RSS   Vulnerabilities for 'W3M'   RSS

2018-01-24
 
CVE-2018-6198

CWE-59
 

 
w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.

 
 
CVE-2018-6197

CWE-476
 

 
w3m through 0.5.3 is prone to a NULL pointer dereference flaw in formUpdateBuffer in form.c.

 
 
CVE-2018-6196

CWE-835
 

 
w3m through 0.5.3 is prone to an infinite recursion flaw in HTMLlineproc0 because the feed_table_block_tag function in table.c does not prevent a negative indent value.

 
2017-01-20
 
CVE-2016-9436

CWE-20
 

 
parsetagx.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html file, related to a <i> tag.

 
 
CVE-2016-9435

CWE-20
 

 
The HTMLtagproc1 function in file.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html file, related to <dd> tags.

 
2016-12-11
 
CVE-2016-9633

 

 
An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (infinite loop and resource consumption) via a crafted HTML page.

 
 
CVE-2016-9632

 

 
An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (global buffer overflow and crash) via a crafted HTML page.

 
 
CVE-2016-9631

 

 
An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.

 
 
CVE-2016-9630

 

 
An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (global buffer overflow and crash) via a crafted HTML page.

 
 
CVE-2016-9629

 

 
An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.

 


Copyright 2024, cxsecurity.com

 

Back to Top