Search

Find a vulnerability

Search criteria

    5 vulnerabilities by Allied Telesis

    JVNDB-2022-000066

    Vulnerability from jvndb - Published: 2022-08-29 08:37 - Updated:2024-06-13 07:21
    Severity
    Summary
    Multiple vulnerabilities in CentreCOM AR260S V2
    Details
    CentreCOM AR260S V2 provided by Allied Telesis K.K. contains multiple vulnerabilities listed below. * OS command injection vulnerability in GUI setting page (CWE-78) - CVE-2022-35273 * Use of hard-coded credentials for the telnet server (CWE-798) - CVE-2022-38394 * Undocumented hidden command that can be excuted from the telnet function (CWE-912) - CVE-2022-34869 * OS command injection vulnerability in the telnet function (CWE-78) - CVE-2022-38094 Chuya Hayakawa of 00One, Inc. reported these vulnerabilities to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-000066.html",
      "dc:date": "2024-06-13T16:21+09:00",
      "dcterms:issued": "2022-08-29T17:37+09:00",
      "dcterms:modified": "2024-06-13T16:21+09:00",
      "description": "CentreCOM AR260S V2 provided by Allied Telesis K.K. contains multiple vulnerabilities listed below.\r\n\r\n  * OS command injection vulnerability in GUI setting page (CWE-78) - CVE-2022-35273\r\n  * Use of hard-coded credentials for the telnet server (CWE-798) - CVE-2022-38394\r\n  * Undocumented hidden command that can be excuted from the telnet function (CWE-912) - CVE-2022-34869\r\n  * OS command injection vulnerability in the telnet function (CWE-78) - CVE-2022-38094  \r\n\r\nChuya Hayakawa of 00One, Inc. reported these vulnerabilities to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2022/JVNDB-2022-000066.html",
      "sec:cpe": {
        "#text": "cpe:/o:allied_telesis_k.k.:centrecom_ar260s_firmware",
        "@product": "CentreCOM AR260S V2 firmware",
        "@vendor": "Allied Telesis",
        "@version": "2.2"
      },
      "sec:cvss": [
        {
          "@score": "9.3",
          "@severity": "High",
          "@type": "Base",
          "@vector": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "@version": "2.0"
        },
        {
          "@score": "8.1",
          "@severity": "High",
          "@type": "Base",
          "@vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "@version": "3.0"
        }
      ],
      "sec:identifier": "JVNDB-2022-000066",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/jp/JVN45473612/index.html",
          "@id": "JVN#45473612",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2022-35273",
          "@id": "CVE-2022-35273",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2022-38394",
          "@id": "CVE-2022-38394",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2022-34869",
          "@id": "CVE-2022-34869",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2022-38094",
          "@id": "CVE-2022-38094",
          "@source": "CVE"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2022-34869",
          "@id": "CVE-2022-34869",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2022-35273",
          "@id": "CVE-2022-35273",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2022-38094",
          "@id": "CVE-2022-38094",
          "@source": "NVD"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2022-38394",
          "@id": "CVE-2022-38394",
          "@source": "NVD"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-287",
          "@title": "Improper Authentication(CWE-287)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-78",
          "@title": "OS Command Injection(CWE-78)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-Other",
          "@title": "No Mapping(CWE-Other)"
        }
      ],
      "title": "Multiple vulnerabilities in CentreCOM AR260S V2"
    }

    JVNDB-2017-000044

    Vulnerability from jvndb - Published: 2017-03-30 05:37 - Updated:2017-06-05 01:51
    Severity
    Summary
    CentreCOM AR260S V2 vulnerable to privilege escalation
    Details
    CentreCOM AR260S V2 provided by Allied Telesis K.K. is a wired LAN router. CentreCOM AR260S V2 contains a privilege escalation vulnerability. Ziv Chang of Trend Micro Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000044.html",
      "dc:date": "2017-06-05T10:51+09:00",
      "dcterms:issued": "2017-03-30T14:37+09:00",
      "dcterms:modified": "2017-06-05T10:51+09:00",
      "description": "CentreCOM AR260S V2 provided by Allied Telesis K.K. is a wired LAN router. CentreCOM AR260S V2 contains a privilege escalation vulnerability.\r\n\r\nZiv Chang of Trend Micro Inc. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2017/JVNDB-2017-000044.html",
      "sec:cpe": {
        "#text": "cpe:/h:allied_telesis_k.k.:centrecom_ar260s_v2",
        "@product": "CentreCOM AR260S V2",
        "@vendor": "Allied Telesis",
        "@version": "2.2"
      },
      "sec:cvss": [
        {
          "@score": "5.2",
          "@severity": "Medium",
          "@type": "Base",
          "@vector": "AV:A/AC:L/Au:S/C:P/I:P/A:P",
          "@version": "2.0"
        },
        {
          "@score": "8.0",
          "@severity": "High",
          "@type": "Base",
          "@vector": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "@version": "3.0"
        }
      ],
      "sec:identifier": "JVNDB-2017-000044",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/jp/JVN55121369/index.html",
          "@id": "JVN#55121369",
          "@source": "JVN"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-2125",
          "@id": "CVE-2017-2125",
          "@source": "CVE"
        },
        {
          "#text": "https://nvd.nist.gov/vuln/detail/CVE-2017-2125",
          "@id": "CVE-2017-2125",
          "@source": "NVD"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-264",
          "@title": "Permissions(CWE-264)"
        }
      ],
      "title": "CentreCOM AR260S V2 vulnerable to privilege escalation"
    }

