Vulnerabilities > Justsystems > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-08-16 CVE-2022-36344 Unquoted Search Path or Element vulnerability in Justsystems products
An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and others.
network
low complexity
justsystems CWE-428
critical
9.8
2017-02-24 CVE-2017-2790 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Justsystems Ichitaro
When processing a record type of 0x3c from a Workbook stream from an Excel file (.xls), JustSystems Ichitaro Office trusts that the size is greater than zero, subtracts one from the length, and uses this result as the size for a memcpy.
network
low complexity
justsystems CWE-119
critical
9.8
2017-02-24 CVE-2017-2789 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Justsystems Ichitaro
When copying filedata into a buffer, JustSystems Ichitaro Office 2016 Trial will calculate two values to determine how much data to copy from the document.
network
low complexity
justsystems CWE-119
critical
9.8