VYPR
Unrated severityNVD Advisory· Published Aug 20, 2010· Updated Apr 29, 2026

CVE-2010-2810

CVE-2010-2810

Description

Heap-based buffer overflow in the convert_to_idna function in WWW/Library/Implementation/HTParse.c in Lynx 2.8.8dev.1 through 2.8.8dev.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed URL containing a % (percent) character in the domain name.

Affected products

4
  • Lynx/Lynx4 versions
    cpe:2.3:a:lynx:lynx:2.8.8:dev.1:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:lynx:lynx:2.8.8:dev.1:*:*:*:*:*:*
    • cpe:2.3:a:lynx:lynx:2.8.8:dev.2:*:*:*:*:*:*
    • cpe:2.3:a:lynx:lynx:2.8.8:dev.3:*:*:*:*:*:*
    • cpe:2.3:a:lynx:lynx:2.8.8:dev.4:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.