Vulnerabilities > W3M

DATE CVE VULNERABILITY TITLE RISK
2010-06-16 CVE-2010-2074 Improper Input Validation vulnerability in W3M 0.5.2
istream.c in w3m 0.5.2 and possibly other versions, when ssl_verify_server is enabled, does not properly handle a '\0' character in a domain name in the (1) subject's Common Name or (2) Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
network
w3m CWE-20
6.8
2003-02-19 CVE-2002-1348 Cross-Site Scripting vulnerability in W3M Image Attribute
w3m before 0.3.2.2 does not properly escape HTML tags in the ALT attribute of an IMG tag, which could allow remote attackers to access files or cookies.
network
low complexity
w3m
5.0
2001-09-20 CVE-2001-0700 Buffer Overflow vulnerability in W3M Malformed MIME Header
Buffer overflow in w3m 0.2.1 and earlier allows a remote attacker to execute arbitrary code via a long base64 encoded MIME header.
network
low complexity
w3m
7.5