VulnerabilityModified
CVE-2007-6339
The Akamai Download Manager (aka DLM or dlmanager) ActiveX control (DownloadManagerV2.ocx) before 2.2.3.5 allows remote attackers to force the download and execution of arbitrary code via unspecified "undocumented object parameters."
MEDIUM 6.8EPSS 11.0%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.0%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The Akamai Download Manager (aka DLM or dlmanager) ActiveX control (DownloadManagerV2.ocx) before 2.2.3.5 allows remote attackers to force the download and execution of arbitrary code via unspecified "undocumented object parameters."
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 10.99% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- akamai technologies/download manager
- Source
- cve@mitre.org
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=695Patch
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-April/061923.html
- http://secunia.com/advisories/30037
- http://www.securityfocus.com/bid/28993Patch
- http://www.securitytracker.com/id?1019955
- http://www.vupen.com/english/advisories/2008/1408/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42117
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=695Patch
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-April/061923.html
- http://secunia.com/advisories/30037
- http://www.securityfocus.com/bid/28993Patch
- http://www.securitytracker.com/id?1019955
- http://www.vupen.com/english/advisories/2008/1408/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/42117
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.