bitcoin records
59 published records for vendor bitcoin.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 13.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-770 Allocation of Resources Without Limits or Throttling10
- CWE-400 Uncontrolled Resource Consumption5
- CWE-399 Resource Management Errors4
- CWE-190 Integer Overflow or Wraparound3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-20 Improper Input Validation2
The weakness classes this vendor ships most often: where to look.
CWEAll records
59 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2021-3401No exploit | Bitcoin Core before 0.19.0 might allow remote attackers to execute arbitrary code when another application unsafely passes the -platformplugbitcoin · bitcoin · CWE-88 | Critical9.8 | — | 10.5% | Feb 4, 2021 |
39Monitor | CVE-2015-20111No exploit | miniupnp before 4c90b87, as used in Bitcoin Core before 0.12 and other products, lacks checks for snprintf return values, leading to a buffeCWE-120 | Critical9.8 | — | 1.3% | Nov 18, 2024 |
32Monitor | CVE-2018-17144Proof of concept | Bitcoin Core 0.14.x before 0.14.3, 0.15.x before 0.15.2, and 0.16.x before 0.16.3 and Bitcoin Knots 0.14.x through 0.16.x before 0.16.3 allobitcoin · bitcoin core | High7.5 | — | 6.7% | Sep 19, 2018 |
32Monitor | CVE-2012-4684No exploit | The alert functionality in bitcoind and Bitcoin-Qt before 0.7.0 supports different character representations of the same signature data, butbitcoin · bitcoin-qt · CWE-399 | High7.8 | — | 2.9% | Mar 12, 2013 |
32Monitor | CVE-2013-2292No exploit | bitcoind and Bitcoin-Qt 0.8.0 and earlier allow remote attackers to cause a denial of service (electricity consumption) by mining a block tobitcoin · bitcoin-qt · CWE-399 | High7.8 | — | 2.6% | Mar 12, 2013 |
31Monitor | CVE-2012-1910No exploit | Bitcoin-Qt 0.5.0.x before 0.5.0.5; 0.5.1.x, 0.5.2.x, and 0.5.3.x before 0.5.3.1; and 0.6.x before 0.6.0rc4 on Windows does not use MinGW mulbitcoin · bitcoin-qt | High7.5 | — | 4.5% | Aug 6, 2012 |
31Monitor | CVE-2018-17145No exploit | Bitcoin Core 0.16.x before 0.16.2 and Bitcoin Knots 0.16.x before 0.16.2 allow remote denial of service via a flood of multiple transaction bitcoin · bitcoin core · CWE-400 | High7.5 | — | 4.1% | Sep 10, 2020 |
31Monitor | CVE-2017-9230No exploit | The Bitcoin Proof-of-Work algorithm does not consider a certain attack methodology related to 80-byte block headers with a variety of initiabitcoin · bitcoin · CWE-338 | High7.5 | — | 3.3% | May 24, 2017 |
31Monitor | CVE-2020-14198No exploit | Bitcoin Core 0.20.0 allows remote denial of service.bitcoin · bitcoin core | High7.5 | — | 3.2% | Sep 10, 2020 |
31Monitor | CVE-2010-5139No exploit | Integer overflow in wxBitcoin and bitcoind before 0.3.11 allows remote attackers to bypass intended economic restrictions and create many bibitcoin · bitcoin core · CWE-189 | High7.5 | — | 2.7% | Aug 6, 2012 |
31Monitor | CVE-2016-10725No exploit | In Bitcoin Core before v0.13.0, a non-final alert is able to block the special "final alert" (which is supposed to override all other alertsbitcoin · bitcoin core · CWE-310 | High7.5 | — | 2.5% | Jul 5, 2018 |
31Monitor | CVE-2016-10724No exploit | Bitcoin Core before v0.13.0 allows denial of service (memory exhaustion) triggered by the remote network alert system (deprecated since Q1 2bitcoin · bitcoin core · CWE-400 | High7.5 | — | 2.3% | Jul 5, 2018 |
31Monitor | CVE-2017-12842No exploit | Bitcoin Core before 0.14 allows an attacker to create an ostensibly valid SPV proof for a payment to a victim who uses an SPV wallet, even ibitcoin · bitcoin core · CWE-20 | High7.5 | — | 2.2% | Mar 16, 2020 |
31Monitor | CVE-2010-5141No exploit | wxBitcoin and bitcoind before 0.3.5 do not properly handle script opcodes in Bitcoin transactions, which allows remote attackers to spend bibitcoin · bitcoin core · CWE-264 | High7.5 | — | 2.2% | Aug 6, 2012 |
31Monitor | CVE-2015-3641No exploit | bitcoind and Bitcoin-Qt prior to 0.10.2 allow attackers to cause a denial of service (disabled functionality such as a client application crbitcoin · bitcoin core | High7.5 | — | 1.8% | Mar 12, 2020 |
