VYPR
Vendor

Tonec Inc.

Products
1
CVEs
6
Across products
6
Status
Private

Products

1

Recent CVEs

6
  • CVE-2025-56231CriNov 5, 2025
    risk 0.59cvss 9.1epss 0.00

    Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows attackers to bypass update protections.

  • CVE-2020-23060HigOct 22, 2021
    risk 0.46cvss 7.1epss 0.00

    Internet Download Manager 6.37.11.1 was discovered to contain a stack buffer overflow in the Export/Import function. This vulnerability allows attackers to escalate local process privileges via a crafted ef2 file.

  • CVE-2020-28964MedOct 22, 2021
    risk 0.44cvss 6.7epss 0.00

    Internet Download Manager 6.37.11.1 was discovered to contain a stack buffer overflow in the Search function. This vulnerability allows attackers to escalate local process privileges via unspecified vectors.

  • CVE-2008-4508Oct 9, 2008
    risk 0.03cvss epss 0.06

    Stack-based buffer overflow in the file parsing function in Tonec Internet Download Manager, possibly 5.14 and earlier, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted AppleDouble file containing a long string. …

  • CVE-2005-2210Jul 11, 2005
    risk 0.03cvss epss 0.04

    Stack-based buffer overflow in Internet Download Manager 4.05 allows remote attackers to execute arbitrary code via a long URL.

  • CVE-2010-0995May 6, 2010
    risk 0.01cvss epss 0.07

    Stack-based buffer overflow in Internet Download Manager (IDM) before 5.19 allows remote attackers to execute arbitrary code via a crafted FTP URI that causes unspecified "test sequences" to be sent from client to server.