MidnightBSD

Advisories for utorrent

CVE-2010-3129 HIGH

Untrusted search path vulnerability in uTorrent 2.0.3 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse plugin_dll.dll, userenv.dll, shfolder.dll, dnsapi.dll, dwmapi.dll, iphlpapi.dll, dhcpcsvc.dll, dhcpcsvc6.dll, or rpcrtremote.dll that is located in the same folder as a .torrent or .btsearch file.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
utorrent utorrent 1.8
utorrent utorrent 1.8.1
utorrent utorrent 1.7.4
utorrent utorrent 2.0.3
utorrent utorrent 1.2
utorrent utorrent 1.7
utorrent utorrent 2.0.2
utorrent utorrent 1.1.3
utorrent utorrent 1.1.6
utorrent utorrent 1.1.1
utorrent utorrent 1.7.5
utorrent utorrent 1.7.1
utorrent utorrent 1.8.4
utorrent utorrent 1.2.1
utorrent utorrent 2.0
utorrent utorrent 1.8.3
utorrent utorrent 2.0.1
utorrent utorrent 1.8.5
utorrent utorrent 1.2.2
utorrent utorrent 1.7.2
utorrent utorrent 1.1.4
utorrent utorrent 1.8.2
utorrent utorrent 1.1.7
utorrent utorrent 1.7.6
utorrent utorrent 1.1.5
CVE-2014-5727 MEDIUM

The uTorrent Remote (aka com.utorrent.web) application 1.0.20110929 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-310,

Products Affected

Vendor Product Version
utorrent utorrent_remote 1.0.20110929
CVE-2015-5474 HIGH

BitTorrent and uTorrent allow remote attackers to inject command line parameters and execute arbitrary commands via a crafted URL using the (1) bittorrent or (2) magnet protocol.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-77,

Products Affected

Vendor Product Version
bittorrent bittorrent *
utorrent utorrent *
CVE-2018-25040 MEDIUM

A vulnerability was found in uTorrent Web. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component HTTP RPC Server. The manipulation leads to privilege escalation. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
nvd@nist.gov 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 2.8 5.9
cna@vuldb.com 6.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L 2.8 3.4

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-269,NVD-CWE-noinfo,

Products Affected

Vendor Product Version
utorrent web -
CVE-2018-25041 MEDIUM

A vulnerability was found in uTorrent. It has been rated as critical. Affected by this issue is some unknown functionality of the component JSON RPC Server. The manipulation leads to privilege escalation. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.

CVSS 3.x

Source Score Severity Vector Exploitability Impact
cna@vuldb.com 6.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L 2.8 3.4
nvd@nist.gov 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 2.8 5.9

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-269,NVD-CWE-noinfo,

Products Affected

Vendor Product Version
utorrent web -