Vulnerabilities > Justsystems > Ichitaro > 13

DATE CVE VULNERABILITY TITLE RISK
2014-06-16 CVE-2014-2003 Improper Input Validation vulnerability in Justsystems Ichitaro and Just Online Update
JustSystems JUST Online Update, as used in Ichitaro through 2014 and other products, does not properly validate signatures of update modules, which allows remote attackers to spoof modules and execute arbitrary code via a crafted signature.
network
high complexity
justsystems CWE-20
7.6
2010-04-06 CVE-2009-4737 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Justsystems Ichitaro and Ichitaro Viewer
Stack-based buffer overflow in JustSystems Corporation Ichitaro 13, 2004 through 2009, Viewer 2009 19.0.1.0 and earlier, and other versions allows context-dependent attackers to execute arbitrary code via a crafted Rich Text File (RTF), related to "pvpara ffooter."
network
justsystems CWE-119
critical
9.3