Download Manager
Vendor:
First CVE: Dec 6, 2006 · Active for 19 years
7
Total CVEs
More Total CVEs than 83% of tracked products
1.2
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 50% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Download Manager over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 6, 2006
19 years ago
Most Recent CVE
Sep 26, 2022
1,397 days ago
CVE Severity & Scoring
Download Manager7 CVEs
43%
43%
14%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (14.3%)
Network2 (28.6%)
Unknown4 (57.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (42.9%)
High0 (0.0%)
Unknown4 (57.1%)
User Interaction
None2 (28.6%)
Unknown4 (57.1%)
Required1 (14.3%)
Privileges Required
Low0 (0.0%)
High1 (14.3%)
None2 (28.6%)
Unknown4 (57.1%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-9688HIGH Adobe Download Manager version 2.0.0.518 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution. | Jul 17, 2020 | 7.8 | 28 | NO | NO |
CVE-2010-0189HIGH A certain ActiveX control in NOS Microsystems getPlus Download Manager (aka DLM or Downloader) 1.5.2.35, as used in Adobe Download Manager, improperly validates requests involving | Feb 23, 2010 | 9.3 | 28 | NO | NO |
CVE-2008-4817HIGH The Download Manager in Adobe Acrobat Professional and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary code via a crafted PDF document that calls an AcroJS fu | Nov 5, 2008 | 9.3 | 26 | NO | NO |
CVE-2019-8071CRITICAL Adobe Download Manager versions 2.0.0.363 have an insecure file permissions vulnerability. Successful exploitation could lead to privilege escalation. | Oct 17, 2019 | 9.8 | 25 | NO | NO |
CVE-2006-5856MEDIUM Stack-based buffer overflow in the Adobe Download Manager before 2.2 allows remote attackers to execute arbitrary code via a long section name in the dm.ini file, which is populate | Dec 6, 2006 | 6.8 | 23 | NO | NO |
CVE-2022-2926MEDIUM The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privilege users such as admin to list and read arbitrary files and | Sep 26, 2022 | 4.9 | 20 | NO | NO |
CVE-2008-4816MEDIUM Unspecified vulnerability in the Download Manager in Adobe Reader 8.1.2 and earlier on Windows allows remote attackers to change Internet Security options on a client machine via u | Nov 5, 2008 | 4.3 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Download Manager
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.0.0.518 | 1 | 7.8 | 4.9% | 0 | 0 |
| 2.0.0.363 | 1 | 9.8 | 3.3% | 0 | 0 |