cve-2006-4326
HIGH CVSS 7.5 opencve
Description
Stack-based buffer overflow in Justsystem Ichitaro 9.x through 13.x, Ichitaro 2004, 2005, 2006, and Government 2006; Ichitaro for Linux; and FormLiner before 20060818 allows remote attackers to execute arbitrary code via long Unicode strings in a crafted document, as being actively exploited by malware such as Trojan.Tarodrop. NOTE: some details are obtained from third party information.
Timeline
- Published
- 2006-08-24 01:04 UTC
- Last Modified
- 2026-06-16
CVSS Details
CVSS details not available.
Affected Products
No product information available.
Weaknesses (CWE)
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"advisories": [
{
"id": "EUVD-2006-4314",
"source": "euvd",
"title": "Stack-based buffer overflow in Justsystem Ichitaro 9.x through 13.x, Ichitaro 2004, 2005, 2006, and Government 2006; Ichitaro for Linux; and FormLiner before 20060818 allows remote attackers to execute arbitrary code via long Unicode strings in a crafted document, as being actively exploited by malware such as Trojan.Tarodrop. NOTE: some details are obtained from third party information.",
"url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-4314"
}
],
"cve": "CVE-2006-4326",
"epss": {
"score": 0.04564
},
"mitre": {
"cpes": [],
"created": "2006-08-24T01:00:00+00:00",
"description": "Stack-based buffer overflow in Justsystem Ichitaro 9.x through 13.x, Ichitaro 2004, 2005, 2006, and Government 2006; Ichitaro for Linux; and FormLiner before 20060818 allows remote attackers to execute arbitrary code via long Unicode strings in a crafted document, as being actively exploited by malware such as Trojan.Tarodrop. NOTE: some details are obtained from third party information.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {}
},
"mitre_repo_path": "cves/2006/4xxx/CVE-2006-4326.json",
"references": [
"http://secunia.com/advisories/21552",
"http://www.justsystem.co.jp/info/pd6002.html",
"http://www.securityfocus.com/bid/19550",
"http://www.symantec.com/enterprise/security_response/weblog/2006/08/justsystems_ichitaro_0day_used.html",
"http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2006-081615-5201-99",
"http://www.vupen.com/english/advisories/2006/3332",
"https://exchange.xforce.ibmcloud.com/vulnerabilities/28484"
],
"title": null,
"updated": "2024-08-07T19:06:07.633000+00:00",
"vendors": [],
"weaknesses": []
},
"nvd": {
"cpes": [
"cpe:2.3:a:justsystem:formliner:*:*:*:*:*:*:*:*",
"cpe:2.3:a:justsystem:ichitaro:10.0:*:*:*:*:*:*:*",
"cpe:2.3:a:justsystem:ichitaro:11.0:*:*:*:*:*:*:*",
"cpe:2.3:a:justsystem:ichitaro:12.0:*:*:*:*:*:*:*",
"cpe:2.3:a:justsystem:ichitaro:13.0:*:*:*:*:*:*:*",
"cpe:2.3:a:justsystem:ichitaro:2004:*:*:*:*:*:*:*",
"cpe:2.3:a:justsystem:ichitaro:2005:*:*:*:*:*:*:*",
"cpe:2.3:a:justsystem:ichitaro:2006:*:*:*:*:*:*:*",
"cpe:2.3:a:justsystem:ichitaro:9.0:*:*:*:*:*:*:*",
"cpe:2.3:a:justsystem:ichitaro_government:2006:*:*:*:*:*:*:*"
],
"created": "2006-08-24T01:04:00+00:00",
"description": "Stack-based buffer overflow in Justsystem Ichitaro 9.x through 13.x, Ichitaro 2004, 2005, 2006, and Government 2006; Ichitaro for Linux; and FormLiner before 20060818 allows remote attackers to execute arbitrary code via long Unicode strings in a crafted document, as being actively exploited by malware such as Trojan.Tarodrop. NOTE: some details are obtained from third party information.",
