W3 records
8 published records for vendor w3.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 12.5%
- Pre-auth RCE
- 2
- With a fix record
- 12.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-835 Loop with Unreachable Exit Condition ('Infinite Loop')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
59Plan | CVE-2009-0323Weaponized | Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0 and 11.0 allow remote attackers to execute arbitrary code via (1) a longw3 · amaya · CWE-119 | Critical10.0 | — | 62.5% | Jan 28, 2009 |
41Plan | CVE-2009-1209Proof of concept | Stack-based buffer overflow in W3C Amaya Web Browser 11.1 allows remote attackers to execute arbitrary code via a script tag with a long defw3 · amaya · CWE-119 | Critical9.3 | — | 12.4% | Apr 1, 2009 |
33Monitor | CVE-2025-1781No exploit | There is a XXE in W3CSS Validator versions before cssval-20250226 that allows an attacker to use specially-crafted XML objects to coerce serw3 · css validator · CWE-611 | High8.4 | — | 0.4% | Mar 28, 2025 |
31Monitor | CVE-2016-9487No exploit | EpubCheck 4.0.1 is vulnerable to external XML entity processing attacksw3 · epubcheck · CWE-611 | High7.8 | — | 1.3% | Jul 13, 2018 |
24Monitor | CVE-2021-4296No exploit | w3c Unicorn ValidatorNuMessage.java ValidatorNuMessage cross site scriptingw3 · unicorn · CWE-79 | Medium6.1 | — | 0.5% | Dec 29, 2022 |
24Monitor | CVE-2014-125108No exploit | w3c online-spellchecker-py spellchecker cross site scriptingw3 · spell checker · CWE-79 | Medium6.1 | — | 0.5% | Dec 23, 2023 |
22Monitor | CVE-2023-30300No exploit | An issue in the component hang.wasm of WebAssembly 1.0 causes an infinite loop.w3 · webassembly · CWE-835 | Medium5.5 | — | 0.3% | May 3, 2023 |
15Monitor | CVE-2017-5928No exploit | The W3C High Resolution Time API, as implemented in various web browsers, does not consider that memory-reference times can be measured by aw3 · high resolution time api | Low3.7 | — | 1.7% | Feb 27, 2017 |
- CVE-2009-032359Plan
Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0 and 11.0 allow remote attackers to execute arbitrary code via (1) a long
CriticalCVSS 10.0WeaponizedEPSS 62%w3 · amayaJan 28, 2009
- CVE-2009-120941Plan
Stack-based buffer overflow in W3C Amaya Web Browser 11.1 allows remote attackers to execute arbitrary code via a script tag with a long def
CriticalCVSS 9.3Proof of conceptEPSS 12%w3 · amayaApr 1, 2009
- CVE-2025-178133Monitor
There is a XXE in W3CSS Validator versions before cssval-20250226 that allows an attacker to use specially-crafted XML objects to coerce ser
HighCVSS 8.4No exploitEPSS 0%w3 · css validatorMar 28, 2025
- CVE-2016-948731Monitor
EpubCheck 4.0.1 is vulnerable to external XML entity processing attacks
HighCVSS 7.8No exploitEPSS 1%w3 · epubcheckJul 13, 2018
- CVE-2021-429624Monitor
w3c Unicorn ValidatorNuMessage.java ValidatorNuMessage cross site scripting
MediumCVSS 6.1No exploitEPSS 1%w3 · unicornDec 29, 2022
- CVE-2014-12510824Monitor
w3c online-spellchecker-py spellchecker cross site scripting
MediumCVSS 6.1No exploitEPSS 0%w3 · spell checkerDec 23, 2023
- CVE-2023-3030022Monitor
An issue in the component hang.wasm of WebAssembly 1.0 causes an infinite loop.
MediumCVSS 5.5No exploitEPSS 0%w3 · webassemblyMay 3, 2023
- CVE-2017-592815Monitor
The W3C High Resolution Time API, as implemented in various web browsers, does not consider that memory-reference times can be measured by a
LowCVSS 3.7No exploitEPSS 2%w3 · high resolution time apiFeb 27, 2017