Tonec maintains Internet Download Manager, a download-acceleration application whose vulnerability profile centers on memory-safety and certificate-handling issues such as out-of-bounds writes, improper buffer bounds enforcement, and improper certificate validation. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tonec over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-56231CRITICAL Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows attackers to bypass update protections. | Nov 5, 2025 | 9.1 | 31 | NO | NO |
CVE-2008-4508HIGH Stack-based buffer overflow in the file parsing function in Tonec Internet Download Manager, possibly 5.14 and earlier, allows remote attackers to cause a denial of service (crash) | Oct 9, 2008 | 7.8 | 31 | NO | YES |
CVE-2005-2210HIGH Stack-based buffer overflow in Internet Download Manager 4.05 allows remote attackers to execute arbitrary code via a long URL. | Jul 11, 2005 | 7.5 | 29 | NO | YES |
CVE-2010-0995HIGH Stack-based buffer overflow in Internet Download Manager (IDM) before 5.19 allows remote attackers to execute arbitrary code via a crafted FTP URI that causes unspecified "test seq | May 6, 2010 | 9.3 | 27 | NO | NO |
CVE-2020-23060HIGH Internet Download Manager 6.37.11.1 was discovered to contain a stack buffer overflow in the Export/Import function. This vulnerability allows attackers to escalate local process p | Oct 22, 2021 | 7.1 | 23 | NO | NO |
CVE-2020-28964MEDIUM Internet Download Manager 6.37.11.1 was discovered to contain a stack buffer overflow in the Search function. This vulnerability allows attackers to escalate local process privileg | Oct 22, 2021 | 6.7 | 22 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tonec.
Media articles that mention a CVE ID that affects a product developed by Tonec — matched by CVE ID, not by vendor name.