30Monitor | CVE-2019-15947No exploit | In Bitcoin Core 0.18.0, bitcoin-qt stores wallet.dat data unencrypted in memory.bitcoin · bitcoin core · CWE-312 | High7.5 | — | 1.4% | Sep 5, 2019 |
30Monitor | CVE-2023-33297No exploit | Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumption) because draininbitcoin · bitcoin core · CWE-400 | High7.5 | — | 1.4% | May 22, 2023 |
30Monitor | CVE-2021-3195No exploit | bitcoind in Bitcoin Core through 0.21.0 can create a new file in an arbitrary directory (e.g., outside the ~/.bitcoin directory) via a dumpwbitcoin · bitcoin core · CWE-20 | High7.5 | — | 1.2% | Jan 26, 2021 |
30Monitor | CVE-2024-35202No exploit | Bitcoin Core before 25.0 allows remote attackers to cause a denial of service (blocktxn message-handling assertion and node exit) by includibitcoin · bitcoin core · CWE-770 | High7.5 | — | 0.9% | Oct 10, 2024 |
30Monitor | CVE-2019-25220No exploit | Bitcoin Core before 24.0.1 allows remote attackers to cause a denial of service (daemon crash) via a flood of low-difficulty header chains (bitcoin · bitcoin core · CWE-770 | High7.5 | — | 0.8% | Nov 18, 2024 |
30Monitor | CVE-2024-52915No exploit | Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption) via a crafted INV message.bitcoin · bitcoin core · CWE-770 | High7.5 | — | 0.6% | Nov 18, 2024 |
30Monitor | CVE-2024-52920No exploit | Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed GETDATA message.bitcoin · bitcoin core · CWE-770 | High7.5 | — | 0.6% | Nov 18, 2024 |
30Monitor | CVE-2023-37192No exploit | Memory management and protection issues in Bitcoin Core v22 allows attackers to modify the stored sending address within the app's memory, pbitcoin · bitcoin core · CWE-311 | High7.5 | — | 0.6% | Jul 6, 2023 |
30Monitor | CVE-2024-52914No exploit | In Bitcoin Core before 0.18.0, a node could be stalled for hours when processing the orphans of a crafted unconfirmed transaction.bitcoin · bitcoin core · CWE-770 | High7.5 | — | 0.5% | Nov 18, 2024 |
30Monitor | CVE-2024-52916No exploit | Bitcoin Core before 0.15.0 allows a denial of service (OOM kill of a daemon process) via a flood of minimum difficulty headers.bitcoin · bitcoin core · CWE-770 | High7.5 | — | 0.5% | Nov 18, 2024 |
- CVE-2021-340142Plan
Bitcoin Core before 0.19.0 might allow remote attackers to execute arbitrary code when another application unsafely passes the -platformplug
CriticalCVSS 9.8No exploitEPSS 10%bitcoin · bitcoinFeb 4, 2021
- CVE-2015-2011139Monitor
miniupnp before 4c90b87, as used in Bitcoin Core before 0.12 and other products, lacks checks for snprintf return values, leading to a buffe
CriticalCVSS 9.8No exploitEPSS 1%Nov 18, 2024
- CVE-2018-1714432Monitor
Bitcoin Core 0.14.x before 0.14.3, 0.15.x before 0.15.2, and 0.16.x before 0.16.3 and Bitcoin Knots 0.14.x through 0.16.x before 0.16.3 allo
HighCVSS 7.5Proof of conceptEPSS 7%bitcoin · bitcoin coreSep 19, 2018
- CVE-2012-468432Monitor
The alert functionality in bitcoind and Bitcoin-Qt before 0.7.0 supports different character representations of the same signature data, but
HighCVSS 7.8No exploitEPSS 3%bitcoin · bitcoin-qtMar 12, 2013
- CVE-2013-229232Monitor
bitcoind and Bitcoin-Qt 0.8.0 and earlier allow remote attackers to cause a denial of service (electricity consumption) by mining a block to
HighCVSS 7.8No exploitEPSS 3%bitcoin · bitcoin-qtMar 12, 2013
- CVE-2012-191031Monitor
Bitcoin-Qt 0.5.0.x before 0.5.0.5; 0.5.1.x, 0.5.2.x, and 0.5.3.x before 0.5.3.1; and 0.6.x before 0.6.0rc4 on Windows does not use MinGW mul
HighCVSS 7.5No exploitEPSS 5%bitcoin · bitcoin-qtAug 6, 2012
- CVE-2018-1714531Monitor
Bitcoin Core 0.16.x before 0.16.2 and Bitcoin Knots 0.16.x before 0.16.2 allow remote denial of service via a flood of multiple transaction
HighCVSS 7.5No exploitEPSS 4%bitcoin · bitcoin coreSep 10, 2020
- CVE-2017-923031Monitor
The Bitcoin Proof-of-Work algorithm does not consider a certain attack methodology related to 80-byte block headers with a variety of initia
HighCVSS 7.5No exploitEPSS 3%bitcoin · bitcoinMay 24, 2017
- CVE-2020-1419831Monitor
Bitcoin Core 0.20.0 allows remote denial of service.
