µTorrent is a lightweight peer-to-peer file-sharing application with a modest but widely distributed user base, encompassing the core client, web interface, and remote-access components. The vendor's vulnerability profile centers on memory-safety and access-control weaknesses characteristic of client applications, particularly buffer-boundary violations and improper privilege management, alongside web-interface issues including cross-site request forgery; public exploit code has frequently become available for disclosed flaws. Defenders should track this vendor's updates closely given the application's deployment across consumer systems and its exposure to untrusted peer networks; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Utorrent over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-0927HIGH Heap-based buffer overflow in uTorrent 1.6 allows remote attackers to execute arbitrary code via a torrent file with a crafted announce header. | Feb 14, 2007 | 7.5 | 54 | NO | YES |
CVE-2008-4434HIGH Stack-based buffer overflow in (1) uTorrent 1.7.7 build 8179 and earlier and (2) BitTorrent 6.0.3 build 8642 and earlier allows remote attackers to cause a denial of service (crash | Oct 3, 2008 | 9.3 | 42 | NO | YES |
CVE-2010-3129HIGH Untrusted search path vulnerability in uTorrent 2.0.3 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via | Aug 26, 2010 | 9.3 | 41 | NO | YES |
CVE-2009-5134MEDIUM Buffer overflow in the "create torrent dialog" functionality in uTorrent 1.8.3 build 15772, and possibly other versions before 1.8.3 (Build 16010), allows user-assisted remote atta | Jan 18, 2013 | 6.8 | 34 | NO | YES |
CVE-2008-6586MEDIUM Cross-site request forgery (CSRF) vulnerability in gui/index.php in µTorrent (uTorrent) WebUI 0.315 allows remote attackers to (1) hijack the authentication of users for requests t | Apr 3, 2009 | 6.8 | 29 | NO | YES |
CVE-2018-25041HIGH A vulnerability was found in uTorrent. It has been rated as critical. Affected by this issue is some unknown functionality of the component JSON RPC Server. The manipulation leads | Jun 17, 2022 | 8.8 | 28 | NO | NO |
CVE-2018-25040HIGH A vulnerability was found in uTorrent Web. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component HTTP RPC Server. The manipu | Jun 17, 2022 | 8.8 | 28 | NO | NO |
CVE-2008-0071MEDIUM The Web UI interface in (1) BitTorrent before 6.0.3 build 8642 and (2) uTorrent before 1.8beta build 10524 allows remote attackers to cause a denial of service (application crash) | Jun 16, 2008 | 4.3 | 26 | NO | YES |
CVE-2008-0364MEDIUM Buffer overflow in (1) BitTorrent 6.0 and earlier; and (2) uTorrent 1.7.5 and earlier, and 1.8-alpha-7834 and earlier in the 1.8.x series; on Windows allows remote attackers to cau | Jan 18, 2008 | 5.0 | 26 | NO | YES |
CVE-2015-5474HIGH BitTorrent and uTorrent allow remote attackers to inject command line parameters and execute arbitrary commands via a crafted URL using the (1) bittorrent or (2) magnet protocol. | Aug 13, 2015 | 9.3 | 24 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Utorrent.
Media articles that mention a CVE ID that affects a product developed by Utorrent — matched by CVE ID, not by vendor name.