Description
Free Download Manager 2.0 Built 417 contains a local buffer overflow vulnerability in the URL import functionality that allows attackers to trigger a structured exception handler (SEH) chain exploitation. Attackers can craft a malicious URL file that, when imported through the File > Import > Import lists of downloads menu, causes a buffer overflow in the Location header response that overwrites the SEH chain and executes arbitrary code.
Published: 2026-04-29
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Apr 2026 20:00:00 +0000

Type Values Removed Values Added
Description Free Download Manager 2.0 Built 417 contains a local buffer overflow vulnerability in the URL import functionality that allows attackers to trigger a structured exception handler (SEH) chain exploitation. Attackers can craft a malicious URL file that, when imported through the File > Import > Import lists of downloads menu, causes a buffer overflow in the Location header response that overwrites the SEH chain and executes arbitrary code.
Title Free Download Manager 2.0 Built 417 Local Buffer Overflow SEH
First Time appeared Freedownloadmanager
Freedownloadmanager free Download Manager
Weaknesses CWE-120
CPEs cpe:2.3:a:freedownloadmanager:free_download_manager:2.0:*:*:*:*:*:*:*
Vendors & Products Freedownloadmanager
Freedownloadmanager free Download Manager
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Freedownloadmanager Free Download Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-04-29T19:24:36.594Z

Reserved: 2026-04-29T12:07:57.580Z

Link: CVE-2018-25304

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-29T20:16:25.760

Modified: 2026-04-29T20:16:25.760

Link: CVE-2018-25304

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses