Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Utorrent

First CVE: Feb 14, 2007Active for: 19 yearsTotal CVEs: 12
46.5
VTI Score
High

µTorrent is a lightweight peer-to-peer file-sharing application with a modest but widely distributed user base, encompassing the core client, web interface, and remote-access components. The vendor's vulnerability profile centers on memory-safety and access-control weaknesses characteristic of client applications, particularly buffer-boundary violations and improper privilege management, alongside web-interface issues including cross-site request forgery; public exploit code has frequently become available for disclosed flaws. Defenders should track this vendor's updates closely given the application's deployment across consumer systems and its exposure to untrusted peer networks; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 53% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Utorrent over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 14, 2007
19 years ago
Most Recent CVE
Jun 17, 2022
1,498 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2007-0927HIGH
Heap-based buffer overflow in uTorrent 1.6 allows remote attackers to execute arbitrary code via a torrent file with a crafted announce header.
Feb 14, 20077.554NOYES
CVE-2008-4434HIGH
Stack-based buffer overflow in (1) uTorrent 1.7.7 build 8179 and earlier and (2) BitTorrent 6.0.3 build 8642 and earlier allows remote attackers to cause a denial of service (crash
Oct 3, 20089.342NOYES
CVE-2010-3129HIGH
Untrusted search path vulnerability in uTorrent 2.0.3 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via
Aug 26, 20109.341NOYES
CVE-2009-5134MEDIUM
Buffer overflow in the "create torrent dialog" functionality in uTorrent 1.8.3 build 15772, and possibly other versions before 1.8.3 (Build 16010), allows user-assisted remote atta
Jan 18, 20136.834NOYES
CVE-2008-6586MEDIUM
Cross-site request forgery (CSRF) vulnerability in gui/index.php in µTorrent (uTorrent) WebUI 0.315 allows remote attackers to (1) hijack the authentication of users for requests t
Apr 3, 20096.829NOYES
CVE-2018-25041HIGH
A vulnerability was found in uTorrent. It has been rated as critical. Affected by this issue is some unknown functionality of the component JSON RPC Server. The manipulation leads
Jun 17, 20228.828NONO
CVE-2018-25040HIGH
A vulnerability was found in uTorrent Web. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component HTTP RPC Server. The manipu
Jun 17, 20228.828NONO
CVE-2008-0071MEDIUM
The Web UI interface in (1) BitTorrent before 6.0.3 build 8642 and (2) uTorrent before 1.8beta build 10524 allows remote attackers to cause a denial of service (application crash)
Jun 16, 20084.326NOYES
CVE-2008-0364MEDIUM
Buffer overflow in (1) BitTorrent 6.0 and earlier; and (2) uTorrent 1.7.5 and earlier, and 1.8-alpha-7834 and earlier in the 1.8.x series; on Windows allows remote attackers to cau
Jan 18, 20085.026NOYES
CVE-2015-5474HIGH
BitTorrent and uTorrent allow remote attackers to inject command line parameters and execute arbitrary commands via a crafted URL using the (1) bittorrent or (2) magnet protocol.
Aug 13, 20159.324NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
50%
50%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network2 (16.7%)
Unknown10 (83.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (16.7%)
High0 (0.0%)
Unknown10 (83.3%)
User Interaction
None0 (0.0%)
Unknown10 (83.3%)
Required2 (16.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (16.7%)
Unknown10 (83.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
58.3% of CVEs· 83rd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Utorrent.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Utorrent — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Utorrent's Products

View all 3 CNAs →

Top CWEs