HIGH🇵🇱 Wersja polska

CVE-2017-10870

CVSS 7.8v3.0pub. 2017-11-02upd. 2026-05-13

Memory corruption vulnerability in Rakuraku Hagaki (Rakuraku Hagaki 2018, Rakuraku Hagaki 2017, Rakuraku Hagaki 2016) and Rakuraku Hagaki Select for Ichitaro (Ichitaro 2017, Ichitaro 2016, Ichitaro 2015, Ichitaro Pro3, Ichitaro Pro2, Ichitaro Pro, Ichitaro 2011, Ichitaro Government 8, Ichitaro Government 7, Ichitaro Government 6 and Ichitaro 2017 Trial version) allows attackers to execute arbitrary code with privileges of the application via specially crafted file.

CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Justsystems Easy Postcard 2016

    APP
    Justsystems
    all versions
  • Justsystems Easy Postcard 2017

    APP
    Justsystems
    all versions
  • Justsystems Easy Postcard 2018

    APP
    Justsystems
    all versions
  • Justsystems Ichitaro 2016

    APP
    Justsystems
    all versions
  • Justsystems Ichitaro 2017

    APP
    Justsystems
    all versions
  • Justsystems Ichitaro 2017 Trial Version

    APP
    Justsystems
    all versions
  • Justsystems Ichitaro 2018

    APP
    Justsystems
    all versions
  • Justsystems Ichitaro Government 6

    APP
    Justsystems
    all versions
  • Justsystems Ichitaro Government 7

    APP
    Justsystems
    all versions
  • Justsystems Ichitaro Government 8

    APP
    Justsystems
    all versions
  • Justsystems Ichitaro Pro

    APP
    Justsystems
    all versions
  • Justsystems Ichitaro Pro 2

    APP
    Justsystems
    all versions
  • Justsystems Ichitaro Pro 2011

    APP
    Justsystems
    all versions
  • Justsystems Ichitaro Pro 3

    APP
    Justsystems
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2022-36344CRITICAL9.8PL ✓same product

Unquoted search path w JustSystems JUST Online Update — eskalacja uprawnień

CVE-2023-38128HIGH7.8same product

An out-of-bounds write vulnerability exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372...

CVE-2023-34366HIGH7.8same product

A use-after-free vulnerability exists in the Figure stream parsing functionality of Ichitaro 2023 1.0.1.59372....

CVE-2023-35126HIGH7.8same product

An out-of-bounds write vulnerability exists within the parsers for both the "DocumentViewStyles" and "Document...

CVE-2023-38127HIGH7.8same product

An integer overflow exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially cra...