CVE-2016-9428

Source
https://nvd.nist.gov/vuln/detail/CVE-2016-9428
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-9428.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2016-9428
Related
Published
2016-12-12T02:59:17Z
Modified
2024-10-16T02:11:58.747833Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Heap-based buffer overflow in the addMultirowsForm function in w3m allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTML page.

References

Affected packages

Debian:11 / w3m

Package

Name
w3m
Purl
pkg:deb/debian/w3m?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.3-30

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / w3m

Package

Name
w3m
Purl
pkg:deb/debian/w3m?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.3-30

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / w3m

Package

Name
w3m
Purl
pkg:deb/debian/w3m?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.3-30

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Git / github.com/tats/w3m

Affected ranges

Type
GIT
Repo
https://github.com/tats/w3m
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

debian/0.*

debian/0.1.10+0.1.11pre+kokb23-4
debian/0.3-2.4
debian/0.5.1-1
debian/0.5.1-3
debian/0.5.1-4
debian/0.5.1-5
debian/0.5.1-5.1
debian/0.5.2-1
debian/0.5.2-10
debian/0.5.2-2
debian/0.5.2-2.1
debian/0.5.2-3
debian/0.5.2-4
debian/0.5.2-5
debian/0.5.2-6
debian/0.5.2-7
debian/0.5.2-8
debian/0.5.2-9
debian/0.5.3-1
debian/0.5.3-10
debian/0.5.3-11
debian/0.5.3-12
debian/0.5.3-13
debian/0.5.3-14
debian/0.5.3-15
debian/0.5.3-16
debian/0.5.3-17
debian/0.5.3-18
debian/0.5.3-19
debian/0.5.3-2
debian/0.5.3-20
debian/0.5.3-21
debian/0.5.3-22
debian/0.5.3-23
debian/0.5.3-24
debian/0.5.3-25
debian/0.5.3-26
debian/0.5.3-27
debian/0.5.3-28
debian/0.5.3-29
debian/0.5.3-3
debian/0.5.3-30
debian/0.5.3-4
debian/0.5.3-5
debian/0.5.3-6
debian/0.5.3-7
debian/0.5.3-8
debian/0.5.3-9

upstream/0.*

upstream/0.1.10+0.1.11pre+kokb23