cbcvebase.

Debian W3M vulnerabilities

42 known vulnerabilities affecting debian/w3m.

Total CVEs
42
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH8MEDIUM29LOW5

Vulnerabilities

Page 1 of 3
CVE-2016-9428P3HIGHCVSS 8.8fixed in w3m 0.5.3-30 (bookworm)2016
CVE-2016-9428 [HIGH] CVE-2016-9428: w3m - An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Heap-... An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Heap-based buffer overflow in the addMultirowsForm function in w3m allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTML page. Scope: local bookworm: resolved (fixed in 0.5.3-30) bullseye: resolved (fixed in 0.5.3-30) forky: resolved (fi
debian
CVE-2016-9429P3HIGHCVSS 8.8fixed in w3m 0.5.3-30 (bookworm)2016
CVE-2016-9429 [HIGH] CVE-2016-9429: w3m - An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Buffe... An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Buffer overflow in the formUpdateBuffer function in w3m allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTML page. Scope: local bookworm: resolved (fixed in 0.5.3-30) bullseye: resolved (fixed in 0.5.3-30) forky: resolved (fixed in 0.5.
debian
CVE-2016-9425P3HIGHCVSS 8.8fixed in w3m 0.5.3-30 (bookworm)2016
CVE-2016-9425 [HIGH] CVE-2016-9425: w3m - An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Heap-... An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Heap-based buffer overflow in the addMultirowsForm function in w3m allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTML page. Scope: local bookworm: resolved (fixed in 0.5.3-30) bullseye: resolved (fixed in 0.5.3-30) forky: resolved (fi
debian
CVE-2016-9423P3HIGHCVSS 8.8fixed in w3m 0.5.3-30 (bookworm)2016
CVE-2016-9423 [HIGH] CVE-2016-9423: w3m - An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Heap-... An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Heap-based buffer overflow in w3m allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTML page. Scope: local bookworm: resolved (fixed in 0.5.3-30) bullseye: resolved (fixed in 0.5.3-30) forky: resolved (fixed in 0.5.3-30) sid: resolved (f
debian
CVE-2016-9422P3HIGHCVSS 8.8fixed in w3m 0.5.3-30 (bookworm)2016
CVE-2016-9422 [HIGH] CVE-2016-9422: w3m - An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. The f... An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. The feed_table_tag function in w3m doesn't properly validate the value of table span, which allows remote attackers to cause a denial of service (stack and/or heap buffer overflow) and possibly execute arbitrary code via a crafted HTML page. Scope: local bookworm: resolved (fixed in 0.5.3-30) bulls
debian
CVE-2006-6772P3LOWCVSS 9.3fixed in w3m 0.5.1-5.1 (bookworm)2006
CVE-2006-6772 [CRITICAL] CVE-2006-6772: w3m - Format string vulnerability in the inputAnswer function in file.c in w3m before ... Format string vulnerability in the inputAnswer function in file.c in w3m before 0.5.2, when run with the dump or backend option, allows remote attackers to execute arbitrary code via format string specifiers in the Common Name (CN) field of an SSL certificate associated with an https URL. Scope: local bookworm: resolved (fixed in 0.5.1-5.1) bullseye: resolved (fixed i
debian
CVE-2016-9424P3HIGHCVSS 8.8fixed in w3m 0.5.3-30 (bookworm)2016
CVE-2016-9424 [HIGH] CVE-2016-9424: w3m - An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m d... An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m doesn't properly validate the value of tag attribute, which allows remote attackers to cause a denial of service (heap buffer overflow crash) and possibly execute arbitrary code via a crafted HTML page. Scope: local bookworm: resolved (fixed in 0.5.3-30) bullseye: resolved (fixed in 0.5.3-30) f
debian
CVE-2016-9426P3HIGHCVSS 8.8fixed in w3m 0.5.3-30 (bookworm)2016
CVE-2016-9426 [HIGH] CVE-2016-9426: w3m - An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Integ... An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Integer overflow vulnerability in the renderTable function in w3m allows remote attackers to cause a denial of service (OOM) and possibly execute arbitrary code due to bdwgc's bug (CVE-2016-9427) via a crafted HTML page. Scope: local bookworm: resolved (fixed in 0.5.3-30) bullseye: resolved (fixed
debian
CVE-2018-6197P3LOWCVSS 7.5fixed in w3m 0.5.3-36 (bookworm)2018
CVE-2018-6197 [HIGH] CVE-2018-6197: w3m - w3m through 0.5.3 is prone to a NULL pointer dereference flaw in formUpdateBuffe... w3m through 0.5.3 is prone to a NULL pointer dereference flaw in formUpdateBuffer in form.c. Scope: local bookworm: resolved (fixed in 0.5.3-36) bullseye: resolved (fixed in 0.5.3-36) forky: resolved (fixed in 0.5.3-36) sid: resolved (fixed in 0.5.3-36) trixie: resolved (fixed in 0.5.3-36)
debian
CVE-2018-6196P3LOWCVSS 7.5fixed in w3m 0.5.3-36 (bookworm)2018
