BitTorrent's vulnerability profile spans a modest set of peer-to-peer and distributed file-sharing products, including the widely deployed uTorrent client and related DHT bootstrap infrastructure, where disclosures cluster around memory-safety and input-handling weaknesses such as buffer-boundary violations, command injection, and improper input validation. The vendor's exposure exhibits a notable tendency toward public exploit availability, reflecting the accessibility of client and network-exposed components to security research and tooling development. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bittorrent over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-4434HIGH Stack-based buffer overflow in (1) uTorrent 1.7.7 build 8179 and earlier and (2) BitTorrent 6.0.3 build 8642 and earlier allows remote attackers to cause a denial of service (crash | Oct 3, 2008 | 9.3 | 42 | NO | YES |
CVE-2020-8437HIGH The bencoding parser in BitTorrent uTorrent through 3.5.5 (build 45505) misparses nested bencoded dictionaries, which allows a remote attacker to cause a denial of service. | Mar 2, 2020 | 7.5 | 30 | NO | NO |
CVE-2018-25044HIGH A vulnerability, which was classified as critical, has been found in uTorrent. This issue affects some unknown processing of the component Guest Account. The manipulation leads to | Jun 17, 2022 | 8.8 | 28 | NO | NO |
CVE-2018-25043HIGH A vulnerability classified as critical was found in uTorrent. This vulnerability affects unknown code of the component PRNG. The manipulation leads to weak authentication. The atta | Jun 17, 2022 | 8.8 | 28 | NO | NO |
CVE-2018-25042HIGH A vulnerability classified as critical has been found in uTorrent. This affects an unknown part. The manipulation leads to memory corruption. It is possible to initiate the attack | Jun 17, 2022 | 8.8 | 28 | NO | NO |
CVE-2008-0071MEDIUM The Web UI interface in (1) BitTorrent before 6.0.3 build 8642 and (2) uTorrent before 1.8beta build 10524 allows remote attackers to cause a denial of service (application crash) | Jun 16, 2008 | 4.3 | 26 | NO | YES |
CVE-2008-0364MEDIUM Buffer overflow in (1) BitTorrent 6.0 and earlier; and (2) uTorrent 1.7.5 and earlier, and 1.8-alpha-7834 and earlier in the 1.8.x series; on Windows allows remote attackers to cau | Jan 18, 2008 | 5.0 | 26 | NO | YES |
CVE-2015-5474HIGH BitTorrent and uTorrent allow remote attackers to inject command line parameters and execute arbitrary commands via a crafted URL using the (1) bittorrent or (2) magnet protocol. | Aug 13, 2015 | 9.3 | 24 | NO | NO |
CVE-2015-2846HIGH BitTorrent Sync allows remote attackers to execute arbitrary commands via a crafted btsync: link. | Apr 13, 2015 | 9.3 | 24 | NO | NO |
CVE-2015-5685HIGH The lazy_bdecode function in BitTorrent DHT bootstrap server (bootstrap-dht ) allows remote attackers to execute arbitrary code via a crafted packet, related to "improper indexing. | Aug 13, 2015 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bittorrent.
Media articles that mention a CVE ID that affects a product developed by Bittorrent — matched by CVE ID, not by vendor name.