Justsystems develops a line of document and office productivity applications, with primary exposure centered on its Ichitaro suite, which has established a presence among users in East Asian markets. The vendor's vulnerability profile spans a meaningful share of serious-severity outcomes across its product family, reflecting the parsing and memory-management complexity inherent to native document-processing software. Recurring weakness classes include buffer-overflow conditions, out-of-bounds memory writes, and improper input validation in document parsers, which are characteristic vulnerabilities in legacy productivity suites that handle untrusted file formats. Defenders should prioritize patches for internet-exposed Ichitaro instances and consider restricting document handling from untrusted sources; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Justsystems over time
Signals from CVEs in this vendor scope (32 CVEs).
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-2790CRITICAL When processing a record type of 0x3c from a Workbook stream from an Excel file (.xls), JustSystems Ichitaro Office trusts that the size is greater than zero, subtracts one from th | Feb 24, 2017 | 9.8 | 31 | NO | NO |
CVE-2017-2789CRITICAL When copying filedata into a buffer, JustSystems Ichitaro Office 2016 Trial will calculate two values to determine how much data to copy from the document. If both of these values | Feb 24, 2017 | 9.8 | 31 | NO | NO |
CVE-2013-5990HIGH Unspecified vulnerability in JustSystems Ichitaro 2006 through 2011; Ichitaro Government 6, 7, and 2006 through 2010; Ichitaro 2011 Sou; Ichitaro 2012 Shou; Ichitaro 2013 Gen and G | Nov 13, 2013 | 9.3 | 31 | NO | NO |
CVE-2022-36344CRITICAL An unquoted search path vulnerability exists in 'JustSystems JUST Online Update for J-License' bundled with multiple products for corporate users as in Ichitaro through Pro5 and ot | Aug 16, 2022 | 9.8 | 30 | NO | NO |
CVE-2011-1331HIGH JustSystems Ichitaro 2005 through 2011, Ichitaro Government 6, Ichitaro Government 2006 through 2010, Ichitaro Portable, Ichitaro Pro, and Ichitaro Viewer allow remote attackers to | Jul 18, 2011 | 9.3 | 30 | NO | NO |
CVE-2010-3915HIGH Unspecified vulnerability in JustSystems Ichitaro and Ichitaro Government allows remote attackers to execute arbitrary code via a crafted document, a different vulnerability than C | Nov 6, 2010 | 9.3 | 29 | NO | NO |
CVE-2012-0269HIGH Buffer overflow in JustSystems Ichitaro 2011 Sou, Ichitaro 2006 through 2011, Ichitaro Government 2006 through 2010, Ichitaro Portable with oreplug, Ichitaro Viewer, JUST School, J | Apr 27, 2012 | 9.3 | 28 | NO | NO |
CVE-2010-3916HIGH Unspecified vulnerability in JustSystems Ichitaro and Ichitaro Government allows remote attackers to execute arbitrary code via a crafted document, a different vulnerability than C | Nov 6, 2010 | 9.3 | 28 | NO | NO |
CVE-2010-2152HIGH Unspecified vulnerability in JustSystems Ichitaro 2004 through 2009, Ichitaro Government 2006 through 2009, and Just School 2008 and 2009 allows remote attackers to execute arbitra | Jun 3, 2010 | 9.3 | 28 | NO | NO |
CVE-2014-7247HIGH Unspecified vulnerability in JustSystems Ichitaro 2008 through 2011; Ichitaro Government 6, 7, 2008, 2009, and 2010; Ichitaro Pro; Ichitaro Pro 2; Ichitaro 2011 Sou; Ichitaro 2012 | Nov 26, 2014 | 10.0 | 26 | NO | NO |
Signals from CVEs in this vendor scope (32 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Justsystems.
Media articles that mention a CVE ID that affects a product developed by Justsystems — matched by CVE ID, not by vendor name.