VDB
CVE-2002-1405
CVE-2002-1405
PUBLISHED
CVSS 5 MEDIUM
CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on the command line, via a URL containing encoded carriage return, line feed, and other whitespace characters.
EPSS 5.04% · 91.6th percentile
Risk Scores
CVSS 2.0
5
EPSS Score
5.04%
91.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | * |
| university_of_kansas | lynx | 2.8.2_rel1, 2.8.3, 2.8.3_rel1 |
| elinks | elinks | 0.2.4, 0.3.2 |
| links | links | 0.96 |
Timeline
- Feb 19, 2003 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 3, 2022 CVE Updated
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Aug 9, 2023 EPSS Score
References
- 2002-0085 vendor-advisory
- lynx-crlf-injection(9887) vdb
- RHSA-2003:029 vendor-advisory
- 20020819 Lynx CRLF Injection mailing-list
- CSSA-2002-049.0 vendor-advisory
- 20020822 Lynx CRLF Injection, part two mailing-list
- 5499 vdb
- http://www.mandrakesoft.com/security/advisories?name=MDKSA-2003:023 technical
- http://www.debian.org/security/2002/dsa-210 patch
- https://nvd.nist.gov/vuln/detail/CVE-2002-1405 advisory
- http://www.redhat.com/support/errata/RHSA-2003-030.html url