Unrated severityNVD Advisory· Published Apr 6, 2008· Updated Apr 23, 2026
CVE-2008-1602
CVE-2008-1602
Description
Stack-based buffer overflow in Orbit downloader 2.6.3 and 2.6.4 allows remote attackers to execute arbitrary code via a long download URL, which is not properly handled during Unicode conversion for a balloon notification after a download has failed.
Affected products
2cpe:2.3:a:orbit_downloader:orbit_downloader:2.6.3:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:orbit_downloader:orbit_downloader:2.6.3:*:*:*:*:*:*:*
- cpe:2.3:a:orbit_downloader:orbit_downloader:2.6.4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.securityfocus.com/bid/28541nvdPatch
- www.coresecurity.comnvdExploitPatch
- secunia.com/advisories/29669nvdVendor Advisory
- securityreason.com/securityalert/3798nvd
- www.securityfocus.com/archive/1/490458/100/0/threadednvd
- www.vupen.com/english/advisories/2008/1101nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/41649nvd
News mentions
0No linked articles in our index yet.