    JVNDB-2014-000132

    Vulnerability from jvndb - Published: 2014-12-18 05:47 - Updated:2015-01-28 08:38
    Severity
    N/A (UNKNOWN) - -
    Summary
    Multiple Allied Telesis products vulnerable to buffer overflow
    Details
    AR Router Series and Alliedware switches provided by Allied Telesis Group contain a buffer overflow vulnerability (CWE-788) due to a flaw when processing a POST method.
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2014/JVNDB-2014-000132.html",
      "dc:date": "2015-01-28T17:38+09:00",
      "dcterms:issued": "2014-12-18T14:47+09:00",
      "dcterms:modified": "2015-01-28T17:38+09:00",
      "description": "AR Router Series and Alliedware switches provided by Allied Telesis Group contain a buffer overflow vulnerability (CWE-788) due to a flaw when processing a POST method.",
      "link": "https://jvndb.jvn.jp/en/contents/2014/JVNDB-2014-000132.html",
      "sec:cpe": [
        {
          "#text": "cpe:/h:allied_telesis_k.k.:ar440s",
          "@product": "AR440S",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:ar441s",
          "@product": "AR441S",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:ar442s",
          "@product": "AR442S",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:ar745",
          "@product": "AR745",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:ar750s",
          "@product": "AR750S",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:ar750s-dp",
          "@product": "AR750S-DP",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:at-8624poe",
          "@product": "AT-8624POE",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:at-8624t%2F2m",
          "@product": "AT-8624T/2M",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:at-8648t%2F2sp",
          "@product": "AT-8648T/2SP",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:at-8848",
          "@product": "AT-8848",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:at-9924t",
          "@product": "AT-9924T",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:centrecom_8700xl",
          "@product": "CentreCOM 8700XL",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:centrecom_8724sl",
          "@product": "CentreCOM 8724SL",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:centrecom_8948xl",
          "@product": "CentreCOM 8948XL",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:centrecom_9812t",
          "@product": "CentreCOM 9812T",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:centrecom_9816gb",
          "@product": "CentreCOM 9816GB",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:centrecom_9924sp",
          "@product": "CentreCOM 9924SP",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:centrecom_9924t%2f4sp",
          "@product": "CentreCOM 9924T/4SP",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:centrecom_9924ts",
          "@product": "CentreCOM 9924Ts",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:centrecom_ar300",
          "@product": "CentreCOM AR300",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:centrecom_ar300l",
          "@product": "CentreCOM AR300L",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:centrecom_ar320",
          "@product": "CentreCOM AR320",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:centrecom_ar410%28s%29",
          "@product": "CentreCOM AR410(S)",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:centrecom_ar415s",
          "@product": "CentreCOM AR415S",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:centrecom_ar450s",
          "@product": "CentreCOM AR450S",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:centrecom_ar550s",
          "@product": "CentreCOM AR550S",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:centrecom_ar560s",
          "@product": "CentreCOM AR560S",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:centrecom_ar570s",
          "@product": "CentreCOM AR570S",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:centrecom_ar720%28s%29",
          "@product": "CentreCOM AR720(S)",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:centrecom_ar740%28s%29",
          "@product": "CentreCOM AR740(S)",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:centrecom_ar8700sl",
          "@product": "CentreCOM 8700SL",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:rapier_48i",
          "@product": "Rapier 48i",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:allied_telesis_k.k.:switchblade4000",
          "@product": "SwitchBlade4000",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        }
      ],
      "sec:cvss": {
        "@score": "10.0",
        "@severity": "High",
        "@type": "Base",
        "@vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
        "@version": "2.0"
      },
      "sec:identifier": "JVNDB-2014-000132",
      "sec:references": [
        {
          "#text": "http://jvn.jp/en/jp/JVN22440986/index.html",
          "@id": "JVN#22440986",
          "@source": "JVN"
        },
        {
          "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7249",
          "@id": "CVE-2014-7249",
          "@source": "CVE"
        },
        {
          "#text": "https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-7249",
          "@id": "CVE-2014-7249",
          "@source": "NVD"
        },
        {
          "#text": "http://www.ipa.go.jp/security/ciadr/vul/20141218-jvn.html",
          "@id": "Security Alert for Multiple Allied Telesis products vulnerable to buffer overflow (JVN#22440986)",
          "@source": "IPA SECURITY ALERTS"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-119",
          "@title": "Buffer Errors(CWE-119)"
        }
      ],
      "title": "Multiple Allied Telesis products vulnerable to buffer overflow"
    }

