Internet Download Manager 6.38.12 contains a buffer overflow vulnerability in the Scheduler component that allows local attackers to crash the application by supplying oversized input. Attackers can paste malicious data exceeding 5000 bytes into the 'Open the following file when done' field to trigger a denial of service condition.
History

Mon, 18 May 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 16 May 2026 15:45:00 +0000

Type Values Removed Values Added
Description Internet Download Manager 6.38.12 contains a buffer overflow vulnerability in the Scheduler component that allows local attackers to crash the application by supplying oversized input. Attackers can paste malicious data exceeding 5000 bytes into the 'Open the following file when done' field to trigger a denial of service condition.
Title Internet Download Manager 6.38.12 Scheduler Buffer Overflow
First Time appeared Tonec
Tonec internet Download Manager
Weaknesses CWE-120
CPEs cpe:2.3:a:tonec:internet_download_manager:6.38.12:*:*:*:*:*:*:*
Vendors & Products Tonec
Tonec internet Download Manager
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-05-18T17:53:34.461Z

Reserved: 2026-05-15T14:12:15.177Z

Link: CVE-2020-37234

cve-icon Vulnrichment

Updated: 2026-05-18T17:39:42.980Z

cve-icon NVD

Status : Deferred

Published: 2026-05-16T16:16:19.440

Modified: 2026-05-18T19:42:03.353

Link: CVE-2020-37234

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-17T18:45:07Z