← Vulnerability feed

Vulnerability record · CVE-2016-9429 · published 12 December 2016

CVE-2016-9429: Tats w3m memory buffer overflow vulnerability

TTats · W3m

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Buffer overflow in the formUpdateBuffer function in w3m allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTML page.

8.8 CVSS 3.0 High EPSS 3.8% · top 10.3% CWE-119 · Memory buffer overflow
8.8CVSS 3.0 base score, v2 6.8
3.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Buffer overflow in the formUpdateBuffer function in w3m allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTML page.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-9429 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2016-9428Tats w3m memory buffer overflow vulnerabilityAn issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Heap-based buffer overflow in the addMultirowsForm function in w3m allows …EPSS 3.3%8.8CVE-2016-9426Tats w3m integer overflow vulnerabilityAn issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Integer overflow vulnerability in the renderTable function in w3m allows r…EPSS 2.9%8.8CVE-2016-9425Tats w3m memory buffer overflow vulnerabilityAn issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Heap-based buffer overflow in the addMultirowsForm function in w3m allows …EPSS 3.3%8.8CVE-2016-9424Tats w3m memory buffer overflow vulnerabilityAn issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m doesn't properly validate the value of tag attribute, which allows rem…EPSS 3.2%8.8CVE-2016-9423Tats w3m memory buffer overflow vulnerabilityAn issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Heap-based buffer overflow in w3m allows remote attackers to cause a denia…EPSS 3.2%8.8CVE-2016-9422Tats w3m memory buffer overflow vulnerabilityAn issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. The feed_table_tag function in w3m doesn't properly validate the value of …EPSS 3.2%7.8CVE-2022-38223Tats w3m out-of-bounds write vulnerabilityThere is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It …EPSS 0.47%7.5CVE-2018-6196Tats w3m vulnerabilityw3m through 0.5.3 is prone to an infinite recursion flaw in HTMLlineproc0 because the feed_table_block_tag function in table.c does not prevent a neg…EPSS 2.9%

Source: NIST National Vulnerability Database (record CVE-2016-9429), CISA KEV, FIRST EPSS (scores of 2026-10-09). This page is refreshed as NVD updates the record.