Akamai Technologies' sparse vulnerability footprint centers on its download-management and client-facing products, with observed issues spanning authentication weaknesses, code-injection flaws, memory-safety concerns, and cross-site request forgery. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Akamai Technologies over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-1892HIGH Stack-based buffer overflow in Akamai Technologies Download Manager ActiveX Control (DownloadManagerV2.ocx) before 2.2.1.0 allows remote attackers to execute arbitrary code via uns | Apr 18, 2007 | 9.3 | 28 | NO | NO |
CVE-2009-2582HIGH Stack-based buffer overflow in manager.exe in Akamai Download Manager (aka DLM or dlmanager) before 2.2.4.8 allows remote web servers to execute arbitrary code via a malformed HTTP | Jul 23, 2009 | 9.3 | 25 | NO | NO |
CVE-2007-1891HIGH Stack-based buffer overflow in the GetPrivateProfileSectionW function in Akamai Technologies Download Manager ActiveX Control (DownloadManagerV2.ocx) after 2.0.4.4 but before 2.2.1 | Apr 18, 2007 | 9.3 | 25 | NO | NO |
CVE-2007-6339MEDIUM The Akamai Download Manager (aka DLM or dlmanager) ActiveX control (DownloadManagerV2.ocx) before 2.2.3.5 allows remote attackers to force the download and execution of arbitrary c | May 1, 2008 | 6.8 | 22 | NO | NO |
CVE-2008-1106HIGH The management interface in Akamai Client (formerly Red Swoosh) 3322 and earlier allows remote attackers to bypass authentication via an HTTP request that contains (1) no Referer h | Jun 9, 2008 | 7.1 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Akamai Technologies.
Media articles that mention a CVE ID that affects a product developed by Akamai Technologies — matched by CVE ID, not by vendor name.