Search CVE reports
1 – 6 of 6 results
CVE-2012-6709
Low priorityELinks 0.12 and Twibright Links 2.3 have Missing SSL Certificate Validation.
2 affected packages
elinks, links2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
elinks | Not affected | Not affected | Not affected | Vulnerable | Vulnerable |
links2 | Not affected | Not affected | Not affected | Not affected | Not affected |
CVE-2012-4545
Medium priorityThe http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GSS-Negotiate authentication, delegates user credentials through GSSAPI, which allows remote...
1 affected packages
elinks
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
elinks | — | — | — | — | Not affected |
CVE-2008-7224
Low priorityBuffer overflow in entity_cache in ELinks before 0.11.4rc0 allows remote attackers to cause a denial of service (crash) via a crafted link.
1 affected packages
elinks
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
elinks | — | — | — | — | — |
CVE-2007-5034
Unknown priorityELinks before 0.11.3, when sending a POST request for an https URL, appends the body and content headers of the POST request to the CONNECT request in cleartext, which allows remote attackers to sniff sensitive data that...
1 affected packages
elinks
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
elinks | — | — | — | — | — |
CVE-2007-2027
Unknown priorityUntrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local users to cause Elinks to use an untrusted gettext message catalog (.po file) in a...
1 affected packages
elinks
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
elinks | — | — | — | — | — |
CVE-2006-5925
Medium prioritySome fixes available 16 of 20
Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharacters in an smb:// URI, as demonstrated by using PUT and GET statements.
3 affected packages
elinks, links, links2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
elinks | — | — | — | — | — |
links | — | — | — | — | — |
links2 | — | — | — | — | — |