
23İzleyin | CVE-2012-6709İstismar yok | ELinks 0.12 and Twibright Links 2.3 have Missing SSL Certificate Validation.elinks · elinks · CWE-295 | Orta5,9 | — | %0,6 | 23 Şub 2018 |
22İzleyin | CVE-2002-1405Kavram kanıtı | CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is proelinks · elinks | Orta5,0 | — | %5,0 | 19 Şub 2003 |
21İzleyin | CVE-2012-4545İstismar yok | The http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GSelinks · elinks · CWE-287 | Orta5,1 | — | %1,9 | 2 Oca 2013 |
18İzleyin | CVE-2007-5034İstismar yok | ELinks before 0.11.3, when sending a POST request for an https URL, appends the body and content headers of the POST request to the CONNECT elinks · elinks · CWE-200 | Orta4,3 | — | %2,6 | 21 Eyl 2007 |
17İzleyin | CVE-2007-2027Kavram kanıtı | Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local userselinks · elinks · CWE-134 | Orta4,4 | — | %0,8 | 13 Nis 2007 |
- CVE-2006-592532İzleyin
Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharac
YüksekCVSS 7,5Kavram kanıtıEPSS %8elinks · elinks15 Kas 2006
- CVE-2008-722432İzleyin
Buffer overflow in entity_cache in ELinks before 0.11.4rc0 allows remote attackers to cause a denial of service (crash) via a crafted link.
YüksekCVSS 7,8İstismar yokEPSS %3elinks · elinks14 Eyl 2009
- CVE-2012-670923İzleyin
ELinks 0.12 and Twibright Links 2.3 have Missing SSL Certificate Validation.
OrtaCVSS 5,9İstismar yokEPSS %1elinks · elinks23 Şub 2018
- CVE-2002-140522İzleyin
CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is pro
OrtaCVSS 5,0Kavram kanıtıEPSS %5elinks · elinks19 Şub 2003
- CVE-2012-454521İzleyin
The http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GS
OrtaCVSS 5,1İstismar yokEPSS %2elinks · elinks2 Oca 2013
- CVE-2007-503418İzleyin
ELinks before 0.11.3, when sending a POST request for an https URL, appends the body and content headers of the POST request to the CONNECT
OrtaCVSS 4,3İstismar yokEPSS %3elinks · elinks21 Eyl 2007
- CVE-2007-202717İzleyin
Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local users
OrtaCVSS 4,4Kavram kanıtıEPSS %1elinks · elinks13 Nis 2007