JVNRSS Feed - Update Entry https://jvn.jp/en/ Japan Vulnerability Notes new/updated information JVN jvn@jvn.jp 2024-11-21T13:45:20+09:00 2024-11-21T13:45:20+09:00 2024-11-21T13:45:20+09:00 Multiple vulnerabilities in Edgecross Basic Software for Windows https://jvn.jp/en/vu/JVNVU92857077/ Edgecross Basic Software for Windows provided by Edgecross Consortium contains multiple vulnerabilities. JVN jvn@jvn.jp JVNVU#92857077 https://jvn.jp/en/vu/JVNVU92857077/ 2024-11-21T14:00:00+09:00 2024-11-21T14:00:00+09:00 2024-11-21T14:00:00+09:00 Multiple vulnerabilities in AIPHONE IX SYSTEM, IXG SYSTEM, and System Support Software https://jvn.jp/en/jp/JVN41397971/ IX SYSTEM, IXG SYSTEM, and System Support Software provided by AIPHONE CO., LTD. contain multiple vulnerabilities. JVN jvn@jvn.jp JVN#41397971 https://jvn.jp/en/jp/JVN41397971/ 2024-11-21T11:00:00+09:00 2024-10-18T14:00:00+09:00 2024-11-21T11:00:00+09:00 "Kura Sushi Official App Produced by EPARK" for Android uses a hard-coded cryptographic key https://jvn.jp/en/jp/JVN16114985/ "Kura Sushi Official App Produced by EPARK" for Android provided by EPARK, Inc. uses a hard-coded cryptographic key. JVN jvn@jvn.jp JVN#16114985 https://jvn.jp/en/jp/JVN16114985/ 2024-11-20T12:00:00+09:00 2024-11-20T12:00:00+09:00 2024-11-20T12:00:00+09:00 Vulnerabilities in multiple Dahua Technology products (DHCC-SA-202407-001) https://jvn.jp/en/vu/JVNVU99607268/ Dahua Technology has released a security update for its multiple products. JVN jvn@jvn.jp JVNVU#99607268 https://jvn.jp/en/vu/JVNVU99607268/ 2024-11-20T10:00:00+09:00 2024-11-20T10:00:00+09:00 2024-11-20T10:00:00+09:00 Multiple vulnerabilities in FitNesse https://jvn.jp/en/jp/JVN36791327/ FitNesse provided by unclebob contains multiple vulnerabilities. JVN jvn@jvn.jp JVN#36791327 https://jvn.jp/en/jp/JVN36791327/ 2024-11-20T09:00:00+09:00 2024-11-15T12:00:00+09:00 2024-11-20T09:00:00+09:00 Multiple vulnerabilities in Rakuten Turbo 5G https://jvn.jp/en/vu/JVNVU90667116/ Rakuten Turbo 5G provided by Rakuten Mobile, Inc. contains multiple vulnerabilities. JVN jvn@jvn.jp JVNVU#90667116 https://jvn.jp/en/vu/JVNVU90667116/ 2024-11-18T13:30:00+09:00 2024-11-18T13:30:00+09:00 2024-11-18T13:30:00+09:00 WordPress Plugin "VK All in One Expansion Unit" vulnerable to cross-site scripting https://jvn.jp/en/jp/JVN05136799/ WordPress Plugin "VK All in One Expansion Unit" contains a cross-site scripting vulnerability. JVN jvn@jvn.jp JVN#05136799 https://jvn.jp/en/jp/JVN05136799/ 2024-11-13T12:00:00+09:00 2024-11-13T12:00:00+09:00 2024-11-13T12:00:00+09:00 Multiple vulnerabilities in SoftBank Mesh Wi-Fi router RP562B https://jvn.jp/en/vu/JVNVU90676195/ Mesh Wi-Fi router RP562B provided by SoftBank Corp. contains multiple vulnerabilities. JVN jvn@jvn.jp JVNVU#90676195 https://jvn.jp/en/vu/JVNVU90676195/ 2024-11-12T10:00:00+09:00 2024-11-12T10:00:00+09:00 2024-11-12T10:00:00+09:00 Insecure initial password configuration issue in SEIKO EPSON Web Config https://jvn.jp/en/vu/JVNVU95133448/ In multiple SEIKO EPSON products, when the product is connected to network without the Web Config settings configured, an arbitrary password may be set, and the product may be operated with an administrative privilege by an attacker. JVN jvn@jvn.jp JVNVU#95133448 https://jvn.jp/en/vu/JVNVU95133448/ 2024-11-11T16:15:00+09:00 2024-09-30T13:00:00+09:00 2024-11-11T16:15:00+09:00 baserCMS plugin "BurgerEditor" vulnerable to directory listing https://jvn.jp/en/jp/JVN54676967/ baserCMS plugin "BurgerEditor" provided by D-ZERO CO.,LTD. contains a directory listing vulnerability. JVN jvn@jvn.jp JVN#54676967 https://jvn.jp/en/jp/JVN54676967/ 2024-11-06T11:30:00+09:00 