Adobe Download Manager vulnerabilities

5 known vulnerabilities affecting adobe/download_manager.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH1MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2022-2926MEDIUMCVSS 4.9fixed in 3.2.552022-09-26
CVE-2022-2926 [MEDIUM] CWE-22 CVE-2022-2926: The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which cou The Download Manager WordPress plugin before 3.2.55 does not validate one of its settings, which could allow high privilege users such as admin to list and read arbitrary files and folders outside of the blog directory
nvd
CVE-2020-9688HIGHCVSS 7.8v2.0.0.5182020-07-17
CVE-2020-9688 [HIGH] CWE-77 CVE-2020-9688: Adobe Download Manager version 2.0.0.518 have a command injection vulnerability. Successful exploita Adobe Download Manager version 2.0.0.518 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
nvd
CVE-2019-8071CRITICALCVSS 9.8v2.0.0.3632019-10-17
CVE-2019-8071 [CRITICAL] CWE-732 CVE-2019-8071: Adobe Download Manager versions 2.0.0.363 have an insecure file permissions vulnerability. Successfu Adobe Download Manager versions 2.0.0.363 have an insecure file permissions vulnerability. Successful exploitation could lead to privilege escalation.
nvd
CVE-2010-0189CRITICALCVSS 9.3≤ 1.6.2.602010-02-23
CVE-2010-0189 [CRITICAL] CWE-20 CVE-2010-0189: A certain ActiveX control in NOS Microsystems getPlus Download Manager (aka DLM or Downloader) 1.5.2 A certain ActiveX control in NOS Microsystems getPlus Download Manager (aka DLM or Downloader) 1.5.2.35, as used in Adobe Download Manager, improperly validates requests involving web sites that are not in subdomains, which allows remote attackers to force the download and installation of arbitrary programs via a crafted name for a download site.
nvd
CVE-2006-5856MEDIUMCVSS 6.8≤ 2.12006-12-06
CVE-2006-5856 [MEDIUM] CVE-2006-5856: Stack-based buffer overflow in the Adobe Download Manager before 2.2 allows remote attackers to exec Stack-based buffer overflow in the Adobe Download Manager before 2.2 allows remote attackers to execute arbitrary code via a long section name in the dm.ini file, which is populated via an AOM file.
nvd