VYPR
Unrated severityNVD Advisory· Published Feb 19, 2003· Updated Apr 16, 2026

CVE-2002-1405

CVE-2002-1405

Description

CRLF injection vulnerability in Lynx 2.8.4 and earlier allows remote attackers to inject false HTTP headers into an HTTP request that is provided on the command line, via a URL containing encoded carriage return, line feed, and other whitespace characters.

Affected products

9
  • Elinks/Elinks2 versions
    cpe:2.3:a:elinks:elinks:0.2.4:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:elinks:elinks:0.2.4:*:*:*:*:*:*:*
    • cpe:2.3:a:elinks:elinks:0.3.2:*:*:*:*:*:*:*
  • cpe:2.3:a:links:links:0.96:*:*:*:*:*:*:*
  • cpe:2.3:a:university_of_kansas:lynx:2.8.2_rel1:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:university_of_kansas:lynx:2.8.2_rel1:*:*:*:*:*:*:*
    • cpe:2.3:a:university_of_kansas:lynx:2.8.3:*:*:*:*:*:*:*
    • cpe:2.3:a:university_of_kansas:lynx:2.8.3_rel1:*:*:*:*:*:*:*
    • cpe:2.3:a:university_of_kansas:lynx:2.8.4:*:*:*:*:*:*:*
    • cpe:2.3:a:university_of_kansas:lynx:2.8.4_rel1:*:*:*:*:*:*:*
    • cpe:2.3:a:university_of_kansas:lynx:2.8.5_dev8:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

10

News mentions

0

No linked articles in our index yet.