« Volver al listado

CVE-2009-4737

Estado: ModificadaAlta (9.3)—

Stack-based buffer overflow in JustSystems Corporation Ichitaro 13, 2004 through 2009, Viewer 2009 19.0.1.0 and earlier, and other versions allows context-dependent attackers to execute arbitrary code via a crafted Rich Text File (RTF), related to "pvpara ffooter."

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-4737",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-04-06T22:30:00.437",
  "references": [
    {
      "url": "http://jvn.jp/en/jp/JVN33846134/index.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000018.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/34611",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.fourteenforty.jp/research/advisory.cgi?FFRRA-20090407",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.ipa.go.jp/security/vuln/documents/2009/200904_ichitaro.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.justsystems.com/jp/info/js09002.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/53349",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/34403",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/0957",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/49739",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://jvn.jp/en/jp/JVN33846134/index.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://jvndb.jvn.jp/ja/contents/2009/JVNDB-2009-000018.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/34611",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.fourteenforty.jp/research/advisory.cgi?FFRRA-20090407",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.ipa.go.jp/security/vuln/documents/2009/200904_ichitaro.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.justsystems.com/jp/info/js09002.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/53349",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/34403",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2009/0957",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/49739",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Stack-based buffer overflow in JustSystems Corporation Ichitaro 13, 2004 through 2009, Viewer 2009 19.0.1.0 and earlier, and other versions allows context-dependent attackers to execute arbitrary code via a crafted Rich Text File (RTF), related to \"pvpara ffooter.\""
    },
    {
      "lang": "es",
      "value": "Desbordamiento de búfer basado en pila en JustSystems Corporation Ichitaro v13, desde v2004 hasta v2009, Viewer 2009 v19.0.1.0  y anteriores y otras versiones, permite a atacantes dependientes de contexto ejecutar código arbitrario a través de un fichero de texto enriquecido manipulado (RTF), relacionado con \"pvpara ffooter.\""
    }
  ],
  "lastModified": "2026-06-16T23:14:15.543",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:justsystems:ichitaro:13:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9D65FA81-F110-4C21-8BD4-1A14BFFC7730"
            },
            {
              "criteria": "cpe:2.3:a:justsystems:ichitaro:2004:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AFAE853E-5415-4B31-A873-E74E7C66C52F"
            },
            {
              "criteria": "cpe:2.3:a:justsystems:ichitaro:2005:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "471FA5F8-8EC2-4FEB-93E0-B838F81BD472"
            },
            {
              "criteria": "cpe:2.3:a:justsystems:ichitaro:2006:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9E7E7611-56FC-4379-99FE-8D42046FA9C8"
            },
            {
              "criteria": "cpe:2.3:a:justsystems:ichitaro:2006:-:government:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AA38365F-0FB9-4570-8A38-4FCC9AADA267"
            },
            {
              "criteria": "cpe:2.3:a:justsystems:ichitaro:2007:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A749FA56-6DE2-48A4-902C-6EB7E6575BA3"
            },
            {
              "criteria": "cpe:2.3:a:justsystems:ichitaro:2007:-:government:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6A5C721C-CA01-4C6A-AC7C-C07FC3A333D3"
            },
            {
              "criteria": "cpe:2.3:a:justsystems:ichitaro:2008:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8B8FAFF2-94AD-4C8B-8B10-57651DEA6191"
            },
            {
              "criteria": "cpe:2.3:a:justsystems:ichitaro:2008:-:government:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "25F1AF4E-E4EC-4E66-B532-002A8512916F"
            },
            {
              "criteria": "cpe:2.3:a:justsystems:ichitaro:2009:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "12205BDB-6DD6-46B8-891B-E4EAAB8F3588"
            },
            {
              "criteria": "cpe:2.3:a:justsystems:ichitaro:2009:-:government:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9BC34189-32FE-4C8E-A87E-731C622ECBC0"
            },
            {
              "criteria": "cpe:2.3:a:justsystems:ichitaro:2009:-:trial:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B5B023D0-C271-45B2-82D9-9AD4D800893E"
            },
            {
              "criteria": "cpe:2.3:a:justsystems:ichitaro:bungei:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BABEE82A-8A24-4F87-9AF5-87B81217C378"
            },
            {
              "criteria": "cpe:2.3:a:justsystems:ichitaro_viewer:19.0.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7D726C33-139F-4514-BDFC-FE8F046B47CF"
            },
            {
              "criteria": "cpe:2.3:a:justsystems:ichitaro_viewer:20.0.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "52CAFFC5-453F-49DD-8A71-8FB98C045A4C"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}