CVE-2006-6400
Buffer overflow in JustSystems Hanako 2004 through 2006, Hanako viewer 1.x, Ichitaro 2004, Ichitaro 2005, Ichitaro Lite2, Ichitaro viewer 4.x, and Sanshiro 2005 allows remote attackers to execute arbitrary code via the (1) Keyword and (2) Title fields,…
Does this matter?
Lower severity and a low EPSS score (3.06%). Track it; it rarely justifies an emergency change on its own.
Description
Buffer overflow in JustSystems Hanako 2004 through 2006, Hanako viewer 1.x, Ichitaro 2004, Ichitaro 2005, Ichitaro Lite2, Ichitaro viewer 4.x, and Sanshiro 2005 allows remote attackers to execute arbitrary code via the (1) Keyword and (2) Title fields, related to string length fields.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 3.06% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- justsystem/hanako · justsystem/hanako viewer · justsystem/ichitaro · justsystem/ichitaro lite2 · justsystem/ichitaro viewer · justsystem/sanshiro
- Source
- cve@mitre.org
References
- http://jvn.jp/jp/JVN%2347272891/index.html
- http://secunia.com/advisories/23185Vendor Advisory
- http://securitytracker.com/id?1017336
- http://www.justsystem.co.jp/info/pd6005.html
- http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/92_e.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/21445
- http://www.vupen.com/english/advisories/2006/4857
- http://jvn.jp/jp/JVN%2347272891/index.html
- http://secunia.com/advisories/23185Vendor Advisory
- http://securitytracker.com/id?1017336
- http://www.justsystem.co.jp/info/pd6005.html
- http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/92_e.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/21445
- http://www.vupen.com/english/advisories/2006/4857
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.