Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Qbittorrent Subscribe
Filtered by product Qbittorrent
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-13640 1 Qbittorrent 1 Qbittorrent 2020-08-24 7.5 HIGH 9.8 CRITICAL
In qBittorrent before 4.1.7, the function Application::runExternalProgram() located in app/application.cpp allows command injection via shell metacharacters in the torrent name parameter or current tracker parameter, as demonstrated by remote command execution via a crafted name within an RSS feed.
CVE-2017-12778 1 Qbittorrent 1 Qbittorrent 2019-07-02 3.6 LOW 7.1 HIGH
** DISPUTED ** The UI Lock feature in qBittorrent version 3.3.15 is vulnerable to Authentication Bypass, which allows Attack to gain unauthorized access to qBittorrent functions by tampering the affected flag value of the config file at the C:\Users\<username>\Roaming\qBittorrent pathname. The attacker must change the value of the "locked" attribute to "false" within the "Locking" stanza. NOTE: This is an intended behavior. See https://github.com/qbittorrent/qBittorrent/wiki/I-forgot-my-UI-lock-password.
CVE-2017-6503 1 Qbittorrent 1 Qbittorrent 2017-03-13 4.3 MEDIUM 6.1 MEDIUM
WebUI in qBittorrent before 3.3.11 did not escape many values, which could potentially lead to XSS.
CVE-2017-6504 1 Qbittorrent 1 Qbittorrent 2017-03-07 4.3 MEDIUM 6.1 MEDIUM
WebUI in qBittorrent before 3.3.11 did not set the X-Frame-Options header, which could potentially lead to clickjacking.