← All CVEs

CVE-2008-1602

high · 10

Stack-based buffer overflow in Orbit downloader 2.6.3 and 2.6.4 allows remote attackers to execute arbitrary code via a long download URL, which is not properly handled during Unicode conversion for a balloon notification after a download has failed.

10
CVSS
67.5%
EPSS (exploit prob.)
99th
EPSS percentile
2008-04-06
Published

AV:N/AC:L/Au:N/C:C/I:C/A:C

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
orbit_downloaderorbit_downloader2.6.3
orbit_downloaderorbit_downloader2.6.4

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2008-1602