peter bassill · operator
$ cve CVE-2005-3120 JSON

CVE-2005-3120 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 23.3% (pctl 98)

Patch early

A public exploit exists.

Description

Stack-based buffer overflow in the HTrjis function in Lynx 2.8.6 and earlier allows remote NNTP servers to execute arbitrary code via certain article headers containing Asian characters that cause Lynx to add extra escape (ESC) characters.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS23.26% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-131
On CISA KEVno
Public exploityes
Published2005-10-17
Last modified2026-06-16

Affected (2)

VendorProduct
debiandebian linux
invisible-islandlynx

Public exploits

SourceTitleDate
exploit-dbLynx 2.8.6dev.13 - Remote Buffer Overflow (PoC)2005-10-17

References

→ the Explorer  ·  watch your stack  ·  NVD