CVE-2014-2087
high · 9.3Stack-based buffer overflow in the CDownloads_Deleted::UpdateDownload function in Downloads_Deleted.cpp in Free Download Manager 3.9.3 build 1360, 3.8 build 1173, 3.0 build 852, and earlier allows user-assisted remote attackers to execute arbitrary code via a long file name, which is then deleted from the download queue by the user.
9.3
CVSS
16.7%
EPSS (exploit prob.)
97th
EPSS percentile
2014-03-18
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| freedownloadmanager | free_download_manager | 3.8 |
| freedownloadmanager | free_download_manager | 3.9.3 |
Check a specific version with /api/v1/cve/match.
References
- http://seclists.org/fulldisclosure/2014/Mar/137
- http://www.securityfocus.com/archive/1/531465/100/0/threaded
- http://www.securityfocus.com/bid/66211
- https://www.rcesecurity.com/2014/03/cve-2014-2087-free-download-manager-cdownloads_deleted-updatedownload-remote-code-execution
- http://seclists.org/fulldisclosure/2014/Mar/137
- http://www.securityfocus.com/archive/1/531465/100/0/threaded
- http://www.securityfocus.com/bid/66211
- https://www.rcesecurity.com/2014/03/cve-2014-2087-free-download-manager-cdownloads_deleted-updatedownload-remote-code-execution
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2014-2087