2024-10-10T14:00:00+09:00 2024-11-06T11:30:00+09:00 Trend Micro Deep Security 20 Agent for Windows vulnerable to improper access control https://jvn.jp/en/vu/JVNVU96058081/ Trend Micro Incorporated has released a security update for Deep Security 20 Agent (for Windows). JVN jvn@jvn.jp JVNVU#96058081 https://jvn.jp/en/vu/JVNVU96058081/ 2024-11-05T11:00:00+09:00 2024-11-05T11:00:00+09:00 2024-11-05T11:00:00+09:00 Incorrect authorization vulnerability in OMRON Sysmac Studio https://jvn.jp/en/vu/JVNVU95685374/ Sysmac Studio provided by OMRON Corporation contains an incorrect authorization vulnerability. JVN jvn@jvn.jp JVNVU#95685374 https://jvn.jp/en/vu/JVNVU95685374/ 2024-11-01T13:00:00+09:00 2024-11-01T13:00:00+09:00 2024-11-01T13:00:00+09:00 Stack-based buffer overflow vulnerability in multiple Ricoh laser printers and MFPs which implement Web Image Monitor https://jvn.jp/en/jp/JVN87770340/ Multiple Ricoh laser printers and MFPs (multifunction printers) which implement Web Image Monitor contain a stack-based buffer overflow vulnerability. JVN jvn@jvn.jp JVN#87770340 https://jvn.jp/en/jp/JVN87770340/ 2024-10-31T14:00:00+09:00 2024-10-31T14:00:00+09:00 2024-10-31T14:00:00+09:00 REST-APIs unintentionally enabled in Century Systems FutureNet NXR series routers https://jvn.jp/en/vu/JVNVU95001899/ FutureNet NXR series provided by Century Systems Co., Ltd. makes REST-APIs unintentionally enabled. JVN jvn@jvn.jp JVNVU#95001899 https://jvn.jp/en/vu/JVNVU95001899/ 2024-10-31T13:00:00+09:00 2024-10-31T13:00:00+09:00 2024-10-31T13:00:00+09:00 Command injection vulnerability in Trend Micro Cloud Edge https://jvn.jp/en/vu/JVNVU94153896/ Trend Micro Incorporated has released a security update for Cloud Edge. JVN jvn@jvn.jp JVNVU#94153896 https://jvn.jp/en/vu/JVNVU94153896/ 2024-10-31T12:20:00+09:00 2024-10-31T12:20:00+09:00 2024-10-31T12:20:00+09:00 Hikvision network camera security enhancement to prevent cleartext transmission of Dynamic DNS credentials https://jvn.jp/en/jp/JVN11779839/ Hangzhou Hikvision Digital Technology Co., Ltd. provides firmware updates for multiple network cameras as a security enhancement, changing the behavior to communicate with Dynamic DNS services, to prevent cleartext transmission. JVN jvn@jvn.jp JVN#11779839 https://jvn.jp/en/jp/JVN11779839/ 2024-10-30T12:00:00+09:00 2024-10-30T12:00:00+09:00 2024-10-30T12:00:00+09:00 Chatwork Desktop Application (Windows) uses a potentially dangerous function https://jvn.jp/en/jp/JVN78335885/ Chatwork Desktop Application (Windows) contains an issue with use of potentially dangerous function. JVN jvn@jvn.jp JVN#78335885 https://jvn.jp/en/jp/JVN78335885/ 2024-10-28T12:00:00+09:00 2024-10-28T12:00:00+09:00 2024-10-28T12:00:00+09:00 Multiple vulnerabilities in Sharp and Toshiba Tec MFPs https://jvn.jp/en/vu/JVNVU95063136/ Sharp and Toshiba Tec MFPs (multifunction printers) contain multiple vulnerabilities. JVN jvn@jvn.jp JVNVU#95063136 https://jvn.jp/en/vu/JVNVU95063136/ 2024-10-25T17:30:00+09:00 2024-10-25T13:00:00+09:00 2024-10-25T17:30:00+09:00 N-LINE vulnerable to HTML injection https://jvn.jp/en/jp/JVN57285747/ N-LINE provided by NEUMANN CO.LTD. contains an HTML injection vulnerability. JVN jvn@jvn.jp JVN#57285747 https://jvn.jp/en/jp/JVN57285747/ 2024-10-25T15:00:15+09:00 2024-10-18T12:00:15+09:00 2024-10-25T15:00:15+09:00 MUSASI version 3 performing authentication on client-side https://jvn.jp/en/jp/JVN31982676/ MUSASI version 3 provided by NEUMANN CO.LTD. performs authentication within the client-side code. JVN jvn@jvn.jp JVN#31982676 https://jvn.jp/en/jp/JVN31982676/ 2024-10-25T15:00:00+09:00 2024-10-18T12:00:00+09:00 2024-10-25T15:00:00+09:00