Show filters
45 Total Results
Displaying 31-40 of 45
Sort by:
Attacker Value
Unknown
CVE-2009-0323
Disclosure Date: January 28, 2009 (last updated October 04, 2023)
Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0 and 11.0 allow remote attackers to execute arbitrary code via (1) a long type parameter in an input tag, which is not properly handled by the EndOfXmlAttributeValue function; (2) an "HTML GI" in a start tag, which is not properly handled by the ProcessStartGI function; and unspecified vectors in (3) html2thot.c and (4) xml2thot.c, related to the msgBuffer variable. NOTE: these are different vectors than CVE-2008-6005.
0
Attacker Value
Unknown
CVE-2008-5282
Disclosure Date: November 29, 2008 (last updated October 04, 2023)
Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0.1 allow remote attackers to execute arbitrary code via (1) a link with a long HREF attribute, and (2) a DIV tag with a long id attribute.
0
Attacker Value
Unknown
CVE-2007-3548
Disclosure Date: July 03, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in W3Filer 2.1.3 allows remote FTP servers to cause a denial of service (application hang or crash) and possibly execute arbitrary code by sending a large banner to a client that is sending a file.
0
Attacker Value
Unknown
CVE-2006-6772
Disclosure Date: December 27, 2006 (last updated October 04, 2023)
Format string vulnerability in the inputAnswer function in file.c in w3m before 0.5.2, when run with the dump or backend option, allows remote attackers to execute arbitrary code via format string specifiers in the Common Name (CN) field of an SSL certificate associated with an https URL.
0
Attacker Value
Unknown
CVE-2006-1900
Disclosure Date: April 20, 2006 (last updated October 04, 2023)
Multiple buffer overflows in World Wide Web Consortium (W3C) Amaya 9.4, and possibly other versions including 8.x before 8.8.5, allow remote attackers to execute arbitrary code via a long value in (1) the COMPACT attribute of the COLGROUP element, (2) the ROWS attribute of the TEXTAREA element, and (3) the COLOR attribute of the LEGEND element; and via other unspecified attack vectors consisting of "dozens of possible snippets."
0
Attacker Value
Unknown
CVE-2005-3183
Disclosure Date: October 12, 2005 (last updated February 22, 2025)
The HTBoundary_put_block function in HTBound.c for W3C libwww (w3c-libwww) allows remote servers to cause a denial of service (segmentation fault) via a crafted multipart/byteranges MIME message that triggers an out-of-bounds read.
0
Attacker Value
Unknown
CVE-2004-2274
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Unknown vulnerability in Jigsaw before 2.2.4 has unknown impact and attack vectors, possibly related to the parsing of the URI.
0
Attacker Value
Unknown
CVE-2002-1348
Disclosure Date: February 19, 2003 (last updated February 22, 2025)
w3m before 0.3.2.2 does not properly escape HTML tags in the ALT attribute of an IMG tag, which could allow remote attackers to access files or cookies.
0
Attacker Value
Unknown
CVE-2002-1335
Disclosure Date: December 11, 2002 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in w3m 0.3.2 does not escape an HTML tag in a frame, which allows remote attackers to insert arbitrary web script or HTML and access files or cookies.
0
Attacker Value
Unknown
CVE-2002-1053
Disclosure Date: October 04, 2002 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in W3C Jigsaw Proxy Server before 2.2.1 allows remote attackers to execute arbitrary script via a URL that contains a reference to a nonexistent host followed by the script, which is included in the resulting error message.
0