CVE Tools

Tats

34 CVEs tracked since 2016. Since Dec 2016, none of them reached CISA KEV.

Tats CVEs per month

Dec 2016 to Jan 2018. Point at a month, or focus the strip and use the arrow keys.
Tats CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2016-12310
2017-01null or fewer
2017-02null or fewer
2017-03null or fewer
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-07null or fewer
2017-08null or fewer
2017-09null or fewer
2017-10null or fewer
2017-11null or fewer
2017-12null or fewer
2018-0130

Products

The products that kept showing up in Tats's monthly top three, with their CVEs summed over those months.

  1. W3M342 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Tats.

  1. CVE-2023-4255W3m: out-of-bounds write in function checktype() in etc.c (incomplete fix for cve-2022-38223)5.5
  2. CVE-2023-38253W3m: out of bounds read in growbuf_to_str() at w3m/indep.c4.7
  3. CVE-2023-38252W3m: out of bounds read in strnew_size() at w3m/str.c4.7
  4. CVE-2022-38223There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or...7.8
  5. CVE-2018-6196w3m through 0.5.3 is prone to an infinite recursion flaw in HTMLlineproc0 because the feed_table_block_tag function in table.c does not prevent a negative indent value.7.5
  6. CVE-2018-6198w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.4.7
  7. CVE-2018-6197w3m through 0.5.3 is prone to a NULL pointer dereference flaw in formUpdateBuffer in form.c.7.5
  8. CVE-2016-9436parsetagx.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html file, related to a <i> tag.6.5
  9. CVE-2016-9435The HTMLtagproc1 function in file.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html file, related to <...6.5
  10. CVE-2016-9426An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Integer overflow vulnerability in the renderTable function in w3m allows remote attackers to cause a denial of service (OO...8.8
  11. CVE-2016-9623An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.6.5
  12. CVE-2016-9631An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.6.5
  13. CVE-2016-9424An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m doesn't properly validate the value of tag attribute, which allows remote attackers to cause a denial of service (heap...8.8
  14. CVE-2016-9422An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. The feed_table_tag function in w3m doesn't properly validate the value of table span, which allows remote attackers to cau...8.8
  15. CVE-2016-9428An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Heap-based buffer overflow in the addMultirowsForm function in w3m allows remote attackers to cause a denial of service (c...8.8

The record

Peak rank
#6 in Dec 2016
Busiest month shown
Dec 2016, 31 CVEs
Months with a KEV entry
0 since Dec 2016
Monthly snapshots
2 since 2016
Tats's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store