6.8
CVSSv2

CVE-2018-10756

Published: 15/05/2020 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Use-after-free in libtransmission/variant.c in Transmission prior to 3.00 allows remote malicious users to cause a denial of service (crash) or possibly execute arbitrary code via a crafted torrent file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

transmissionbt transmission

debian debian linux 8.0

debian debian linux 9.0

fedoraproject fedora 31

fedoraproject fedora 32

Vendor Advisories

Debian Bug report logs - #961461 transmission: CVE-2018-10756 Package: src:transmission; Maintainer for src:transmission is Sandro Tosi <morph@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 24 May 2020 19:09:01 UTC Severity: important Tags: security, upstream Found in versions transmis ...
Use-after-free in libtransmission/variantc in Transmission before 300 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted torrent file (CVE-2018-10756) ...