Releases12
Frequency1 month 3 weeks
Last Release
Minimalistic StatsD client for Node.js programs

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
<= 2.8.95.3 MEDIUM2.6 LOW

Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.

< 1.0.02.1 LOW

The lynx gem before 1.0.0 for Ruby places the configured password on command lines, which allows local users to obtain sensitive information by listing processes.

= 2.8.95 MEDIUM

Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself.

all versions5 MEDIUM

lynx: It was found that Lynx doesn't parse the authority component of the URL correctly when the host name part ends with '?', and could instead be tricked into connecting to a different host.