W3m
Vendor:
First CVE: Dec 12, 2016 · Active for 9 years
40
Total CVEs
More Total CVEs than 98% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 43% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact W3m over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 12, 2016
9 years ago
Most Recent CVE
Dec 21, 2023
950 days ago
CVE Severity & Scoring
W3m40 CVEs
75%
25%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local5 (12.5%)
Network35 (87.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low39 (97.5%)
High1 (2.5%)
Unknown0 (0.0%)
User Interaction
None3 (7.5%)
Unknown0 (0.0%)
Required37 (92.5%)
Privileges Required
Low1 (2.5%)
High0 (0.0%)
None39 (97.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (40 CVEs).
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-38223HIGH There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Den | Aug 15, 2022 | 7.8 | 26 | NO | NO |
CVE-2018-6197HIGH w3m through 0.5.3 is prone to a NULL pointer dereference flaw in formUpdateBuffer in form.c. | Jan 25, 2018 | 7.5 | 26 | NO | NO |
CVE-2016-9426HIGH An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Integer overflow vulnerability in the renderTable function in w3m allows remote attackers to cause a deni | Dec 12, 2016 | 8.8 | 26 | NO | NO |
CVE-2016-9425HIGH An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Heap-based buffer overflow in the addMultirowsForm function in w3m allows remote attackers to cause a den | Dec 12, 2016 | 8.8 | 26 | NO | NO |
CVE-2016-9424HIGH An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m doesn't properly validate the value of tag attribute, which allows remote attackers to cause a denial | Dec 12, 2016 | 8.8 | 26 | NO | NO |
CVE-2018-6196HIGH w3m through 0.5.3 is prone to an infinite recursion flaw in HTMLlineproc0 because the feed_table_block_tag function in table.c does not prevent a negative indent value. | Jan 25, 2018 | 7.5 | 25 | NO | NO |
CVE-2016-9423HIGH An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Heap-based buffer overflow in w3m allows remote attackers to cause a denial of service (crash) and possib | Dec 12, 2016 | 8.8 | 24 | NO | NO |
CVE-2016-9435MEDIUM The HTMLtagproc1 function in file.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html f | Jan 20, 2017 | 6.5 | 23 | NO | NO |
CVE-2016-9429HIGH An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Buffer overflow in the formUpdateBuffer function in w3m allows remote attackers to cause a denial of serv | Dec 12, 2016 | 8.8 | 23 | NO | NO |
CVE-2016-9428HIGH An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Heap-based buffer overflow in the addMultirowsForm function in w3m allows remote attackers to cause a den | Dec 12, 2016 | 8.8 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (40 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (40 CVEs).
Media Mentions
Signals from CVEs in this product scope (40 CVEs).
Top CNAs Publishing CVEs For W3m
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 0.5.3\+git20230129 | 1 | 5.5 | 0.3% | 0 | 0 |
| 0.5.3\+git20230121-2 | 1 | 5.5 | 0.3% | 0 | 0 |
| 0.5.3\+git20230121-1 | 1 | 5.5 | 0.3% | 0 | 0 |
| 0.5.3\+git20230121 | 2 | 5.5 | 0.4% | 0 | 0 |
| 0.5.3 | 1 | 7.8 | 0.4% | 0 | 0 |