Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

W3c

First CVE: Jan 18, 2000Active for: 27 yearsTotal CVEs: 10
37.0
VTI Score
Medium

W3C's vulnerability footprint centers on a small set of web infrastructure and browser tools developed or stewarded by the organization, including components such as Jigsaw, Amaya, and the CSS Validator. The durable signal reflects the web-facing and parsing-intensive nature of these tools, with recurrent weakness classes spanning input validation, buffer-boundary violations, and cross-site scripting that are characteristic of client-side and server-side web processors. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by W3c over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 18, 2000
26 years ago
Most Recent CVE
Jun 22, 2020
2,223 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2008-5282HIGH
Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0.1 allow remote attackers to execute arbitrary code via (1) a link with a long HREF attribute, and (2) a DIV tag
Nov 29, 200810.044NOYES
CVE-2006-1900HIGH
Multiple buffer overflows in World Wide Web Consortium (W3C) Amaya 9.4, and possibly other versions including 8.x before 8.8.5, allow remote attackers to execute arbitrary code via
Apr 20, 20067.636NOYES
CVE-2008-6005HIGH
Multiple buffer overflows in the CheckUniqueName function in W3C Amaya Web Browser 10.0.1, and possibly other versions including 11.0.1, might allow remote attackers to execute arb
Jan 28, 200910.026NONO
CVE-2002-1445MEDIUM
Cross-site scripting (XSS) vulnerability in CERN Proxy Server allows remote attackers to execute script as other users via a link to a non-existent page whose name contains the scr
Aug 12, 20024.322NOYES
CVE-2002-1052MEDIUM
Jigsaw 2.2.1 on Windows systems allows remote attackers to use MS-DOS device names in HTTP requests to (1) cause a denial of service using the "con" device, or (2) obtain the physi
Oct 4, 20025.020NONO
CVE-2000-0079HIGH
The W3C CERN httpd HTTP server allows remote attackers to determine the real pathnames of some commands via a request for a nonexistent URL.
Jan 18, 20007.520NONO
CVE-2002-1053MEDIUM
Cross-site scripting (XSS) vulnerability in W3C Jigsaw Proxy Server before 2.2.1 allows remote attackers to execute arbitrary script via a URL that contains a reference to a nonexi
Oct 4, 20026.818NONO
CVE-2004-2274MEDIUM
Unknown vulnerability in Jigsaw before 2.2.4 has unknown impact and attack vectors, possibly related to the parsing of the URI.
Dec 31, 20046.417NONO
CVE-2020-4070MEDIUM
In CSS Validator less than or equal to commit 54d68a1, there is a cross-site scripting vulnerability in handling URIs. A user would have to click on a specifically crafted validato
Jun 22, 20205.415NONO
CVE-2005-3183MEDIUM
The HTBoundary_put_block function in HTBound.c for W3C libwww (w3c-libwww) allows remote servers to cause a denial of service (segmentation fault) via a crafted multipart/byterange
Oct 12, 20054.314NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
60%
40%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (10.0%)
Unknown9 (90.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (10.0%)
High0 (0.0%)
Unknown9 (90.0%)
User Interaction
None0 (0.0%)
Unknown9 (90.0%)
Required1 (10.0%)
Privileges Required
Low1 (10.0%)
High0 (0.0%)
None0 (0.0%)
Unknown9 (90.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
30.0% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by W3c.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by W3c — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For W3c's Products

View all 3 CNAs →

Top CWEs