Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Bittorrent

First CVE: Jan 18, 2008Active for: 19 yearsTotal CVEs: 13
52.5
VTI Score
TOP TARGET

BitTorrent's vulnerability profile spans a modest set of peer-to-peer and distributed file-sharing products, including the widely deployed uTorrent client and related DHT bootstrap infrastructure, where disclosures cluster around memory-safety and input-handling weaknesses such as buffer-boundary violations, command injection, and improper input validation. The vendor's exposure exhibits a notable tendency toward public exploit availability, reflecting the accessibility of client and network-exposed components to security research and tooling development. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 71% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Bittorrent over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 18, 2008
18 years ago
Most Recent CVE
Jun 17, 2022
1,500 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2008-4434HIGH
Stack-based buffer overflow in (1) uTorrent 1.7.7 build 8179 and earlier and (2) BitTorrent 6.0.3 build 8642 and earlier allows remote attackers to cause a denial of service (crash
Oct 3, 20089.342NOYES
CVE-2020-8437HIGH
The bencoding parser in BitTorrent uTorrent through 3.5.5 (build 45505) misparses nested bencoded dictionaries, which allows a remote attacker to cause a denial of service.
Mar 2, 20207.530NONO
CVE-2018-25044HIGH
A vulnerability, which was classified as critical, has been found in uTorrent. This issue affects some unknown processing of the component Guest Account. The manipulation leads to
Jun 17, 20228.828NONO
CVE-2018-25043HIGH
A vulnerability classified as critical was found in uTorrent. This vulnerability affects unknown code of the component PRNG. The manipulation leads to weak authentication. The atta
Jun 17, 20228.828NONO
CVE-2018-25042HIGH
A vulnerability classified as critical has been found in uTorrent. This affects an unknown part. The manipulation leads to memory corruption. It is possible to initiate the attack
Jun 17, 20228.828NONO
CVE-2008-0071MEDIUM
The Web UI interface in (1) BitTorrent before 6.0.3 build 8642 and (2) uTorrent before 1.8beta build 10524 allows remote attackers to cause a denial of service (application crash)
Jun 16, 20084.326NOYES
CVE-2008-0364MEDIUM
Buffer overflow in (1) BitTorrent 6.0 and earlier; and (2) uTorrent 1.7.5 and earlier, and 1.8-alpha-7834 and earlier in the 1.8.x series; on Windows allows remote attackers to cau
Jan 18, 20085.026NOYES
CVE-2015-5474HIGH
BitTorrent and uTorrent allow remote attackers to inject command line parameters and execute arbitrary commands via a crafted URL using the (1) bittorrent or (2) magnet protocol.
Aug 13, 20159.324NONO
CVE-2015-2846HIGH
BitTorrent Sync allows remote attackers to execute arbitrary commands via a crafted btsync: link.
Apr 13, 20159.324NONO
CVE-2015-5685HIGH
The lazy_bdecode function in BitTorrent DHT bootstrap server (bootstrap-dht ) allows remote attackers to execute arbitrary code via a crafted packet, related to "improper indexing.
Aug 13, 20157.521NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
31%
69%
Severity distribution among all CVEs352,713 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network4 (30.8%)
Unknown9 (69.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (30.8%)
High0 (0.0%)
Unknown9 (69.2%)
User Interaction
None1 (7.7%)
Unknown9 (69.2%)
Required3 (23.1%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (30.8%)
Unknown9 (69.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
23.1% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Bittorrent.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Bittorrent — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Bittorrent's Products

View all 2 CNAs →

Top CWEs