"metrics": {
"cvssV2_0": {
"score": 7.5,
"vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {}
},
"nvd_repo_path": "2006/CVE-2006-4326.json",
"references": [
"http://secunia.com/advisories/21552",
"http://www.justsystem.co.jp/info/pd6002.html",
"http://www.securityfocus.com/bid/19550",
"http://www.symantec.com/enterprise/security_response/weblog/2006/08/justsystems_ichitaro_0day_used.html",
"http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2006-081615-5201-99",
"http://www.vupen.com/english/advisories/2006/3332",
"https://exchange.xforce.ibmcloud.com/vulnerabilities/28484"
],
"title": null,
"updated": "2026-06-16T22:28:51.637000+00:00",
"vendors": [
"justsystem",
"justsystem$PRODUCT$formliner",
"justsystem$PRODUCT$ichitaro",
"justsystem$PRODUCT$ichitaro_government"
],
"weaknesses": [
"CWE-119"
]
},
"opencve": {
"changes": [],
"cpes": {
"data": [
"cpe:2.3:a:justsystem:formliner:*:*:*:*:*:*:*:*",
"cpe:2.3:a:justsystem:ichitaro:10.0:*:*:*:*:*:*:*",
"cpe:2.3:a:justsystem:ichitaro:11.0:*:*:*:*:*:*:*",
"cpe:2.3:a:justsystem:ichitaro:12.0:*:*:*:*:*:*:*",
"cpe:2.3:a:justsystem:ichitaro:13.0:*:*:*:*:*:*:*",
"cpe:2.3:a:justsystem:ichitaro:2004:*:*:*:*:*:*:*",
"cpe:2.3:a:justsystem:ichitaro:2005:*:*:*:*:*:*:*",
"cpe:2.3:a:justsystem:ichitaro:2006:*:*:*:*:*:*:*",
"cpe:2.3:a:justsystem:ichitaro:9.0:*:*:*:*:*:*:*",
"cpe:2.3:a:justsystem:ichitaro_government:2006:*:*:*:*:*:*:*"
],
"providers": [
"nvd"
]
},
"created": {
"data": "2006-08-24T01:00:00+00:00",
"provider": "mitre"
},
"description": {
"data": "Stack-based buffer overflow in Justsystem Ichitaro 9.x through 13.x, Ichitaro 2004, 2005, 2006, and Government 2006; Ichitaro for Linux; and FormLiner before 20060818 allows remote attackers to execute arbitrary code via long Unicode strings in a crafted document, as being actively exploited by malware such as Trojan.Tarodrop. NOTE: some details are obtained from third party information.",
"provider": "mitre"
},
"metrics": {
"cvssV2_0": {
"data": {
"score": 7.5,
"vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P"
},
"provider": "nvd"
},
"cvssV3_0": {
"data": {},
"provider": null
},
"cvssV3_1": {
"data": {},
"provider": null
},
"cvssV4_0": {
"data": {},
"provider": null
},
"epss": {
"data": {
"score": 0.04564
},
"provider": "first"
},
"kev": {
"data": {},
"provider": null
},
"ssvc": {
"data": {},
"provider": null
},
"threat_severity": {
"data": null,
"provider": null
}
},
"references": {
"data": [
"http://secunia.com/advisories/21552",
"http://www.justsystem.co.jp/info/pd6002.html",
"http://www.securityfocus.com/bid/19550",
"http://www.symantec.com/enterprise/security_response/weblog/2006/08/justsystems_ichitaro_0day_used.html",
"http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2006-081615-5201-99",
"http://www.vupen.com/english/advisories/2006/3332",
"https://exchange.xforce.ibmcloud.com/vulnerabilities/28484"
],
"providers": [
"mitre",
"nvd"
]
},
"title": {
"data": null,
"provider": null
},
"updated": {
"data": "2026-04-16T00:27:16.627000+00:00",
"provider": "nvd"
},
"vendors": {
"data": [
"justsystem",
"justsystem$PRODUCT$formliner",
"justsystem$PRODUCT$ichitaro",
"justsystem$PRODUCT$ichitaro_government"
],
"providers": [
"nvd"
]
},
"weaknesses": {
"data": [
"CWE-119"
],
"providers": [
"nvd"
]
}
}
}
Enrichment data
Aggregated bundle (all enrichments)