Skip to main content

Vendor archive

w3c CVEs

Beta · best-effort

10 CVEs tagged to vendor w3c2 Critical, 2 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2020-4070

Published Jun 22, 2020

In CSS Validator less than or equal to commit 54d68a1, there is a cross-site scripting vulnerability in handling URIs. A user would have to click on a specifically crafted validat…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6005

Published Jan 28, 2009

Multiple buffer overflows in the CheckUniqueName function in W3C Amaya Web Browser 10.0.1, and possibly other versions including 11.0.1, might allow remote attackers to execute ar…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-5282

Published Nov 29, 2008

Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0.1 allow remote attackers to execute arbitrary code via (1) a link with a long HREF attribute, and (2) a DIV tag…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2006-1900

Published Apr 20, 2006

Multiple buffer overflows in World Wide Web Consortium (W3C) Amaya 9.4, and possibly other versions including 8.x before 8.8.5, allow remote attackers to execute arbitrary code vi…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2005-3183

Published Oct 12, 2005

The HTBoundary_put_block function in HTBound.c for W3C libwww (w3c-libwww) allows remote servers to cause a denial of service (segmentation fault) via a crafted multipart/byterang…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-2274

Published Dec 31, 2004

Unknown vulnerability in Jigsaw before 2.2.4 has unknown impact and attack vectors, possibly related to the parsing of the URI.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1052

Published Oct 4, 2002

Jigsaw 2.2.1 on Windows systems allows remote attackers to use MS-DOS device names in HTTP requests to (1) cause a denial of service using the "con" device, or (2) obtain the phys…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1053

Published Oct 4, 2002

Cross-site scripting (XSS) vulnerability in W3C Jigsaw Proxy Server before 2.2.1 allows remote attackers to execute arbitrary script via a URL that contains a reference to a nonex…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2002-1445

Published Aug 12, 2002

Cross-site scripting (XSS) vulnerability in CERN Proxy Server allows remote attackers to execute script as other users via a link to a non-existent page whose name contains the sc…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-0079

Published Jan 18, 2000

The W3C CERN httpd HTTP server allows remote attackers to determine the real pathnames of some commands via a request for a nonexistent URL.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1