CVE-2006-6400
https://notcve.org/view.php?id=CVE-2006-6400
Buffer overflow in JustSystems Hanako 2004 through 2006, Hanako viewer 1.x, Ichitaro 2004, Ichitaro 2005, Ichitaro Lite2, Ichitaro viewer 4.x, and Sanshiro 2005 allows remote attackers to execute arbitrary code via the (1) Keyword and (2) Title fields, related to string length fields. Desbordamiento de búfer en JustSystems Hanako 2004 hasta 2006, Hanako viewer 1.x, Ichitaro 2004, Ichitaro 2005, Ichitaro Lite2, Ichitaro viewer 4.x, y Sanshiro 2005 permite a atacantes remotos ejecutar código de su elección mediante los campos (1) Keyword y (2) Title, relativos a campos de longitud de cadenas. • http://jvn.jp/jp/JVN%2347272891/index.html http://secunia.com/advisories/23185 http://securitytracker.com/id?1017336 http://www.justsystem.co.jp/info/pd6005.html http://www.lac.co.jp/business/sns/intelligence/SNSadvisory_e/92_e.html http://www.securityfocus.com/bid/21445 http://www.vupen.com/english/advisories/2006/4857 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2006-4326
https://notcve.org/view.php?id=CVE-2006-4326
Stack-based buffer overflow in Justsystem Ichitaro 9.x through 13.x, Ichitaro 2004, 2005, 2006, and Government 2006; Ichitaro for Linux; and FormLiner before 20060818 allows remote attackers to execute arbitrary code via long Unicode strings in a crafted document, as being actively exploited by malware such as Trojan.Tarodrop. NOTE: some details are obtained from third party information. Desbordamiento de búfer basado en pila en Justsystem Ichitaro 9.x hasta 13.x, Ichitaro 2004, 2005, 2006, y Government 2006; Ichitaro para Linux; y FormLiner anterior al 18/08/2006 permite a ataacntes remotos ejecutar código de su elección mediante cadenas Unicode largas en un documento manipulado, tal y como está siendo explotado activamente por software malicioso como Trojan.Tarodrop. NOTA: algunos detalles se han obtenido de información de terceros. • http://secunia.com/advisories/21552 http://www.justsystem.co.jp/info/pd6002.html http://www.securityfocus.com/bid/19550 http://www.symantec.com/enterprise/security_response/weblog/2006/08/justsystems_ichitaro_0day_used.html http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2006-081615-5201-99 http://www.vupen.com/english/advisories/2006/3332 https://exchange.xforce.ibmcloud.com/vulnerabilities/28484 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •