Vulnerabilities > Lynx

DATE CVE VULNERABILITY TITLE RISK
2016-12-22 CVE-2016-9179 Improper Input Validation vulnerability in Lynx
lynx: It was found that Lynx doesn't parse the authority component of the URL correctly when the host name part ends with '?', and could instead be tricked into connecting to a different host.
network
low complexity
lynx CWE-20
7.5
2012-11-04 CVE-2012-5821 Improper Certificate Validation vulnerability in multiple products
Lynx does not verify that the server's certificate is signed by a trusted certification authority, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate, related to improper use of a certain GnuTLS function.
network
high complexity
lynx canonical CWE-295
5.9