Vulnerabilities > Justsystem
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2008-01-10 | CVE-2008-0223 | Buffer Errors vulnerability in Justsystem Ichitaro, Ichitaro Lite2 and Ichitaro Viewer Buffer overflow in JustSystems JSFC.DLL, as used in multiple JustSystems products such as Ichitaro, allows remote attackers to execute arbitrary code via a crafted .JTD file. | 9.3 |
2007-12-18 | CVE-2007-6436 | Buffer Errors vulnerability in Justsystem Ichitaro 2005/2006/2007 Stack-based buffer overflow in JSGCI.DLL in JustSystems Ichitaro 2005, 2006, and 2007 allows user-assisted remote attackers to execute arbitrary code via a crafted document, as actively exploited in December 2007 by the Tarodrop.F trojan. | 9.3 |
2007-10-28 | CVE-2007-5687 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Justsystem Ichitaro Multiple buffer overflows in the rich text processing functionality in JustSystems Ichitaro 2004 through 2007, 11 through 13, and other versions allow remote attackers to execute arbitrary code via a long (1) pard field or (2) font name in the fcharset0 field, which is not properly handled in (a) JSTARO4.OCX; or (3) a long title, which is not properly handled by (b) TJSVDA.DLL. | 9.3 |
2007-08-08 | CVE-2007-4246 | Code Execution vulnerability in Justsystem Ichitaro 2007 Unspecified vulnerability, possibly a buffer overflow, in Justsystem Ichitaro 2007 and earlier allows remote attackers to execute arbitrary code via a modified document, as actively exploited in August 2007 by malware such as Tarodrop.D (Tarodrop.Q), a different vulnerability than CVE-2006-4326, CVE-2006-5424, CVE-2006-6400, and CVE-2007-1938. network justsystem | 6.8 |
2006-12-10 | CVE-2006-6400 | Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Justsystem products Buffer overflow in JustSystems Hanako 2004 through 2006, Hanako viewer 1.x, Ichitaro 2004, Ichitaro 2005, Ichitaro Lite2, Ichitaro viewer 4.x, and Sanshiro 2005 allows remote attackers to execute arbitrary code via the (1) Keyword and (2) Title fields, related to string length fields. | 6.8 |
2006-10-20 | CVE-2006-5424 | Resource Management Errors vulnerability in Justsystem Ichitaro 2006/2006Governmentedition/2006Trialedition Unspecified vulnerability in Justsystem Ichitaro 2006, 2006 trial version, and Government 2006 allows remote attackers to execute arbitrary code via a modified document, possibly because of a buffer overflow, a different vulnerability than CVE-2006-4326. | 5.1 |
2006-08-24 | CVE-2006-4326 | Buffer Errors vulnerability in Justsystem Formliner, Ichitaro and Ichitaro Government Stack-based buffer overflow in Justsystem Ichitaro 9.x through 13.x, Ichitaro 2004, 2005, 2006, and Government 2006; Ichitaro for Linux; and FormLiner before 20060818 allows remote attackers to execute arbitrary code via long Unicode strings in a crafted document, as being actively exploited by malware such as Trojan.Tarodrop. | 7.5 |