Lucene search

K

W3c Security Vulnerabilities

cve
cve

CVE-2014-125108

A vulnerability was found in w3c online-spellchecker-py up to 20140130. It has been rated as problematic. This issue affects some unknown processing of the file spellchecker. The manipulation leads to cross site scripting. The attack may be initiated remotely. The complexity of an attack is rather....

6.1CVSS

6AI Score

0.001EPSS

2023-12-23 05:15 PM
17
cve
cve

CVE-2021-4296

A vulnerability, which was classified as problematic, has been found in w3c Unicorn. This issue affects the function ValidatorNuMessage of the file src/org/w3c/unicorn/response/impl/ValidatorNuMessage.java. The manipulation of the argument message leads to cross site scripting. The attack may be...

6.1CVSS

6AI Score

0.001EPSS

2022-12-29 09:15 AM
30
cve
cve

CVE-2020-4070

In CSS Validator less than or equal to commit 54d68a1, there is a cross-site scripting vulnerability in handling URIs. A user would have to click on a specifically crafted validator link to trigger it. This has been patched in commit...

5.4CVSS

5.1AI Score

0.001EPSS

2020-06-22 04:15 PM
24
cve
cve

CVE-2008-6005

Multiple buffer overflows in the CheckUniqueName function in W3C Amaya Web Browser 10.0.1, and possibly other versions including 11.0.1, might allow remote attackers to execute arbitrary code via "duplicated" attribute value...

7.9AI Score

0.039EPSS

2009-01-28 08:30 PM
30
cve
cve

CVE-2008-5282

Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0.1 allow remote attackers to execute arbitrary code via (1) a link with a long HREF attribute, and (2) a DIV tag with a long id...

7.5AI Score

0.747EPSS

2008-11-29 02:30 AM
25
cve
cve

CVE-2006-1900

Multiple buffer overflows in World Wide Web Consortium (W3C) Amaya 9.4, and possibly other versions including 8.x before 8.8.5, allow remote attackers to execute arbitrary code via a long value in (1) the COMPACT attribute of the COLGROUP element, (2) the ROWS attribute of the TEXTAREA element,...

7.7AI Score

0.207EPSS

2006-04-20 10:02 AM
26
cve
cve

CVE-2005-3183

The HTBoundary_put_block function in HTBound.c for W3C libwww (w3c-libwww) allows remote servers to cause a denial of service (segmentation fault) via a crafted multipart/byteranges MIME message that triggers an out-of-bounds...

6.1AI Score

0.003EPSS

2005-10-12 10:02 PM
21
cve
cve

CVE-2004-2274

Unknown vulnerability in Jigsaw before 2.2.4 has unknown impact and attack vectors, possibly related to the parsing of the...

6.6AI Score

0.005EPSS

2005-07-19 04:00 AM
24
cve
cve

CVE-2002-1053

Cross-site scripting (XSS) vulnerability in W3C Jigsaw Proxy Server before 2.2.1 allows remote attackers to execute arbitrary script via a URL that contains a reference to a nonexistent host followed by the script, which is included in the resulting error...

6.5AI Score

0.01EPSS

2003-04-02 05:00 AM
21
cve
cve

CVE-2002-1445

Cross-site scripting (XSS) vulnerability in CERN Proxy Server allows remote attackers to execute script as other users via a link to a non-existent page whose name contains the script, which is inserted into the resulting error...

6.2AI Score

0.006EPSS

2003-03-18 05:00 AM
19
cve
cve

CVE-2002-1052

Jigsaw 2.2.1 on Windows systems allows remote attackers to use MS-DOS device names in HTTP requests to (1) cause a denial of service using the "con" device, or (2) obtain the physical path of the server using two requests to the "aux"...

6.5AI Score

0.017EPSS

2002-10-04 04:00 AM
32
cve
cve

CVE-2000-0079

The W3C CERN httpd HTTP server allows remote attackers to determine the real pathnames of some commands via a request for a nonexistent...

6.9AI Score

0.007EPSS

2000-02-04 05:00 AM
28