W3C's vulnerability footprint centers on a small set of web infrastructure and browser tools developed or stewarded by the organization, including components such as Jigsaw, Amaya, and the CSS Validator. The durable signal reflects the web-facing and parsing-intensive nature of these tools, with recurrent weakness classes spanning input validation, buffer-boundary violations, and cross-site scripting that are characteristic of client-side and server-side web processors. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by W3c over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-5282HIGH Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0.1 allow remote attackers to execute arbitrary code via (1) a link with a long HREF attribute, and (2) a DIV tag | Nov 29, 2008 | 10.0 | 44 | NO | YES |
CVE-2006-1900HIGH Multiple buffer overflows in World Wide Web Consortium (W3C) Amaya 9.4, and possibly other versions including 8.x before 8.8.5, allow remote attackers to execute arbitrary code via | Apr 20, 2006 | 7.6 | 36 | NO | YES |
CVE-2008-6005HIGH Multiple buffer overflows in the CheckUniqueName function in W3C Amaya Web Browser 10.0.1, and possibly other versions including 11.0.1, might allow remote attackers to execute arb | Jan 28, 2009 | 10.0 | 26 | NO | NO |
CVE-2002-1445MEDIUM Cross-site scripting (XSS) vulnerability in CERN Proxy Server allows remote attackers to execute script as other users via a link to a non-existent page whose name contains the scr | Aug 12, 2002 | 4.3 | 22 | NO | YES |
CVE-2002-1052MEDIUM Jigsaw 2.2.1 on Windows systems allows remote attackers to use MS-DOS device names in HTTP requests to (1) cause a denial of service using the "con" device, or (2) obtain the physi | Oct 4, 2002 | 5.0 | 20 | NO | NO |
CVE-2000-0079HIGH The W3C CERN httpd HTTP server allows remote attackers to determine the real pathnames of some commands via a request for a nonexistent URL. | Jan 18, 2000 | 7.5 | 20 | NO | NO |
CVE-2002-1053MEDIUM Cross-site scripting (XSS) vulnerability in W3C Jigsaw Proxy Server before 2.2.1 allows remote attackers to execute arbitrary script via a URL that contains a reference to a nonexi | Oct 4, 2002 | 6.8 | 18 | NO | NO |
CVE-2004-2274MEDIUM Unknown vulnerability in Jigsaw before 2.2.4 has unknown impact and attack vectors, possibly related to the parsing of the URI. | Dec 31, 2004 | 6.4 | 17 | NO | NO |
CVE-2020-4070MEDIUM In CSS Validator less than or equal to commit 54d68a1, there is a cross-site scripting vulnerability in handling URIs. A user would have to click on a specifically crafted validato | Jun 22, 2020 | 5.4 | 15 | NO | NO |
CVE-2005-3183MEDIUM The HTBoundary_put_block function in HTBound.c for W3C libwww (w3c-libwww) allows remote servers to cause a denial of service (segmentation fault) via a crafted multipart/byterange | Oct 12, 2005 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by W3c.
Media articles that mention a CVE ID that affects a product developed by W3c — matched by CVE ID, not by vendor name.