CVE-2018-6196 [HIGH] CVE-2018-6196: w3m - w3m through 0.5.3 is prone to an infinite recursion flaw in HTMLlineproc0 becaus... w3m through 0.5.3 is prone to an infinite recursion flaw in HTMLlineproc0 because the feed_table_block_tag function in table.c does not prevent a negative indent value. Scope: local bookworm: resolved (fixed in 0.5.3-36) bullseye: resolved (fixed in 0.5.3-36) forky: resolved (fixed in 0.5.3-36) sid: resolved (fixed in 0.5.3-36) trixie: resolved (fixed in 0.5.3-36)
debian
CVE-2022-38223P4HIGHCVSS 7.8fixed in w3m 0.5.3+git20230121-1 (bookworm)2022
CVE-2022-38223 [HIGH] CVE-2022-38223: w3m - There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It c... There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact. Scope: local bookworm: resolved (fixed in 0.5.3+git20230121-1) bullseye: resolved (fixed in 0.5.3+git20210102-6+deb11u1) forky: resolv
debian
CVE-2016-9435P4MEDIUMCVSS 6.5fixed in w3m 0.5.3-30 (bookworm)2016
CVE-2016-9435 [MEDIUM] CVE-2016-9435: w3m - The HTMLtagproc1 function in file.c in w3m before 0.5.3+git20161009 does not pro... The HTMLtagproc1 function in file.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html file, related to tags. Scope: local bookworm: resolved (fixed in 0.5.3-30) bullseye: resolved (fixed in 0.5.3-30) forky: resolved (fixed in 0.5.3-30) sid: resolved (fixed in 0.5.3-30) trixie: r
debian
CVE-2010-2074P4LOWCVSS 5.9fixed in w3m 0.5.2-5 (bookworm)2010
CVE-2010-2074 [MEDIUM] CVE-2010-2074: w3m - istream.c in w3m 0.5.2 and possibly other versions, when ssl_verify_server is en... istream.c in w3m 0.5.2 and possibly other versions, when ssl_verify_server is enabled, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certifica
debian
CVE-2016-9436P4MEDIUMCVSS 6.5fixed in w3m 0.5.3-30 (bookworm)2016
CVE-2016-9436 [MEDIUM] CVE-2016-9436: w3m - parsetagx.c in w3m before 0.5.3+git20161009 does not properly initialize values,... parsetagx.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html file, related to a tag. Scope: local bookworm: resolved (fixed in 0.5.3-30) bullseye: resolved (fixed in 0.5.3-30) forky: resolved (fixed in 0.5.3-30) sid: resolved (fixed in 0.5.3-30) trixie: resolved (fixed in 0.5.3
debian
CVE-2016-9442P4MEDIUMCVSS 6.5fixed in w3m 0.5.3-30 (bookworm)2016
CVE-2016-9442 [MEDIUM] CVE-2016-9442: w3m - An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m a... An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause memory corruption in certain conditions via a crafted HTML page. Scope: local bookworm: resolved (fixed in 0.5.3-30) bullseye: resolved (fixed in 0.5.3-30) forky: resolved (fixed in 0.5.3-30) sid: resolved (fixed in 0.5.3-30) trixie: resolved (fixed in 0.5.3-3
debian
CVE-2016-9627P4MEDIUMCVSS 6.5fixed in w3m 0.5.3-33 (bookworm)2016
CVE-2016-9627 [MEDIUM] CVE-2016-9627: w3m - An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m a... An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (heap buffer overflow and crash) via a crafted HTML page. Scope: local bookworm: resolved (fixed in 0.5.3-33) bullseye: resolved (fixed in 0.5.3-33) forky: resolved (fixed in 0.5.3-33) sid: resolved (fixed in 0.5.3-33) trixie: resolved (fix
debian
CVE-2016-9433P4MEDIUMCVSS 6.5fixed in w3m 0.5.3-30 (bookworm)2016
CVE-2016-9433 [MEDIUM] CVE-2016-9433: w3m - An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m a... An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (out-of-bounds array access) via a crafted HTML page. Scope: local bookworm: resolved (fixed in 0.5.3-30) bullseye: resolved (fixed in 0.5.3-30) forky: resolved (fixed in 0.5.3-30) sid: resolved (fixed in 0.5.3-30) trixie: resolved (fixed i
debian
CVE-2016-9630P4MEDIUMCVSS 6.5fixed in w3m 0.5.3-33 (bookworm)2016
CVE-2016-9630 [MEDIUM] CVE-2016-9630: w3m - An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m a... An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (global buffer overflow and crash) via a crafted HTML page. Scope: local bookworm: resolved (fixed in 0.5.3-33) bullseye: resolved (fixed in 0.5.3-33) forky: resolved (fixed in 0.5.3-33) sid: resolved (fixed in 0.5.3-33) trixie: resolved (f
debian
CVE-2016-9632P4MEDIUMCVSS 6.5fixed in w3m 0.5.3-33 (bookworm)2016
CVE-2016-9632 [MEDIUM] CVE-2016-9632: w3m - An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m a... An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (global buffer overflow and crash) via a crafted HTML page. Scope: local bookworm: resolved (fixed in 0.5.3-33) bullseye: resolved (fixed in 0.5.3-33) forky: resolved (fixed in 0.5.3-33) sid: resolved (fixed in 0.5.3-33) trixie: resolved (f
debian
CVE-2016-9437P4MEDIUMCVSS 6.5fixed in w3m 0.5.3-30 (bookworm)2016
CVE-2016-9437 [MEDIUM] CVE-2016-9437: w3m - An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m a... An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) and possibly memory corruption via a crafted HTML page. Scope: local bookworm: resolved (fixed in 0.5.3-30) bullseye: resolved (fixed in 0.5.3-30) forky: resolved (fixed in 0.5.3-30) sid: resolved (fixed in 0.
debian
Debian W3M vulnerabilities | cvebase