Tats maintains a focused vulnerability footprint concentrated in w3m, a text-based web browser whose memory-handling demands expose it to recurring weaknesses in buffer management and input validation. The vendor's disclosure portfolio, while modest in product count, recurs through classes characteristic of C-based command-line tools: buffer overflows, out-of-bounds reads and writes, NULL pointer dereferences, and improper input validation. These weakness patterns reflect the parser-oriented and memory-unsafe implementation typical of legacy terminal applications, where untrusted HTML or malformed network input can trigger memory-safety violations. Defenders should treat w3m advisories as applicable to environments where text-based web access is deployed—particularly headless servers, legacy systems, and automation contexts—and prioritize patches for exposed instances. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tats over time
Signals from CVEs in this vendor scope (40 CVEs).
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-38223HIGH There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Den | Aug 15, 2022 | 7.8 | 26 | NO | NO |
CVE-2018-6197HIGH w3m through 0.5.3 is prone to a NULL pointer dereference flaw in formUpdateBuffer in form.c. | Jan 25, 2018 | 7.5 | 26 | NO | NO |
CVE-2016-9426HIGH An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Integer overflow vulnerability in the renderTable function in w3m allows remote attackers to cause a deni | Dec 12, 2016 | 8.8 | 26 | NO | NO |
CVE-2016-9425HIGH An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Heap-based buffer overflow in the addMultirowsForm function in w3m allows remote attackers to cause a den | Dec 12, 2016 | 8.8 | 26 | NO | NO |
CVE-2016-9424HIGH An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m doesn't properly validate the value of tag attribute, which allows remote attackers to cause a denial | Dec 12, 2016 | 8.8 | 26 | NO | NO |
CVE-2018-6196HIGH w3m through 0.5.3 is prone to an infinite recursion flaw in HTMLlineproc0 because the feed_table_block_tag function in table.c does not prevent a negative indent value. | Jan 25, 2018 | 7.5 | 25 | NO | NO |
CVE-2016-9423HIGH An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Heap-based buffer overflow in w3m allows remote attackers to cause a denial of service (crash) and possib | Dec 12, 2016 | 8.8 | 24 | NO | NO |
CVE-2016-9435MEDIUM The HTMLtagproc1 function in file.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html f | Jan 20, 2017 | 6.5 | 23 | NO | NO |
CVE-2016-9429HIGH An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Buffer overflow in the formUpdateBuffer function in w3m allows remote attackers to cause a denial of serv | Dec 12, 2016 | 8.8 | 23 | NO | NO |
CVE-2016-9428HIGH An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Heap-based buffer overflow in the addMultirowsForm function in w3m allows remote attackers to cause a den | Dec 12, 2016 | 8.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (40 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tats.
Media articles that mention a CVE ID that affects a product developed by Tats — matched by CVE ID, not by vendor name.