7.6
CVE-2014-2003
- EPSS 5.37%
- Veröffentlicht 16.06.2014 14:55:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
- Quelle vultures@jpcert.or.jp
- CVE-Watchlists
- Unerledigt
JustSystems JUST Online Update, as used in Ichitaro through 2014 and other products, does not properly validate signatures of update modules, which allows remote attackers to spoof modules and execute arbitrary code via a crafted signature.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Justsystems ≫ Ichitaro Version <= 2014
Justsystems ≫ Ichitaro Version10
Justsystems ≫ Ichitaro Version11
Justsystems ≫ Ichitaro Version12
Justsystems ≫ Ichitaro Version13
Justsystems ≫ Ichitaro Version2004
Justsystems ≫ Ichitaro Version2005
Justsystems ≫ Ichitaro Version2006
Justsystems ≫ Ichitaro Version2006 Update- Editiongovernment
Justsystems ≫ Ichitaro Version2007
Justsystems ≫ Ichitaro Version2007 Update- Editiongovernment
Justsystems ≫ Ichitaro Version2008
Justsystems ≫ Ichitaro Version2008 Update- Editiongovernment
Justsystems ≫ Ichitaro Version2009
Justsystems ≫ Ichitaro Version2009 Update- Editiongovernment
Justsystems ≫ Ichitaro Version2009 Update- Editiontrial
Justsystems ≫ Ichitaro Version2010
Justsystems ≫ Ichitaro Version2010 Update- Editiongovernment
Justsystems ≫ Ichitaro Version2011
Justsystems ≫ Ichitaro Version2011 Update- Editionsou
Justsystems ≫ Ichitaro Version2012 Update- Editionshou
Justsystems ≫ Ichitaro Version2013 Update- Editiongen
Justsystems ≫ Ichitaro Version2013 Update- Editiongen_trial
Justsystems ≫ Just Online Update Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.37% | 0.897 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.6 | 4.9 | 10 |
AV:N/AC:H/Au:N/C:C/I:C/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.