rpm package
suse/w3m&distro=SUSE Linux Enterprise Module for Basesystem 15 SP4
pkg:rpm/suse/w3m&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP4
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-38253 | Med | 4.7 | < 0.5.3+git20230121-150000.3.6.1 | 0.5.3+git20230121-150000.3.6.1 | Jul 14, 2023 | An out-of-bounds read flaw was found in w3m, in the growbuf_to_Str function in indep.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file. | |
| CVE-2023-38252 | Med | 4.7 | < 0.5.3+git20230121-150000.3.6.1 | 0.5.3+git20230121-150000.3.6.1 | Jul 14, 2023 | An out-of-bounds read flaw was found in w3m, in the Strnew_size function in Str.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file. | |
| CVE-2022-38223 | Hig | 7.8 | < 0.5.3+git20180125-150000.3.3.1 | 0.5.3+git20180125-150000.3.3.1 | Aug 15, 2022 | There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact. |
- affected < 0.5.3+git20230121-150000.3.6.1fixed 0.5.3+git20230121-150000.3.6.1
An out-of-bounds read flaw was found in w3m, in the growbuf_to_Str function in indep.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.
- affected < 0.5.3+git20230121-150000.3.6.1fixed 0.5.3+git20230121-150000.3.6.1
An out-of-bounds read flaw was found in w3m, in the Strnew_size function in Str.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.
- affected < 0.5.3+git20180125-150000.3.3.1fixed 0.5.3+git20180125-150000.3.3.1
There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.