    JVNDB-2007-000329

    Vulnerability from jvndb - Published: 2008-05-20 15:00 - Updated:2008-06-06 07:22
    Severity
    N/A (UNKNOWN) - -
    Summary
    Java Web Start vulnerable to execution of unauthorized system classes
    Details
    Java Web Start, included in the JRE (Java Runtime Environment) from Sun Microsystems and other products, contains a vulnerability allowing unauthorized execution of system classes. Java Web Start, included in the JRE (Java Runtime Environment) and other products, is a tool for distributing Java applications over the web. A vulnerability exists in an implementation of Java Web Start which may allow Java Web Start Application including a malformed JAR file to execute an unauthorized system class.
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2007/JVNDB-2007-000329.html",
      "dc:date": "2008-06-06T16:22+09:00",
      "dcterms:issued": "2008-05-21T00:00+09:00",
      "dcterms:modified": "2008-06-06T16:22+09:00",
      "description": "Java Web Start, included in the JRE (Java Runtime Environment) from Sun Microsystems and other products, contains a vulnerability allowing unauthorized execution of system classes.\r\n\r\nJava Web Start, included in the JRE (Java Runtime Environment) and other products, is a tool for distributing Java applications over the web.  A vulnerability exists in an implementation of Java Web Start which may allow Java Web Start Application including a malformed JAR file to execute an unauthorized system class.",
      "link": "https://jvndb.jvn.jp/en/contents/2007/JVNDB-2007-000329.html",
      "sec:cpe": [
        {
          "#text": "cpe:/a:allied_telesis_k.k.:ssl_vpn-plus",
          "@product": "SSL VPN-Plus",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:allied_telesis_k.k.:swimradius",
          "@product": "SwimRadius",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:bea:jrockit",
          "@product": "BEA JRockit",
          "@vendor": "BEA Systems, Inc.",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:nec:tw703000",
          "@product": "TW703000",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:nec:websam_deploymentmanager",
          "@product": "WebSAM DeploymentManager",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:redhat:enterprise_linux",
          "@product": "Red Hat Enterprise Linux Extras",
          "@vendor": "Red Hat, Inc.",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:redhat:rhel_desktop_supplementary",
          "@product": "RHEL Desktop Supplementary",
          "@vendor": "Red Hat, Inc.",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:redhat:rhel_supplementary",
          "@product": "RHEL Supplementary",
          "@vendor": "Red Hat, Inc.",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:sun:jdk",
          "@product": "JDK",
          "@vendor": "Sun Microsystems, Inc.",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:sun:jre",
          "@product": "JRE",
          "@vendor": "Sun Microsystems, Inc.",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:sun:sdk",
          "@product": "SDK",
          "@vendor": "Sun Microsystems, Inc.",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:apple:mac_os_x",
          "@product": "Apple Mac OS X",
          "@vendor": "Apple Inc.",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:apple:mac_os_x_server",
          "@product": "Apple Mac OS X Server",
          "@vendor": "Apple Inc.",
          "@version": "2.2"
        }
      ],
      "sec:cvss": {
        "@score": "7.5",
        "@severity": "High",
        "@type": "Base",
        "@vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
        "@version": "2.0"
      },
      "sec:identifier": "JVNDB-2007-000329",
      "sec:references": [
        {
          "#text": "http://jvn.jp/en/jp/JVN44724673/index.html",
          "@id": "JVN#44724673",
          "@source": "JVN"
        },
        {
          "#text": "http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2435",
          "@id": "CVE-2007-2435",
          "@source": "CVE"
        },
        {
          "#text": "http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-2435",
          "@id": "CVE-2007-2435",
          "@source": "NVD"
        },
        {
          "#text": "http://www.jpcert.or.jp/wr/2007/wr071701.txt",
          "@id": "JPCERT-WR-2007-1701",
          "@source": "JPCERT-WR"
        },
        {
          "#text": "http://secunia.com/advisories/25069/",
          "@id": "SA25069",
          "@source": "SECUNIA"
        },
        {
          "#text": "http://www.securityfocus.com/bid/23728",
          "@id": "23728",
          "@source": "BID"
        },
        {
          "#text": "http://xforce.iss.net/xforce/xfdb/33984",
          "@id": "33984",
          "@source": "XF"
        },
        {
          "#text": "http://www.securitytracker.com/id?1017986",
          "@id": "1017986",
          "@source": "SECTRACK"
        },
        {
          "#text": "http://www.frsirt.com/english/advisories/2007/1598",
          "@id": "FrSIRT/ADV-2007-1598",
          "@source": "FRSIRT"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-264",
          "@title": "Permissions(CWE-264)"
        }
      ],
      "title": "Java Web Start vulnerable to execution of unauthorized system classes"
    }

