CVE-2008-1602

Orbit Downloader <2.6.4 - Buffer Overflow

Title source: llm

Description

Stack-based buffer overflow in Orbit downloader 2.6.3 and 2.6.4 allows remote attackers to execute arbitrary code via a long download URL, which is not properly handled during Unicode conversion for a balloon notification after a download has failed.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocalwindows
https://www.exploit-db.com/exploits/18515
metasploit WORKING POC NORMAL
by Diego Juarez, juan vazquez · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/fileformat/orbit_download_failed_bof.rb

Scores

EPSS 0.7658
EPSS Percentile 99.0%

Details

CWE
CWE-119
Status published
Products (2)
orbit_downloader/orbit_downloader 2.6.3
orbit_downloader/orbit_downloader 2.6.4
Published Apr 06, 2008
Tracked Since Feb 18, 2026