Twibright maintains the Links web browser, a specialized lightweight client that prioritizes text-based and low-bandwidth browsing modes, where the observed vulnerability surface centers on certificate validation, symlink-following, and boundary-read issues in its network and file-handling code. The vendor's disclosure pattern reflects the security demands of a focused, narrowly scoped product; current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Twibright over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-3329HIGH Unspecified vulnerability in Links before 2.1, when "only proxies" is enabled, has unknown impact and attack vectors related to providing "URLs to external programs." | Jul 27, 2008 | 9.3 | 23 | NO | NO |
CVE-2012-6709MEDIUM ELinks 0.12 and Twibright Links 2.3 have Missing SSL Certificate Validation. | Feb 23, 2018 | 5.9 | 20 | NO | NO |
CVE-2017-11114MEDIUM The put_chars function in html_r.c in Twibright Links 2.14 allows remote attackers to cause a denial of service (buffer over-read) via a crafted HTML file. | Jul 31, 2017 | 5.5 | 19 | NO | NO |
CVE-2013-6050MEDIUM Integer overflow in Links before 2.8 allows remote attackers to cause a denial of service (crash) via crafted HTML tables. | Dec 7, 2013 | 4.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Twibright.
Media articles that mention a CVE ID that affects a product developed by Twibright — matched by CVE ID, not by vendor name.