← Vulnerability feed

Vulnerability record · CVE-2016-9626 · published 12 December 2016

CVE-2016-9626: Tats w3m memory buffer overflow vulnerability

TTats · W3m

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. Infinite recursion vulnerability in w3m allows remote attackers to cause a denial of service via a crafted HTML page.

6.5 CVSS 3.0 Medium EPSS 2.4% · top 16.4% CWE-119 · Memory buffer overflow
6.5CVSS 3.0 base score, v2 4.3
2.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. Infinite recursion vulnerability in w3m allows remote attackers to cause a denial of service via a crafted HTML page.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-9626 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2016-9429Tats w3m memory buffer overflow vulnerabilityAn issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Buffer overflow in the formUpdateBuffer function in w3m allows remote atta…EPSS 3.8%8.8CVE-2016-9428Tats w3m memory buffer overflow vulnerabilityAn issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Heap-based buffer overflow in the addMultirowsForm function in w3m allows …EPSS 3.3%8.8CVE-2016-9426Tats w3m integer overflow vulnerabilityAn issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Integer overflow vulnerability in the renderTable function in w3m allows r…EPSS 2.9%8.8CVE-2016-9425Tats w3m memory buffer overflow vulnerabilityAn issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Heap-based buffer overflow in the addMultirowsForm function in w3m allows …EPSS 3.3%8.8CVE-2016-9424Tats w3m memory buffer overflow vulnerabilityAn issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m doesn't properly validate the value of tag attribute, which allows rem…EPSS 3.2%8.8CVE-2016-9423Tats w3m memory buffer overflow vulnerabilityAn issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Heap-based buffer overflow in w3m allows remote attackers to cause a denia…EPSS 3.2%8.8CVE-2016-9422Tats w3m memory buffer overflow vulnerabilityAn issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. The feed_table_tag function in w3m doesn't properly validate the value of …EPSS 3.2%7.8CVE-2022-38223Tats w3m out-of-bounds write vulnerabilityThere is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It …EPSS 0.47%

Source: NIST National Vulnerability Database (record CVE-2016-9626), CISA KEV, FIRST EPSS (scores of 2026-10-09). This page is refreshed as NVD updates the record.