CVE-2016-9422 PUBLISHED

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. The feed_table_tag function in w3m doesn't properly validate the value of table span, which allows remote attackers to cause a denial of service (stack and/or heap buffer overflow) and possibly execute arbitrary code via a crafted HTML page.

EPSS 1.04% · 77.3th percentile

Risk Scores

EPSS Score
1.04%
77.3th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSw3m0.5.3-26build1, 0, 0.5.3-24
Ubuntu:14.04:LTSw3m0, 0.5.3-11, 0.5.3-12

Timeline

References

Open in Interactive Console →