Vulnerability Details CVE-2023-38127
An integer overflow exists in the "HyperLinkFrame" stream parser of Ichitaro 2023 1.0.1.59372. A specially crafted document can cause the parser to make an under-sized allocation, which can later allow for memory corruption, potentially resulting in arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 41.6%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2023-38127
-
cpe:2.3:a:justsystems:easy_postcard_max:-
-
cpe:2.3:a:justsystems:ichitaro_2021:-
-
cpe:2.3:a:justsystems:ichitaro_2022:-
-
cpe:2.3:a:justsystems:ichitaro_2023:1.0.1.59372
-
cpe:2.3:a:justsystems:ichitaro_government_10:-
-
cpe:2.3:a:justsystems:ichitaro_government_8:-
-
cpe:2.3:a:justsystems:ichitaro_government_9:-
-
cpe:2.3:a:justsystems:ichitaro_pro_3:-
-
cpe:2.3:a:justsystems:ichitaro_pro_4:-
-
cpe:2.3:a:justsystems:ichitaro_pro_5:-
-
cpe:2.3:a:justsystems:just_government_3:-
-
cpe:2.3:a:justsystems:just_government_4:-
-
cpe:2.3:a:justsystems:just_government_5:-
-
cpe:2.3:a:justsystems:just_office_3:-
-
cpe:2.3:a:justsystems:just_office_4:-
-
cpe:2.3:a:justsystems:just_office_5:-
-
cpe:2.3:a:justsystems:just_police_3:-
-
cpe:2.3:a:justsystems:just_police_4:-
-
cpe:2.3:a:justsystems:just_police_5:-