tats CVE Vulnerabilities & Metrics

Focus on tats vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About tats Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with tats. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total tats CVEs: 40
Earliest CVE date: 12 Dec 2016, 02:59 UTC
Latest CVE date: 21 Dec 2023, 16:15 UTC

Latest CVE reference: CVE-2023-4255

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical tats CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.32

Max CVSS: 6.8

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 5
4.0-6.9 35
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS tats CVEs

These are the five CVEs with the highest CVSS scores for tats, sorted by severity first and recency.

All CVEs for tats

CVE-2023-4255 tats vulnerability CVSS: 0 21 Dec 2023, 16:15 UTC

An out-of-bounds write issue has been discovered in the backspace handling of the checkType() function in etc.c within the W3M application. This vulnerability is triggered by supplying a specially crafted HTML file to the w3m binary. Exploitation of this flaw could lead to application crashes, resulting in a denial of service condition.

CVE-2023-38253 tats vulnerability CVSS: 0 14 Jul 2023, 18:15 UTC

An out-of-bounds read flaw was found in w3m, in the growbuf_to_Str function in indep.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.

CVE-2023-38252 tats vulnerability CVSS: 0 14 Jul 2023, 18:15 UTC

An out-of-bounds read flaw was found in w3m, in the Strnew_size function in Str.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.

CVE-2022-38223 tats vulnerability CVSS: 0 15 Aug 2022, 11:21 UTC

There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.

CVE-2018-6198 tats vulnerability CVSS: 3.3 25 Jan 2018, 03:29 UTC

w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.

CVE-2018-6197 tats vulnerability CVSS: 5.0 25 Jan 2018, 03:29 UTC

w3m through 0.5.3 is prone to a NULL pointer dereference flaw in formUpdateBuffer in form.c.

CVE-2018-6196 tats vulnerability CVSS: 5.0 25 Jan 2018, 03:29 UTC

w3m through 0.5.3 is prone to an infinite recursion flaw in HTMLlineproc0 because the feed_table_block_tag function in table.c does not prevent a negative indent value.

CVE-2016-9436 tats vulnerability CVSS: 4.3 20 Jan 2017, 15:59 UTC

parsetagx.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html file, related to a <i> tag.

CVE-2016-9435 tats vulnerability CVSS: 4.3 20 Jan 2017, 15:59 UTC

The HTMLtagproc1 function in file.c in w3m before 0.5.3+git20161009 does not properly initialize values, which allows remote attackers to crash the application via a crafted html file, related to <dd> tags.

CVE-2016-9633 tats vulnerability CVSS: 4.3 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (infinite loop and resource consumption) via a crafted HTML page.

CVE-2016-9632 tats vulnerability CVSS: 4.3 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (global buffer overflow and crash) via a crafted HTML page.

CVE-2016-9631 tats vulnerability CVSS: 4.3 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.

CVE-2016-9630 tats vulnerability CVSS: 4.3 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (global buffer overflow and crash) via a crafted HTML page.

CVE-2016-9629 tats vulnerability CVSS: 4.3 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.

CVE-2016-9628 tats vulnerability CVSS: 4.3 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.

CVE-2016-9627 tats vulnerability CVSS: 4.3 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (heap buffer overflow and crash) via a crafted HTML page.

CVE-2016-9626 tats vulnerability CVSS: 4.3 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. Infinite recursion vulnerability in w3m allows remote attackers to cause a denial of service via a crafted HTML page.

CVE-2016-9625 tats vulnerability CVSS: 4.3 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. Infinite recursion vulnerability in w3m allows remote attackers to cause a denial of service via a crafted HTML page.

CVE-2016-9624 tats vulnerability CVSS: 4.3 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.

CVE-2016-9623 tats vulnerability CVSS: 4.3 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.

CVE-2016-9622 tats vulnerability CVSS: 4.3 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.

CVE-2016-9443 tats vulnerability CVSS: 4.3 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.

CVE-2016-9442 tats vulnerability CVSS: 4.3 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause memory corruption in certain conditions via a crafted HTML page.

CVE-2016-9441 tats vulnerability CVSS: 4.3 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.

CVE-2016-9440 tats vulnerability CVSS: 4.3 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.

CVE-2016-9439 tats vulnerability CVSS: 4.3 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Infinite recursion vulnerability in w3m allows remote attackers to cause a denial of service via a crafted HTML page.

CVE-2016-9438 tats vulnerability CVSS: 4.3 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.

CVE-2016-9437 tats vulnerability CVSS: 4.3 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) and possibly memory corruption via a crafted HTML page.

CVE-2016-9434 tats vulnerability CVSS: 4.3 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.

CVE-2016-9433 tats vulnerability CVSS: 4.3 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (out-of-bounds array access) via a crafted HTML page.

CVE-2016-9432 tats vulnerability CVSS: 4.3 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (memory corruption, segmentation fault, and crash) via a crafted HTML page.

CVE-2016-9431 tats vulnerability CVSS: 4.3 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Infinite recursion vulnerability in w3m allows remote attackers to cause a denial of service via a crafted HTML page.

CVE-2016-9430 tats vulnerability CVSS: 4.3 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.

CVE-2016-9429 tats vulnerability CVSS: 6.8 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Buffer overflow in the formUpdateBuffer function in w3m allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTML page.

CVE-2016-9428 tats vulnerability CVSS: 6.8 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Heap-based buffer overflow in the addMultirowsForm function in w3m allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTML page.

CVE-2016-9426 tats vulnerability CVSS: 6.8 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Integer overflow vulnerability in the renderTable function in w3m allows remote attackers to cause a denial of service (OOM) and possibly execute arbitrary code due to bdwgc's bug (CVE-2016-9427) via a crafted HTML page.

CVE-2016-9425 tats vulnerability CVSS: 6.8 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Heap-based buffer overflow in the addMultirowsForm function in w3m allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTML page.

CVE-2016-9424 tats vulnerability CVSS: 6.8 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m doesn't properly validate the value of tag attribute, which allows remote attackers to cause a denial of service (heap buffer overflow crash) and possibly execute arbitrary code via a crafted HTML page.

CVE-2016-9423 tats vulnerability CVSS: 6.8 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Heap-based buffer overflow in w3m allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTML page.

CVE-2016-9422 tats vulnerability CVSS: 6.8 12 Dec 2016, 02:59 UTC

An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. The feed_table_tag function in w3m doesn't properly validate the value of table span, which allows remote attackers to cause a denial of service (stack and/or heap buffer overflow) and possibly execute arbitrary code via a crafted HTML page.