Vulnerabilities > Elinks > Elinks > 0.11.1
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2009-09-14 | CVE-2008-7224 | Buffer Errors vulnerability in Elinks 0.11.1/0.11.11/0.11.2 Buffer overflow in entity_cache in ELinks before 0.11.4rc0 allows remote attackers to cause a denial of service (crash) via a crafted link. | 7.8 |
2007-04-13 | CVE-2007-2027 | USE of Externally-Controlled Format String vulnerability in Elinks 0.11.1 Untrusted search path vulnerability in the add_filename_to_string function in intl/gettext/loadmsgcat.c for Elinks 0.11.1 allows local users to cause Elinks to use an untrusted gettext message catalog (.po file) in a "../po" directory, which can be leveraged to conduct format string attacks. | 4.4 |