uTorrent records
12 published records for vendor utorrent.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer4
- CWE-269 Improper Privilege Management2
- CWE-20 Improper Input Validation1
- CWE-310 Cryptographic Issues1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2007-0927Proof of concept | Heap-based buffer overflow in uTorrent 1.6 allows remote attackers to execute arbitrary code via a torrent file with a crafted announce headutorrent · utorrent | High7.5 | — | 45.0% | Feb 14, 2007 |
40Plan | CVE-2008-4434Proof of concept | Stack-based buffer overflow in (1) uTorrent 1.7.7 build 8179 and earlier and (2) BitTorrent 6.0.3 build 8642 and earlier allows remote attacutorrent · utorrent · CWE-119 | Critical9.3 | — | 11.0% | Oct 3, 2008 |
39Monitor | CVE-2010-3129Proof of concept | Untrusted search path vulnerability in uTorrent 2.0.3 and earlier allows local users, and possibly remote attackers, to execute arbitrary coutorrent · utorrent | Critical9.3 | — | 7.3% | Aug 26, 2010 |
38Monitor | CVE-2015-5474No exploit | BitTorrent and uTorrent allow remote attackers to inject command line parameters and execute arbitrary commands via a crafted URL using the bittorrent · bittorrent · CWE-77 | Critical9.3 | — | 3.8% | Aug 13, 2015 |
35Monitor | CVE-2018-25041No exploit | uTorrent JSON RPC Server privileges managementutorrent · web · CWE-269 | High8.8 | — | 1.0% | Jun 17, 2022 |
35Monitor | CVE-2018-25040No exploit | uTorrent Web HTTP RPC Server privileges managementutorrent · web · CWE-269 | High8.8 | — | 0.9% | Jun 17, 2022 |
29Monitor | CVE-2009-5134Proof of concept | Buffer overflow in the "create torrent dialog" functionality in uTorrent 1.8.3 build 15772, and possibly other versions before 1.8.3 (Build utorrent · utorrent · CWE-119 | Medium6.8 | — | 7.7% | Jan 18, 2013 |
28Monitor | CVE-2008-6586Proof of concept | Cross-site request forgery (CSRF) vulnerability in gui/index.php in µTorrent (uTorrent) WebUI 0.315 allows remote attackers to (1) hijack thutorrent · utorrent webui · CWE-352 | Medium6.8 | — | 2.7% | Apr 3, 2009 |
23Monitor | CVE-2008-0364Proof of concept | Buffer overflow in (1) BitTorrent 6.0 and earlier; and (2) uTorrent 1.7.5 and earlier, and 1.8-alpha-7834 and earlier in the 1.8.x series; obittorrent · bittorrent · CWE-119 | Medium5.0 | — | 8.9% | Jan 18, 2008 |
21Monitor | CVE-2008-7166No exploit | Buffer overflow in the web interface in BitTorrent 6.0.1 (build 7859) and earlier, and uTorrent 1.7.6 (build 7859) and earlier, allows remotbittorrent · bittorrent · CWE-119 | Medium5.0 | — | 2.8% | Sep 4, 2009 |
21Monitor | CVE-2014-5727No exploit | The uTorrent Remote (aka com.utorrent.web) application 1.0.20110929 for Android does not verify X.509 certificates from SSL servers, which autorrent · utorrent remote · CWE-310 | Medium5.4 | — | 0.3% | Sep 9, 2014 |
19Monitor | CVE-2008-0071Proof of concept | The Web UI interface in (1) BitTorrent before 6.0.3 build 8642 and (2) uTorrent before 1.8beta build 10524 allows remote attackers to cause bittorrent · bittorrent · CWE-20 | Medium4.3 | — | 7.2% | Jun 16, 2008 |
- CVE-2007-092743Plan
Heap-based buffer overflow in uTorrent 1.6 allows remote attackers to execute arbitrary code via a torrent file with a crafted announce head
HighCVSS 7.5Proof of conceptEPSS 45%utorrent · utorrentFeb 14, 2007
- CVE-2008-443440Plan
Stack-based buffer overflow in (1) uTorrent 1.7.7 build 8179 and earlier and (2) BitTorrent 6.0.3 build 8642 and earlier allows remote attac
CriticalCVSS 9.3Proof of conceptEPSS 11%utorrent · utorrentOct 3, 2008
- CVE-2010-312939Monitor
Untrusted search path vulnerability in uTorrent 2.0.3 and earlier allows local users, and possibly remote attackers, to execute arbitrary co
CriticalCVSS 9.3Proof of conceptEPSS 7%utorrent · utorrentAug 26, 2010
- CVE-2015-547438Monitor
BitTorrent and uTorrent allow remote attackers to inject command line parameters and execute arbitrary commands via a crafted URL using the
CriticalCVSS 9.3No exploitEPSS 4%bittorrent · bittorrentAug 13, 2015
- CVE-2018-2504135Monitor
uTorrent JSON RPC Server privileges management
HighCVSS 8.8No exploitEPSS 1%utorrent · webJun 17, 2022
- CVE-2018-2504035Monitor
uTorrent Web HTTP RPC Server privileges management
HighCVSS 8.8No exploitEPSS 1%utorrent · webJun 17, 2022
- CVE-2009-513429Monitor
Buffer overflow in the "create torrent dialog" functionality in uTorrent 1.8.3 build 15772, and possibly other versions before 1.8.3 (Build
MediumCVSS 6.8Proof of conceptEPSS 8%utorrent · utorrentJan 18, 2013
- CVE-2008-658628Monitor
Cross-site request forgery (CSRF) vulnerability in gui/index.php in µTorrent (uTorrent) WebUI 0.315 allows remote attackers to (1) hijack th
MediumCVSS 6.8Proof of conceptEPSS 3%utorrent · utorrent webuiApr 3, 2009
- CVE-2008-036423Monitor
Buffer overflow in (1) BitTorrent 6.0 and earlier; and (2) uTorrent 1.7.5 and earlier, and 1.8-alpha-7834 and earlier in the 1.8.x series; o
MediumCVSS 5.0Proof of conceptEPSS 9%bittorrent · bittorrentJan 18, 2008
- CVE-2008-716621Monitor
Buffer overflow in the web interface in BitTorrent 6.0.1 (build 7859) and earlier, and uTorrent 1.7.6 (build 7859) and earlier, allows remot
MediumCVSS 5.0No exploitEPSS 3%bittorrent · bittorrentSep 4, 2009
- CVE-2014-572721Monitor
The uTorrent Remote (aka com.utorrent.web) application 1.0.20110929 for Android does not verify X.509 certificates from SSL servers, which a
MediumCVSS 5.4No exploitEPSS 0%utorrent · utorrent remoteSep 9, 2014
- CVE-2008-007119Monitor
The Web UI interface in (1) BitTorrent before 6.0.3 build 8642 and (2) uTorrent before 1.8beta build 10524 allows remote attackers to cause
MediumCVSS 4.3Proof of conceptEPSS 7%bittorrent · bittorrentJun 16, 2008