CVE History
| CVE | Affected | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|---|
| < 3.00 | 7.8 HIGH | 6.8 MEDIUM | ||
Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted torrent file. | ||||
| < 1.92 | 9.8 CRITICAL | 7.5 HIGH | ||
Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr arguments in a magnet link. | ||||
| < 1.92 | 5.3 MEDIUM | 5 MEDIUM | ||
Transmission before 1.92 allows attackers to prevent download of a file by corrupted data during the endgame. | ||||
| <= 2.92 | — | 6.8 MEDIUM | ||
Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access control, which allows remote attackers to execute arbitrary RPC commands, and consequently write to arbitrary files, via POST requests to /transmission/rpc in conjunction with a DNS rebinding attack. | ||||