← Back

Transmissionbt

transmissionbt

10 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Transmission
transmission

CVEs (10)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
FedoraprojectTransmissionbt
3Debian Linux
FedoraTransmission
Nov 21, 2024
May 15, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted torrent file.
2Debian
Transmissionbt
2Debian Linux
Transmission
Nov 21, 2024
Oct 30, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Transmission before 1.92 allows attackers to prevent download of a file by corrupted data during the endgame.
2Debian
Transmissionbt
2Debian Linux
Transmission
Nov 21, 2024
Oct 30, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr arguments in a magnet link.
2Debian
Transmissionbt
2Debian Linux
Transmission
Nov 21, 2024
Jan 15, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access control, which allows remote attackers to execute arbitrary RPC commands, and consequently write to arb...Show more
Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access control, which allows remote attackers to execute arbitrary RPC commands, and consequently write to arbitrary files, via POST requests to /transmission/rpc in conjunction with a DNS rebinding attack.Show less
4Canonical
FedoraprojectGentoo+1 more
4Fedora
LinuxTransmission+1 more
May 6, 2026
Jul 29, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted peer messag...Show more
Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted peer message, which triggers an out-of-bounds write.Show less
3Canonical
FedoraprojectTransmissionbt
3Fedora
TransmissionUbuntu Linux
Apr 29, 2026
Apr 3, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via craf...Show more
Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted "micro transport protocol packets."Show less
1Transmissionbt
1Transmission
Apr 29, 2026
Aug 15, 2012
N/A· v4
N/A· v3
2.6 LOW· v2
Multiple cross-site scripting (XSS) vulnerabilities in the web client in Transmission before 2.61 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) created by, or (3) name field in a...Show more
Multiple cross-site scripting (XSS) vulnerabilities in the web client in Transmission before 2.61 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) created by, or (3) name field in a torrent file.Show less
1Transmissionbt
1Transmission
Apr 29, 2026
May 7, 2010
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple stack-based buffer overflows in the tr_magnetParse function in libtransmission/magnet.c in Transmission 1.91 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a c...Show more
Multiple stack-based buffer overflows in the tr_magnetParse function in libtransmission/magnet.c in Transmission 1.91 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted magnet URL with a large number of (1) tr or (2) ws links.Show less
3Debian
OpensuseTransmissionbt
3Debian Linux
OpensuseTransmission
Apr 23, 2026
Jan 8, 2010
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Directory traversal vulnerability in libtransmission/metainfo.c in Transmission 1.22, 1.34, 1.75, and 1.76 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a pathname within a .torrent file.
1Transmissionbt
1Transmission
Apr 23, 2026
May 22, 2009
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in Transmission 1.5 before 1.53 and 1.6 before 1.61 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.