mirror of
https://github.com/0xMarcio/cve.git
synced 2026-03-27 05:01:13 +01:00
843 B
843 B
CVE-2016-9424
Description
An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m doesn't properly validate the value of tag attribute, which allows remote attackers to cause a denial of service (heap buffer overflow crash) and possibly execute arbitrary code via a crafted HTML page.
POC
Reference
- http://www.securityfocus.com/bid/94407
- https://github.com/tats/w3m/blob/master/ChangeLog
- https://github.com/tats/w3m/issues/12