<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 09 Oct 2026 14:05:55 +0000</lastBuildDate>
    <item>
      <title>ALSA-2022:2129 — Moderate: lynx security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2022:2129</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: lynx&lt;/p&gt;
&lt;p&gt;Lynx is a text-based Web browser. Lynx does not display any images, but it does support frames, tables, and most other HTML tags.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* lynx: Disclosure of HTTP authentication credentials via SNI data (CVE-2021-38165)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: lynx&lt;/p&gt;
&lt;p&gt;Lynx is a text-based Web browser. Lynx does not display any images, but it does support frames, tables, and most other HTML tags.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* lynx: Disclosure of HTTP authentication credentials via SNI data (CVE-2021-38165)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2022:2129</guid>
    </item>
    <item>
      <title>bdu:2022-00255</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-00255</link>
      <description>bdu:2022-00255</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-00255</guid>
    </item>
    <item>
      <title>EUVD-2026-30202</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-30202</link>
      <description>EUVD-2026-30202</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-30202</guid>
    </item>
    <item>
      <title>fkie_cve-2021-38165</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2021-38165</link>
      <description>&lt;p&gt;Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2021-38165</guid>
    </item>
    <item>
      <title>GHSA-88f3-hp86-v36f</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-88f3-hp86-v36f</link>
      <description>&lt;p&gt;Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-88f3-hp86-v36f</guid>
    </item>
    <item>
      <title>gsd-2021-38165</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2021-38165</link>
      <description>gsd-2021-38165</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2021-38165</guid>
    </item>
    <item>
      <title>OESA-2021-1326 — lynx security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2021-1326</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: lynx, openEuler:20.03-LTS-SP2: lynx&lt;/p&gt;
&lt;p&gt;Lynx is a fully-featured World Wide Web (WWW) client for users running cursor-addressable, character-cell display devices such as vt100 terminals, vt100 emulators running on Windows 95/NT or Macintoshes, or any other character-cell display.  It will display Hypertext Markup Language (HTML) documents containing links to files on the local system, as well as files on remote systems running http, gopher, ftp, wais, nntp, finger, or cso/ph/qi servers, and services accessible via logins to telnet, tn3270 or rlogin accounts.  Current versions of Lynx run on Unix, VMS, Windows95 through Windows 8, 386DOS and OS/2 EMX.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.(CVE-2021-38165)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP1: lynx, openEuler:20.03-LTS-SP2: lynx&lt;/p&gt;
&lt;p&gt;Lynx is a fully-featured World Wide Web (WWW) client for users running cursor-addressable, character-cell display devices such as vt100 terminals, vt100 emulators running on Windows 95/NT or Macintoshes, or any other character-cell display.  It will display Hypertext Markup Language (HTML) documents containing links to files on the local system, as well as files on remote systems running http, gopher, ftp, wais, nntp, finger, or cso/ph/qi servers, and services accessible via logins to telnet, tn3270 or rlogin accounts.  Current versions of Lynx run on Unix, VMS, Windows95 through Windows 8, 386DOS and OS/2 EMX.&#13;
&#13;
Security Fix(es):&#13;
&#13;
Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.(CVE-2021-38165)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2021-1326</guid>
    </item>
    <item>
      <title>RHSA-2022:2129 — Red Hat Security Advisory: lynx security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2022:2129</link>
      <description>&lt;p&gt;lynx: Disclosure of HTTP authentication credentials via SNI data&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;lynx: Disclosure of HTTP authentication credentials via SNI data&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2022:2129</guid>
    </item>
    <item>
      <title>RLSA-2022:2129 — Moderate: lynx security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2022:2129</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: lynx&lt;/p&gt;
&lt;p&gt;Lynx is a text-based Web browser. Lynx does not display any images, but it does support frames, tables, and most other HTML tags.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* lynx: Disclosure of HTTP authentication credentials via SNI data (CVE-2021-38165)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the Rocky Linux 8.6 Release Notes linked from the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: lynx&lt;/p&gt;
&lt;p&gt;Lynx is a text-based Web browser. Lynx does not display any images, but it does support frames, tables, and most other HTML tags.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* lynx: Disclosure of HTTP authentication credentials via SNI data (CVE-2021-38165)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;
&lt;p&gt;Additional Changes:&lt;/p&gt;
&lt;p&gt;For detailed information on changes in this release, see the Rocky Linux 8.6 Release Notes linked from the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2022:2129</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2021-38165</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-38165</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: lynx, Ubuntu:Pro:18.04:LTS: lynx, Ubuntu:Pro:20.04:LTS: lynx&lt;/p&gt;
&lt;p&gt;Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: lynx, Ubuntu:Pro:18.04:LTS: lynx, Ubuntu:Pro:20.04:LTS: lynx&lt;/p&gt;
&lt;p&gt;Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2021-38165</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-1822 — Lynx: Schwachstelle ermöglicht Offenlegung von Informationen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1822</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Lynx ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Lynx ausnutzen, um Informationen offenzulegen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-1822</guid>
    </item>
  </channel>
</rss>
