7.6

CVE-2014-2003

JustSystems JUST Online Update, as used in Ichitaro through 2014 and other products, does not properly validate signatures of update modules, which allows remote attackers to spoof modules and execute arbitrary code via a crafted signature.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Justsystems ≫ Ichitaro Version <= 2014
Justsystems ≫ Ichitaro Version 10
Justsystems ≫ Ichitaro Version 11
Justsystems ≫ Ichitaro Version 12
Justsystems ≫ Ichitaro Version 13
Justsystems ≫ Ichitaro Version 2004
Justsystems ≫ Ichitaro Version 2005
Justsystems ≫ Ichitaro Version 2006
Justsystems ≫ Ichitaro Version 2006 Update - Edition government
Justsystems ≫ Ichitaro Version 2007
Justsystems ≫ Ichitaro Version 2007 Update - Edition government
Justsystems ≫ Ichitaro Version 2008
Justsystems ≫ Ichitaro Version 2008 Update - Edition government
Justsystems ≫ Ichitaro Version 2009
Justsystems ≫ Ichitaro Version 2009 Update - Edition government
Justsystems ≫ Ichitaro Version 2009 Update - Edition trial
Justsystems ≫ Ichitaro Version 2010
Justsystems ≫ Ichitaro Version 2010 Update - Edition government
Justsystems ≫ Ichitaro Version 2011
Justsystems ≫ Ichitaro Version 2011 Update - Edition sou
Justsystems ≫ Ichitaro Version 2012 Update - Edition shou
Justsystems ≫ Ichitaro Version 2013 Update - Edition gen
Justsystems ≫ Ichitaro Version 2013 Update - Edition gen_trial
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.59% 0.879
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.6 4.9 10
AV:N/AC:H/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://jvn.jp/en/jp/JVN50129191/index.html
http://jvndb.jvn.jp/jvndb/JVNDB-2014-000053
http://www.ipa.go.jp/security/ciadr/vul/20140611-jvn.html
http://www.justsystems.com/jp/info/js14002.html
Vendor Advisory