transmissionbt CVE Vulnerabilities & CVE List (10)

Products (CPE): — CVEs: 10

transmissionbt vulnerability overview

Aggregates CVE and security vulnerability intelligence across all transmissionbt-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Disclosed issues often relate to vendor risk cross-site scripting, vendor risk csrf, and vendor risk path handling; exposure may include vendor impact memory corruption in vendor surface production workloads contexts.

Vulnerability distribution trend (last 24 months)

Showing 110 of 10 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2018-10756 Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted torrent file. [email protected] 7.8 2.38% 2020-05-15 2024-11-21
CVE-2010-0749 Transmission before 1.92 allows attackers to prevent download of a file by corrupted data during the endgame. [email protected] 5.3 0.73% 2019-10-30 2024-11-21
CVE-2010-0748 Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr arguments in a magnet link. [email protected] 9.8 0.86% 2019-10-30 2024-11-21
CVE-2018-5702 Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access control, which allows remote attackers to execute arbitrary RPC commands, and consequently write to arbitrary files, via POST requests to /transmission/rpc in conjunction with a DNS rebinding attack. [email protected] 8.8 26.35% 2018-01-15 2024-11-21
CVE-2014-4909 Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted peer message, which triggers an out-of-bounds write. [email protected] 6.8 9.19% 2014-07-29 2026-05-06
CVE-2012-6129 Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted "micro transport protocol packets." [email protected] 7.5 2.68% 2013-04-03 2026-04-29
CVE-2012-4037 Multiple cross-site scripting (XSS) vulnerabilities in the web client in Transmission before 2.61 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) created by, or (3) name field in a torrent file. [email protected] 2.6 0.55% 2012-08-15 2026-04-29
CVE-2010-1853 Multiple stack-based buffer overflows in the tr_magnetParse function in libtransmission/magnet.c in Transmission 1.91 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted magnet URL with a large number of (1) tr or (2) ws links. [email protected] 6.8 3.01% 2010-05-07 2026-04-29
CVE-2010-0012 Directory traversal vulnerability in libtransmission/metainfo.c in Transmission 1.22, 1.34, 1.75, and 1.76 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a pathname within a .torrent file. [email protected] 8.8 0.30% 2010-01-08 2026-04-23
CVE-2009-1757 Cross-site request forgery (CSRF) vulnerability in Transmission 1.5 before 1.53 and 1.6 before 1.61 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. [email protected] 6.8 0.12% 2009-05-22 2026-04-23
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence