CVE-2014-2087
Stack-based buffer overflow in the CDownloads_Deleted::UpdateDownload function in Downloads_Deleted.cpp in Free Download Manager 3.9.3 build 1360, 3.8 build 1173, 3.0 build 852, and earlier allows user-assisted remote attackers to execute arbitrary code via a long file name, which is then deleted from the download queue by the user.
Ver en NVDSeveridad
N/A
EPSS
Probabilidad de explotación (próx. 30 días): 0.3683 (36.8%)
Percentil: 97.2%
EPSS: 2026-05-06
Afecta
freedownloadmanager:free_download_managerDescripción técnica
Stack-based buffer overflow in the CDownloads_Deleted::UpdateDownload function in Downloads_Deleted.cpp in Free Download Manager 3.9.3 build 1360, 3.8 build 1173, 3.0 build 852, and earlier allows user-assisted remote attackers to execute arbitrary code via a long file name, which is then deleted from the download queue by the user.
Publicada: 18/3/2014, 17:04:17
Última modificación: 6/5/2026, 22:30:45
Referencias
- http://seclists.org/fulldisclosure/2014/Mar/137
- http://www.securityfocus.com/archive/1/531465/100/0/threaded
- http://www.securityfocus.com/bid/66211
- https://www.rcesecurity.com/2014/03/cve-2014-2087-free-download-manager-cdownloads_deleted-updatedownload-remote-code-execution
- http://seclists.org/fulldisclosure/2014/Mar/137
- http://www.securityfocus.com/archive/1/531465/100/0/threaded
- http://www.securityfocus.com/bid/66211
- https://www.rcesecurity.com/2014/03/cve-2014-2087-free-download-manager-cdownloads_deleted-updatedownload-remote-code-execution