    JVNDB-2005-000772

    Vulnerability from jvndb - Published: 2008-05-20 15:00 - Updated:2008-05-20 15:00
    Severity
    N/A (UNKNOWN) - -
    Summary
    Inappropriate interpretation of mailto URL scheme by mail client software
    Details
    The mailto URL scheme is used to designate the Internet email address on a web page. Specifying an email address and body text using the mailto URL scheme gives a template for a mail message. Many mail clients have a function to set a field specified by the mailto URL scheme in a mail header. RFC2368 defining the mailto URL scheme points out the followings in its Security Considerations section. - A mail client should never send anything without complete disclosure to the user of the full message created based on descriptions of the mailto URL scheme - It should explicitly display any headers along with the message destination. - It is inappropriate to set a header related to mail delivery based on descriptions of the mailto URL scheme However, some mail clients set the header related to mail delivery based on descriptions of the mailto URL scheme or do not explicitly display the full header. We published this issue on JVN in coordination with developers, to publicize the issue to users and mail client developers.
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2005/JVNDB-2005-000772.html",
      "dc:date": "2008-05-21T00:00+09:00",
      "dcterms:issued": "2008-05-21T00:00+09:00",
      "dcterms:modified": "2008-05-21T00:00+09:00",
      "description": "The mailto URL scheme is used to designate the Internet email address on a web page. Specifying an email address and body text using the mailto URL scheme gives a template for a mail message. Many mail clients have a function to set a field specified by the mailto URL scheme in a mail header.\r\n\r\nRFC2368 defining the mailto URL scheme points out the followings in its Security Considerations section.\r\n\r\n- A mail client should never send anything without complete disclosure to the user of the full message created based on descriptions of the mailto URL scheme\r\n- It should explicitly display any headers along with the message destination.\r\n- It is inappropriate to set a header related to mail delivery based on descriptions of the mailto URL scheme  \r\n\r\nHowever, some mail clients set the header related to mail delivery based on descriptions of the mailto URL scheme or do not explicitly display the full header.\r\n\r\nWe published this issue on JVN in coordination with developers, to publicize the issue to users and mail client developers.",
      "link": "https://jvndb.jvn.jp/en/contents/2005/JVNDB-2005-000772.html",
      "sec:cpe": [
        {
          "#text": "cpe:/a:allied_telesis_k.k.:at-mail_server",
          "@product": "AT-Mail Server",
          "@vendor": "Allied Telesis",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:hidemaru:hidemaru_mail",
          "@product": "Hidemaru Mail",
          "@vendor": "Saitoh Kikaku",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:justsystems:shuriken",
          "@product": "Shuriken",
          "@vendor": "JustSystems Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:misc:edcom_edmax",
          "@product": "EdMax",
          "@vendor": "Edcom Inc. ",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:misc:edcom_edmax_free",
          "@product": "EdMax Free",
          "@vendor": "Edcom Inc. ",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:misc:orange_winbiff",
          "@product": "Winbiff",
          "@vendor": "Orangesoft Inc.",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:rimarts_inc.:becky_internet_mail",
          "@product": "Becky! Internet Mail",
          "@vendor": "RIMARTS",
          "@version": "2.2"
        }
      ],
      "sec:cvss": {
        "@score": "4.3",
        "@severity": "Medium",
        "@type": "Base",
        "@vector": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
        "@version": "2.0"
      },
      "sec:identifier": "JVNDB-2005-000772",
      "sec:references": [
        {
          "#text": "http://jvn.jp/en/jp/JVNFCAD9BD8/index.html",
          "@id": "JVN#FCAD9BD8",
          "@source": "JVN"
        },
        {
          "#text": "http://www.ietf.org/rfc/rfc2368.txt",
          "@id": "RFC2368: The mailto URL scheme",
          "@source": "IETF"
        }
      ],
      "title": "Inappropriate interpretation of mailto URL scheme by mail client software"
    }