dscape/lynx

dscape/lynx

Releases15
Frequency2 months 2 weeks
Last Release
Stars174
node.js client for Etsy'd StatsD server

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
<= 2.8.95.3 MEDIUM2.6 LOW

Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.

< 1.0.02.1 LOW

The lynx gem before 1.0.0 for Ruby places the configured password on command lines, which allows local users to obtain sensitive information by listing processes.

= 2.8.95 MEDIUM

Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself.

all versions5 MEDIUM

lynx: It was found that Lynx doesn't parse the authority component of the URL correctly when the host name part ends with '?', and could instead be tricked into connecting to a different host.

all versions5.9 MEDIUM5.8 MEDIUM

Lynx does not verify that the server's certificate is signed by a trusted certification authority, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate, related to improper use of a certain GnuTLS function.