CVE-2009-0184 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 27.8% (pctl 98)
Patch early
A public exploit exists.
Description
Multiple buffer overflows in the torrent parsing implementation in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allow remote attackers to execute arbitrary code via (1) a long file name within a torrent file, (2) a long tracker URL in a torrent file, or (3) a long comment in a torrent file.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 27.8% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-02-03 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| free download manager | free download manager |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Free Download Manager 3.0 Build 844 - Torrent Parsing Buffer Overflow (Metasploit) | 2010-09-25 |
| exploit-db | Free Download Manager - '.Torrent' File Parsing Multiple Buffer Overflow Vulnerabilities (Metasploit) | 2009-11-11 |
References
- http://secunia.com/advisories/33524
- http://secunia.com/secunia_research/2009-5/
- http://www.securityfocus.com/archive/1/500605/100/0/threaded
- http://www.securityfocus.com/bid/33555
- http://www.vupen.com/english/advisories/2009/0302
- http://secunia.com/advisories/33524
- http://secunia.com/secunia_research/2009-5/
- http://www.securityfocus.com/archive/1/500605/100/0/threaded
- http://www.securityfocus.com/bid/33555
- http://www.vupen.com/english/advisories/2009/0302
→ the Explorer · watch your stack · NVD