Elinks

Vendor:

First CVE: Feb 19, 2003 · Active for 23 years

7
Total CVEs
More Total CVEs than 83% of tracked products
1.2
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
5.7
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Elinks over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 19, 2003
23 years ago
Most Recent CVE
Feb 23, 2018
3,073 days ago

CVE Severity & Scoring

Elinks7 CVEs
All CVEs352,294 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (14.3%)
Unknown6 (85.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High1 (14.3%)
Unknown6 (85.7%)
User Interaction
None1 (14.3%)
Unknown6 (85.7%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (14.3%)
Unknown6 (85.7%)

Top CVEs

Signals from CVEs in this product scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Links web browser 1.00pre12 and Elinks 0.9.2 with smbclient installed allows remote attackers to execute arbitrary code via shell metacharacters in an smb:// URI, as demonstrated b
Nov 15, 20067.539NOYES
CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on the command line, via a URL con
Feb 19, 20035.024NOYES
Buffer overflow in entity_cache in ELinks before 0.11.4rc0 allows remote attackers to cause a denial of service (crash) via a crafted link.
Sep 14, 20097.823NONO
Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local users to cause Elinks to use an untrusted get
Apr 13, 20074.421NOYES
ELinks 0.12 and Twibright Links 2.3 have Missing SSL Certificate Validation.
Feb 23, 20185.920NONO
The http_negotiate_create_context function in protocol/http/http_negotiate.c in ELinks 0.12 before 0.12pre6, when using HTTP Negotiate or GSS-Negotiate authentication, delegates us
Jan 3, 20135.120NONO
ELinks before 0.11.3, when sending a POST request for an https URL, appends the body and content headers of the POST request to the CONNECT request in cleartext, which allows remot
Sep 21, 20074.314NONO

Exploit Exposure

Signals from CVEs in this product scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
42.9% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (7 CVEs).

Media Mentions

Signals from CVEs in this product scope (7 CVEs).

Top CNAs Publishing CVEs For Elinks

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
0.9.217.58.1%01
0.3.215.05.0%01
0.2.415.05.0%01
0.1225.21.7%00
0.11.217.82.8%00
0.11.1-117.82.8%00
0.11.126.11.8%01