Vulnerabilities > Bittorrent > Critical

DATE CVE VULNERABILITY TITLE RISK
2015-08-13 CVE-2015-5474 Command Injection vulnerability in multiple products
BitTorrent and uTorrent allow remote attackers to inject command line parameters and execute arbitrary commands via a crafted URL using the (1) bittorrent or (2) magnet protocol.
network
bittorrent utorrent CWE-77
critical
9.3
2015-04-13 CVE-2015-2846 Command Injection vulnerability in Bittorrent Sync
BitTorrent Sync allows remote attackers to execute arbitrary commands via a crafted btsync: link.
network
bittorrent CWE-77
critical
9.3
2008-10-03 CVE-2008-4434 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in multiple products
Stack-based buffer overflow in (1) uTorrent 1.7.7 build 8179 and earlier and (2) BitTorrent 6.0.3 build 8642 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Created By field in a .torrent file.
network
utorrent bittorrent CWE-119
critical
9.3