An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-33. w3m allows remote attackers to cause a denial of service (global buffer overflow and crash) via a crafted HTML page.
https://github.com/tats/w3m/issues/41
https://github.com/tats/w3m/blob/master/ChangeLog