CVE-2023-38252 (https://github.com/tats/w3m/issues/270): An out-of-bounds read flaw was found in w3m, in the Strnew_size function in Str.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file. CVE-2023-38253 (https://github.com/tats/w3m/issues/271): An out-of-bounds read flaw was found in w3m, in the growbuf_to_Str function in indep.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file. Fixes in https://github.com/tats/w3m/commit/25fb402cea405b263466c627f32513d186a38ade from https://github.com/tats/w3m/pull/273, seemingly not in any release.