Tats
34 CVEs tracked since 2016. Since Dec 2016, none of them reached CISA KEV.
Tats CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2016-12 | 31 | 0 |
| 2017-01 | null or fewer | |
| 2017-02 | null or fewer | |
| 2017-03 | null or fewer | |
| 2017-04 | null or fewer | |
| 2017-05 | null or fewer | |
| 2017-06 | null or fewer | |
| 2017-07 | null or fewer | |
| 2017-08 | null or fewer | |
| 2017-09 | null or fewer | |
| 2017-10 | null or fewer | |
| 2017-11 | null or fewer | |
| 2017-12 | null or fewer | |
| 2018-01 | 3 | 0 |
Products
The products that kept showing up in Tats's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Tats.
- CVE-2023-4255W3m: out-of-bounds write in function checktype() in etc.c (incomplete fix for cve-2022-38223)5.5
- CVE-2023-38253W3m: out of bounds read in growbuf_to_str() at w3m/indep.c4.7
- CVE-2023-38252W3m: out of bounds read in strnew_size() at w3m/str.c4.7
- CVE-2022-38223There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or...7.8
- CVE-2018-6196w3m through 0.5.3 is prone to an infinite recursion flaw in HTMLlineproc0 because the feed_table_block_tag function in table.c does not prevent a negative indent value.7.5
- CVE-2018-6198w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.4.7
- CVE-2018-6197w3m through 0.5.3 is prone to a NULL pointer dereference flaw in formUpdateBuffer in form.c.7.5
- CVE-2016-9436parsetagx.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html file, related to a <i> tag.6.5
- CVE-2016-9435The HTMLtagproc1 function in file.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html file, related to <...6.5
- CVE-2016-9426An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Integer overflow vulnerability in the renderTable function in w3m allows remote attackers to cause a denial of service (OO...8.8
- CVE-2016-9623An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.6.5
- CVE-2016-9631An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.6.5
- CVE-2016-9424An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m doesn't properly validate the value of tag attribute, which allows remote attackers to cause a denial of service (heap...8.8
- CVE-2016-9422An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. The feed_table_tag function in w3m doesn't properly validate the value of table span, which allows remote attackers to cau...8.8
- CVE-2016-9428An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Heap-based buffer overflow in the addMultirowsForm function in w3m allows remote attackers to cause a denial of service (c...8.8
The record
- Peak rank
- #6 in Dec 2016
- Busiest month shown
- Dec 2016, 31 CVEs
- Months with a KEV entry
- 0 since Dec 2016
- Monthly snapshots
- 2 since 2016