← Back

W3c

w3c

10 CVEs • 6 products

Products (6)

Click to collapse
Toggle
Jigsaw
jigsaw
Cern Httpd
cern_httpd
Libwww
libwww
Amaya
amaya
Css Validator
css_validator

CVEs (10)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1W3c
1Css Validator
Jun 17, 2026
Jun 22, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In CSS Validator less than or equal to commit 54d68a1, there is a cross-site scripting vulnerability in handling URIs. A user would have to click on a specifically crafted validator link to trigger it. This has been patc...Show more
In CSS Validator less than or equal to commit 54d68a1, there is a cross-site scripting vulnerability in handling URIs. A user would have to click on a specifically crafted validator link to trigger it. This has been patched in commit e5c09a9.Show less
1W3c
1Amaya Web Browser
Apr 23, 2026
Jan 28, 2009
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple buffer overflows in the CheckUniqueName function in W3C Amaya Web Browser 10.0.1, and possibly other versions including 11.0.1, might allow remote attackers to execute arbitrary code via "duplicated" attribute v...Show more
Multiple buffer overflows in the CheckUniqueName function in W3C Amaya Web Browser 10.0.1, and possibly other versions including 11.0.1, might allow remote attackers to execute arbitrary code via "duplicated" attribute value inputs.Show less
1W3c
1Amaya Web Browser
Apr 23, 2026
Nov 29, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0.1 allow remote attackers to execute arbitrary code via (1) a link with a long HREF attribute, and (2) a DIV tag with a long id attribute.
1W3c
1Amaya
Apr 16, 2026
Apr 20, 2006
N/A· v4
N/A· v3
7.6 HIGH· v2
Multiple buffer overflows in World Wide Web Consortium (W3C) Amaya 9.4, and possibly other versions including 8.x before 8.8.5, allow remote attackers to execute arbitrary code via a long value in (1) the COMPACT attribu...Show more
Multiple buffer overflows in World Wide Web Consortium (W3C) Amaya 9.4, and possibly other versions including 8.x before 8.8.5, allow remote attackers to execute arbitrary code via a long value in (1) the COMPACT attribute of the COLGROUP element, (2) the ROWS attribute of the TEXTAREA element, and (3) the COLOR attribute of the LEGEND element; and via other unspecified attack vectors consisting of "dozens of possible snippets."Show less
1W3c
1Libwww
Apr 16, 2026
Oct 12, 2005
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The HTBoundary_put_block function in HTBound.c for W3C libwww (w3c-libwww) allows remote servers to cause a denial of service (segmentation fault) via a crafted multipart/byteranges MIME message that triggers an out-of-b...Show more
The HTBoundary_put_block function in HTBound.c for W3C libwww (w3c-libwww) allows remote servers to cause a denial of service (segmentation fault) via a crafted multipart/byteranges MIME message that triggers an out-of-bounds read.Show less
1W3c
1Jigsaw
Apr 16, 2026
Dec 31, 2004
N/A· v4
N/A· v3
6.4 MEDIUM· v2
Unknown vulnerability in Jigsaw before 2.2.4 has unknown impact and attack vectors, possibly related to the parsing of the URI.
1W3c
1Jigsaw
Apr 16, 2026
Oct 4, 2002
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in W3C Jigsaw Proxy Server before 2.2.1 allows remote attackers to execute arbitrary script via a URL that contains a reference to a nonexistent host followed by the script, which...Show more
Cross-site scripting (XSS) vulnerability in W3C Jigsaw Proxy Server before 2.2.1 allows remote attackers to execute arbitrary script via a URL that contains a reference to a nonexistent host followed by the script, which is included in the resulting error message.Show less
1W3c
1Jigsaw
Apr 16, 2026
Oct 4, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Jigsaw 2.2.1 on Windows systems allows remote attackers to use MS-DOS device names in HTTP requests to (1) cause a denial of service using the "con" device, or (2) obtain the physical path of the server using two request...Show more
Jigsaw 2.2.1 on Windows systems allows remote attackers to use MS-DOS device names in HTTP requests to (1) cause a denial of service using the "con" device, or (2) obtain the physical path of the server using two requests to the "aux" device.Show less
1W3c
1Cern Httpd
Apr 16, 2026
Aug 12, 2002
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in CERN Proxy Server allows remote attackers to execute script as other users via a link to a non-existent page whose name contains the script, which is inserted into the resultin...Show more
Cross-site scripting (XSS) vulnerability in CERN Proxy Server allows remote attackers to execute script as other users via a link to a non-existent page whose name contains the script, which is inserted into the resulting error page.Show less
1W3c
1Cern Httpd
Apr 16, 2026
Jan 18, 2000
N/A· v4
N/A· v3
7.5 HIGH· v2
The W3C CERN httpd HTTP server allows remote attackers to determine the real pathnames of some commands via a request for a nonexistent URL.