CVE-2008-1602
Orbit Downloader <2.6.4 - Buffer Overflow
Title source: llmDescription
Stack-based buffer overflow in Orbit downloader 2.6.3 and 2.6.4 allows remote attackers to execute arbitrary code via a long download URL, which is not properly handled during Unicode conversion for a balloon notification after a download has failed.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/18515
metasploit
WORKING POC
NORMAL
by Diego Juarez, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/orbit_download_failed_bof.rb
References (7)
Scores
EPSS
0.7658
EPSS Percentile
99.0%
Details
CWE
CWE-119
Status
published
Products (2)
orbit_downloader/orbit_downloader
2.6.3
orbit_downloader/orbit_downloader
2.6.4
Published
Apr 06, 2008
Tracked Since
Feb 18, 2026