Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2018-10756

Disclosure Date: May 15, 2020 (last updated November 08, 2023)
Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted torrent file.
Attacker Value
Unknown

CVE-2010-0748

Disclosure Date: October 30, 2019 (last updated November 27, 2024)
Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr arguments in a magnet link.
Attacker Value
Unknown

CVE-2010-0749

Disclosure Date: October 30, 2019 (last updated November 27, 2024)
Transmission before 1.92 allows attackers to prevent download of a file by corrupted data during the endgame.
Attacker Value
Unknown

CVE-2018-5702

Disclosure Date: January 15, 2018 (last updated November 26, 2024)
Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access control, which allows remote attackers to execute arbitrary RPC commands, and consequently write to arbitrary files, via POST requests to /transmission/rpc in conjunction with a DNS rebinding attack.
0
Attacker Value
Unknown

CVE-2014-4909

Disclosure Date: July 29, 2014 (last updated October 05, 2023)
Integer overflow in the tr_bitfieldEnsureNthBitAlloced function in bitfield.c in Transmission before 2.84 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted peer message, which triggers an out-of-bounds write.
0
Attacker Value
Unknown

CVE-2012-6129

Disclosure Date: April 03, 2013 (last updated October 05, 2023)
Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted "micro transport protocol packets."
0
Attacker Value
Unknown

CVE-2012-4037

Disclosure Date: August 15, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the web client in Transmission before 2.61 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) created by, or (3) name field in a torrent file.
0
Attacker Value
Unknown

CVE-2010-1853

Disclosure Date: May 07, 2010 (last updated October 04, 2023)
Multiple stack-based buffer overflows in the tr_magnetParse function in libtransmission/magnet.c in Transmission 1.91 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted magnet URL with a large number of (1) tr or (2) ws links.
0
Attacker Value
Unknown

CVE-2010-0012

Disclosure Date: January 08, 2010 (last updated January 27, 2024)
Directory traversal vulnerability in libtransmission/metainfo.c in Transmission 1.22, 1.34, 1.75, and 1.76 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a pathname within a .torrent file.
Attacker Value
Unknown

CVE-2009-1757

Disclosure Date: May 22, 2009 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in Transmission 1.5 before 1.53 and 1.6 before 1.61 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
0