Transmissionbt Transmission vulnerabilities
10 known vulnerabilities affecting transmissionbt/transmission.
Total CVEs
10
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH4MEDIUM4LOW1
Vulnerabilities
Page 1 of 1
CVE-2018-5702P2HIGHCVSS 8.8PoC≤ 2.922018-01-15
CVE-2018-5702 [HIGH] CVE-2018-5702: Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for F
Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access control, which allows remote attackers to execute arbitrary RPC commands, and consequently write to arbitrary files, via POST requests to /transmission/rpc in conjunction with a DNS rebinding attack.
nvdosv
CVE-2010-0012P3HIGHCVSS 8.8v1.22v1.34+2 more2010-01-08
CVE-2010-0012 [HIGH] CWE-22 CVE-2010-0012: Directory traversal vulnerability in libtransmission/metainfo.c in Transmission 1.22, 1.34, 1.75, an
Directory traversal vulnerability in libtransmission/metainfo.c in Transmission 1.22, 1.34, 1.75, and 1.76 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a pathname within a .torrent file.
nvdosv
CVE-2012-6129P3HIGHCVSS 7.5≤ 2.73v0.1+90 more2013-04-03
CVE-2012-6129 [HIGH] CWE-119 CVE-2012-6129: Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly o
Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted "micro transport protocol packets."
nvdosv
CVE-2010-0748P3CRITICALCVSS 9.8fixed in 1.922019-10-30
CVE-2010-0748 [CRITICAL] CWE-20 CVE-2010-0748: Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have ot
Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr arguments in a magnet link.
nvdosv
CVE-2014-4909P3MEDIUMCVSS 6.8≤ 2.83v0.1+98 more2014-07-29
CVE-2014-4909 [MEDIUM] CWE-189 CVE-2014-4909: Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before
Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted peer message, which triggers an out-of-bounds write.
nvdosv
CVE-2018-10756P3HIGHCVSS 7.8fixed in 3.002020-05-15
CVE-2018-10756 [HIGH] CWE-416 CVE-2018-10756: Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to c
Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted torrent file.
nvdosv
CVE-2010-1853P4MEDIUMCVSS 6.8v1.912010-05-07
CVE-2010-1853 [MEDIUM] CWE-119 CVE-2010-1853: Multiple stack-based buffer overflows in the tr_magnetParse function in libtransmission/magnet.c in
Multiple stack-based buffer overflows in the tr_magnetParse function in libtransmission/magnet.c in Transmission 1.91 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted magnet URL with a large number of (1) tr or (2) ws links.
nvdosv
CVE-2010-0749P4MEDIUMCVSS 5.3fixed in 1.922019-10-30
CVE-2010-0749 [MEDIUM] CWE-119 CVE-2010-0749: Transmission before 1.92 allows attackers to prevent download of a file by corrupted data during the
Transmission before 1.92 allows attackers to prevent download of a file by corrupted data during the endgame.
nvdosv
CVE-2009-1757P4MEDIUMCVSS 6.8v1.50v1.51+2 more2009-05-22
CVE-2009-1757 [MEDIUM] CWE-352 CVE-2009-1757: Cross-site request forgery (CSRF) vulnerability in Transmission 1.5 before 1.53 and 1.6 before 1.61
Cross-site request forgery (CSRF) vulnerability in Transmission 1.5 before 1.53 and 1.6 before 1.61 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
nvdosv
CVE-2012-4037P4LOWCVSS 2.6≤ 2.60v0.1+85 more2012-08-15
CVE-2012-4037 [LOW] CWE-79 CVE-2012-4037: Multiple cross-site scripting (XSS) vulnerabilities in the web client in Transmission before 2.61 al
Multiple cross-site scripting (XSS) vulnerabilities in the web client in Transmission before 2.61 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) created by, or (3) name field in a torrent file.
nvdosv