← All CVEs

CVE-2005-3120

critical · 9.8

Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escape (ESC) characters.

9.8
CVSS
23.3%
EPSS (exploit prob.)
98th
EPSS percentile
2005-10-17
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-131

Affected products

VendorProductAffected versions
invisible-islandlynx<= 2.8.6
debiandebian_linux3.0
debiandebian_linux3.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2005-3120