Vulnerabilities
Vulnerable Software
Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted torrent file.
CVSS Score
7.8
EPSS Score
0.024
Published
2020-05-15
Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr arguments in a magnet link.
CVSS Score
9.8
EPSS Score
0.009
Published
2019-10-30
Transmission before 1.92 allows attackers to prevent download of a file by corrupted data during the endgame.
CVSS Score
5.3
EPSS Score
0.007
Published
2019-10-30
Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access control, which allows remote attackers to execute arbitrary RPC commands, and consequently write to arbitrary files, via POST requests to /transmission/rpc in conjunction with a DNS rebinding attack.
CVSS Score
8.8
EPSS Score
0.361
Published
2018-01-15
Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted peer message, which triggers an out-of-bounds write.
CVSS Score
6.8
EPSS Score
0.092
Published
2014-07-29
Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted "micro transport protocol packets."
CVSS Score
7.5
EPSS Score
0.027
Published
2013-04-03
Multiple cross-site scripting (XSS) vulnerabilities in the web client in Transmission before 2.61 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) created by, or (3) name field in a torrent file.
CVSS Score
2.6
EPSS Score
0.005
Published
2012-08-15


Contact Us

Shodan ® - All rights reserved