Записи uTorrent
12 опубликованных записей вендора utorrent.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer4
- CWE-269 Improper Privilege Management2
- CWE-20 Improper Input Validation1
- CWE-310 Cryptographic Issues1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
12 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
43В плане | CVE-2007-0927Proof of concept | Heap-based buffer overflow in uTorrent 1.6 allows remote attackers to execute arbitrary code via a torrent file with a crafted announce headutorrent · utorrent | Высокая7,5 | — | 45,0 % | 14 февр. 2007 г. |
40В плане | CVE-2008-4434Proof of concept | Stack-based buffer overflow in (1) uTorrent 1.7.7 build 8179 and earlier and (2) BitTorrent 6.0.3 build 8642 and earlier allows remote attacutorrent · utorrent · CWE-119 | Критическая9,3 | — | 11,0 % | 3 окт. 2008 г. |
39Наблюдать | CVE-2010-3129Proof of concept | Untrusted search path vulnerability in uTorrent 2.0.3 and earlier allows local users, and possibly remote attackers, to execute arbitrary coutorrent · utorrent | Критическая9,3 | — | 7,3 % | 26 авг. 2010 г. |
38Наблюдать | CVE-2015-5474Эксплойта нет | BitTorrent and uTorrent allow remote attackers to inject command line parameters and execute arbitrary commands via a crafted URL using the bittorrent · bittorrent · CWE-77 | Критическая9,3 | — | 3,8 % | 13 авг. 2015 г. |
35Наблюдать | CVE-2018-25041Эксплойта нет | uTorrent JSON RPC Server privileges managementutorrent · web · CWE-269 | Высокая8,8 | — | 1,0 % | 17 июн. 2022 г. |
35Наблюдать | CVE-2018-25040Эксплойта нет | uTorrent Web HTTP RPC Server privileges managementutorrent · web · CWE-269 | Высокая8,8 | — | 0,9 % | 17 июн. 2022 г. |
29Наблюдать | CVE-2009-5134Proof of concept | Buffer overflow in the "create torrent dialog" functionality in uTorrent 1.8.3 build 15772, and possibly other versions before 1.8.3 (Build utorrent · utorrent · CWE-119 | Средняя6,8 | — | 7,7 % | 18 янв. 2013 г. |
28Наблюдать | CVE-2008-6586Proof of concept | Cross-site request forgery (CSRF) vulnerability in gui/index.php in µTorrent (uTorrent) WebUI 0.315 allows remote attackers to (1) hijack thutorrent · utorrent webui · CWE-352 | Средняя6,8 | — | 2,7 % | 3 апр. 2009 г. |
23Наблюдать | CVE-2008-0364Proof of concept | Buffer overflow in (1) BitTorrent 6.0 and earlier; and (2) uTorrent 1.7.5 and earlier, and 1.8-alpha-7834 and earlier in the 1.8.x series; obittorrent · bittorrent · CWE-119 | Средняя5,0 | — | 8,9 % | 18 янв. 2008 г. |
21Наблюдать | CVE-2008-7166Эксплойта нет | Buffer overflow in the web interface in BitTorrent 6.0.1 (build 7859) and earlier, and uTorrent 1.7.6 (build 7859) and earlier, allows remotbittorrent · bittorrent · CWE-119 | Средняя5,0 | — | 2,8 % | 4 сент. 2009 г. |
21Наблюдать | CVE-2014-5727Эксплойта нет | The uTorrent Remote (aka com.utorrent.web) application 1.0.20110929 for Android does not verify X.509 certificates from SSL servers, which autorrent · utorrent remote · CWE-310 | Средняя5,4 | — | 0,3 % | 9 сент. 2014 г. |
19Наблюдать | CVE-2008-0071Proof of concept | The Web UI interface in (1) BitTorrent before 6.0.3 build 8642 and (2) uTorrent before 1.8beta build 10524 allows remote attackers to cause bittorrent · bittorrent · CWE-20 | Средняя4,3 | — | 7,2 % | 16 июн. 2008 г. |
- CVE-2007-092743В плане
Heap-based buffer overflow in uTorrent 1.6 allows remote attackers to execute arbitrary code via a torrent file with a crafted announce head
ВысокаяCVSS 7,5Proof of conceptEPSS 45 %utorrent · utorrent14 февр. 2007 г.
- CVE-2008-443440В плане
Stack-based buffer overflow in (1) uTorrent 1.7.7 build 8179 and earlier and (2) BitTorrent 6.0.3 build 8642 and earlier allows remote attac
КритическаяCVSS 9,3Proof of conceptEPSS 11 %utorrent · utorrent3 окт. 2008 г.
- CVE-2010-312939Наблюдать
Untrusted search path vulnerability in uTorrent 2.0.3 and earlier allows local users, and possibly remote attackers, to execute arbitrary co
КритическаяCVSS 9,3Proof of conceptEPSS 7 %utorrent · utorrent26 авг. 2010 г.
- CVE-2015-547438Наблюдать
BitTorrent and uTorrent allow remote attackers to inject command line parameters and execute arbitrary commands via a crafted URL using the
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %bittorrent · bittorrent13 авг. 2015 г.
- CVE-2018-2504135Наблюдать
uTorrent JSON RPC Server privileges management
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %utorrent · web17 июн. 2022 г.
- CVE-2018-2504035Наблюдать
uTorrent Web HTTP RPC Server privileges management
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %utorrent · web17 июн. 2022 г.
- CVE-2009-513429Наблюдать
Buffer overflow in the "create torrent dialog" functionality in uTorrent 1.8.3 build 15772, and possibly other versions before 1.8.3 (Build
СредняяCVSS 6,8Proof of conceptEPSS 8 %utorrent · utorrent18 янв. 2013 г.
- CVE-2008-658628Наблюдать
Cross-site request forgery (CSRF) vulnerability in gui/index.php in µTorrent (uTorrent) WebUI 0.315 allows remote attackers to (1) hijack th
СредняяCVSS 6,8Proof of conceptEPSS 3 %utorrent · utorrent webui3 апр. 2009 г.
- CVE-2008-036423Наблюдать
Buffer overflow in (1) BitTorrent 6.0 and earlier; and (2) uTorrent 1.7.5 and earlier, and 1.8-alpha-7834 and earlier in the 1.8.x series; o
СредняяCVSS 5,0Proof of conceptEPSS 9 %bittorrent · bittorrent18 янв. 2008 г.
- CVE-2008-716621Наблюдать
Buffer overflow in the web interface in BitTorrent 6.0.1 (build 7859) and earlier, and uTorrent 1.7.6 (build 7859) and earlier, allows remot
СредняяCVSS 5,0Эксплойта нетEPSS 3 %bittorrent · bittorrent4 сент. 2009 г.
- CVE-2014-572721Наблюдать
The uTorrent Remote (aka com.utorrent.web) application 1.0.20110929 for Android does not verify X.509 certificates from SSL servers, which a
СредняяCVSS 5,4Эксплойта нетEPSS 0 %utorrent · utorrent remote9 сент. 2014 г.
- CVE-2008-007119Наблюдать
The Web UI interface in (1) BitTorrent before 6.0.3 build 8642 and (2) uTorrent before 1.8beta build 10524 allows remote attackers to cause
СредняяCVSS 4,3Proof of conceptEPSS 7 %bittorrent · bittorrent16 июн. 2008 г.