CVE-2023-4255
- EPSS 0.02%
- Veröffentlicht 21.12.2023 16:15:10
- Zuletzt bearbeitet 21.11.2024 08:34:44
An out-of-bounds write issue has been discovered in the backspace handling of the checkType() function in etc.c within the W3M application. This vulnerability is triggered by supplying a specially crafted HTML file to the w3m binary. Exploitation of ...
CVE-2023-38253
- EPSS 0.02%
- Veröffentlicht 14.07.2023 18:15:11
- Zuletzt bearbeitet 21.11.2024 08:13:11
An out-of-bounds read flaw was found in w3m, in the growbuf_to_Str function in indep.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.
CVE-2023-38252
- EPSS 0.02%
- Veröffentlicht 14.07.2023 18:15:10
- Zuletzt bearbeitet 08.02.2025 04:15:08
An out-of-bounds read flaw was found in w3m, in the Strnew_size function in Str.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.
CVE-2022-38223
- EPSS 0.13%
- Veröffentlicht 15.08.2022 11:21:43
- Zuletzt bearbeitet 21.11.2024 07:16:05
There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.
CVE-2018-6198
- EPSS 0.18%
- Veröffentlicht 25.01.2018 03:29:00
- Zuletzt bearbeitet 21.11.2024 04:10:16
w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.
CVE-2018-6197
- EPSS 1.15%
- Veröffentlicht 25.01.2018 03:29:00
- Zuletzt bearbeitet 21.11.2024 04:10:16
w3m through 0.5.3 is prone to a NULL pointer dereference flaw in formUpdateBuffer in form.c.
CVE-2018-6196
- EPSS 0.59%
- Veröffentlicht 25.01.2018 03:29:00
- Zuletzt bearbeitet 21.11.2024 04:10:16
w3m through 0.5.3 is prone to an infinite recursion flaw in HTMLlineproc0 because the feed_table_block_tag function in table.c does not prevent a negative indent value.
CVE-2016-9436
- EPSS 1.36%
- Veröffentlicht 20.01.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
parsetagx.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html file, related to a <i> tag.
CVE-2016-9435
- EPSS 1.41%
- Veröffentlicht 20.01.2017 15:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The HTMLtagproc1 function in file.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html file, related to <dd> tags.
CVE-2016-9633
- EPSS 0.75%
- Veröffentlicht 12.12.2016 02:59:50
- Zuletzt bearbeitet 12.04.2025 10:46:40
An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (infinite loop and resource consumption) via a crafted HTML page.