Elinks is a text-based web browser with a modestly represented vulnerability profile that clusters around its core product and its interaction with network protocols and authentication mechanisms. The recurring weakness classes—including improper certificate validation, improper authentication, and memory-buffer handling issues—reflect the complexities of TLS validation, credential management, and parsing in a browser implementation; these flaws frequently acquire public exploit code. Defenders should treat Elinks deployments in automated or headless contexts as a patching concern, particularly where the browser handles untrusted content; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Elinks over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-5925HIGH Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharacters in an smb:// URI, as demonstrated b | Nov 15, 2006 | 7.5 | 39 | NO | YES |
CVE-2002-1405MEDIUM CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on the command line, via a URL con | Feb 19, 2003 | 5.0 | 24 | NO | YES |
CVE-2008-7224HIGH Buffer overflow in entity_cache in ELinks before 0.11.4rc0 allows remote attackers to cause a denial of service (crash) via a crafted link. | Sep 14, 2009 | 7.8 | 23 | NO | NO |
CVE-2007-2027MEDIUM Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local users to cause Elinks to use an untrusted get | Apr 13, 2007 | 4.4 | 21 | NO | YES |
CVE-2012-6709MEDIUM ELinks 0.12 and Twibright Links 2.3 have Missing SSL Certificate Validation. | Feb 23, 2018 | 5.9 | 20 | NO | NO |
CVE-2012-4545MEDIUM The http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GSS-Negotiate authentication, delegates us | Jan 3, 2013 | 5.1 | 20 | NO | NO |
CVE-2007-5034MEDIUM ELinks before 0.11.3, when sending a POST request for an https URL, appends the body and content headers of the POST request to the CONNECT request in cleartext, which allows remot | Sep 21, 2007 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Elinks.
Media articles that mention a CVE ID that affects a product developed by Elinks — matched by CVE ID, not by vendor name.