Vulnerability Details CVE-2014-2087
Stack-based buffer overflow in the CDownloads_Deleted::UpdateDownload function in Downloads_Deleted.cpp in Free Download Manager 3.9.3 build 1360, 3.8 build 1173, 3.0 build 852, and earlier allows user-assisted remote attackers to execute arbitrary code via a long file name, which is then deleted from the download queue by the user.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.464
EPSS Ranking 97.6%
CVSS Severity
CVSS v2 Score 9.3
Products affected by CVE-2014-2087
-
cpe:2.3:a:freedownloadmanager:free_download_manager:3.8
-
cpe:2.3:a:freedownloadmanager:free_download_manager:3.9.3