Vulnerabilities (CVE)

Filtered by vendor Transmissionbt Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-10756 3 Debian, Fedoraproject, Transmissionbt 3 Debian Linux, Fedora, Transmission 2020-08-14 6.8 MEDIUM 7.8 HIGH
Use-after-free in libtransmission/variant.c in Transmission before 3.00 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted torrent file.
CVE-2018-5702 2 Debian, Transmissionbt 2 Debian Linux, Transmission 2019-10-03 6.8 MEDIUM 8.8 HIGH
Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access control, which allows remote attackers to execute arbitrary RPC commands, and consequently write to arbitrary files, via POST requests to /transmission/rpc in conjunction with a DNS rebinding attack.