Official Product Homepageproduct
http://www.internetdownloadmanager.com/ CVE-2020-37234
MEDIUM
Internet Download Manager 6.38.12 Scheduler Buffer Overflow
Record summary
CVE-2020-37234 has a selected CVSS score of 6.9 (medium); EIP currently links 1 catalogued exploit.
Description
Internet Download Manager 6.38.12 contains a buffer overflow vulnerability in the Scheduler component that allows local attackers to crash the application by supplying oversized input. Attackers can paste malicious data exceeding 5000 bytes into the 'Open the following file when done' field to trigger a denial of service condition.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 18, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Internet Download ManagerBrowse Internetdownloadmanager / Internet Download Manager | CVE List | 6.38.12 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBInternet Download Manager 6.38.12 - Scheduler Downloads Scheduler Buffer Overflow (PoC)ExploitDB exploitby Vincent WoltermanNot analyzed1 file
References
5Product Referenceproduct
http://www.internetdownloadmanager.com/download.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-37234 ExploitDB-49083exploit
https://www.exploit-db.com/exploits/49083 VulnCheck Advisory: Internet Download Manager 6.38.12 Scheduler Buffer OverflowThird-party advisory
https://www.vulncheck.com/advisories/internet-download-manager-scheduler-buffer-overflow