HighCVSS 7.5No exploitEPSS 3%bitcoin · bitcoin coreSep 10, 2020
- CVE-2010-513931Monitor
Integer overflow in wxBitcoin and bitcoind before 0.3.11 allows remote attackers to bypass intended economic restrictions and create many bi
HighCVSS 7.5No exploitEPSS 3%bitcoin · bitcoin coreAug 6, 2012
- CVE-2016-1072531Monitor
In Bitcoin Core before v0.13.0, a non-final alert is able to block the special "final alert" (which is supposed to override all other alerts
HighCVSS 7.5No exploitEPSS 2%bitcoin · bitcoin coreJul 5, 2018
- CVE-2016-1072431Monitor
Bitcoin Core before v0.13.0 allows denial of service (memory exhaustion) triggered by the remote network alert system (deprecated since Q1 2
HighCVSS 7.5No exploitEPSS 2%bitcoin · bitcoin coreJul 5, 2018
- CVE-2017-1284231Monitor
Bitcoin Core before 0.14 allows an attacker to create an ostensibly valid SPV proof for a payment to a victim who uses an SPV wallet, even i
HighCVSS 7.5No exploitEPSS 2%bitcoin · bitcoin coreMar 16, 2020
- CVE-2010-514131Monitor
wxBitcoin and bitcoind before 0.3.5 do not properly handle script opcodes in Bitcoin transactions, which allows remote attackers to spend bi
HighCVSS 7.5No exploitEPSS 2%bitcoin · bitcoin coreAug 6, 2012
- CVE-2015-364131Monitor
bitcoind and Bitcoin-Qt prior to 0.10.2 allow attackers to cause a denial of service (disabled functionality such as a client application cr
HighCVSS 7.5No exploitEPSS 2%bitcoin · bitcoin coreMar 12, 2020
- CVE-2019-1594730Monitor
In Bitcoin Core 0.18.0, bitcoin-qt stores wallet.dat data unencrypted in memory.
HighCVSS 7.5No exploitEPSS 1%bitcoin · bitcoin coreSep 5, 2019
- CVE-2023-3329730Monitor
Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumption) because drainin
HighCVSS 7.5No exploitEPSS 1%bitcoin · bitcoin coreMay 22, 2023
- CVE-2021-319530Monitor
bitcoind in Bitcoin Core through 0.21.0 can create a new file in an arbitrary directory (e.g., outside the ~/.bitcoin directory) via a dumpw
HighCVSS 7.5No exploitEPSS 1%bitcoin · bitcoin coreJan 26, 2021
- CVE-2024-3520230Monitor
Bitcoin Core before 25.0 allows remote attackers to cause a denial of service (blocktxn message-handling assertion and node exit) by includi
HighCVSS 7.5No exploitEPSS 1%bitcoin · bitcoin coreOct 10, 2024
- CVE-2019-2522030Monitor
Bitcoin Core before 24.0.1 allows remote attackers to cause a denial of service (daemon crash) via a flood of low-difficulty header chains (
HighCVSS 7.5No exploitEPSS 1%bitcoin · bitcoin coreNov 18, 2024
- CVE-2024-5291530Monitor
Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption) via a crafted INV message.
HighCVSS 7.5No exploitEPSS 1%bitcoin · bitcoin coreNov 18, 2024
- CVE-2024-5292030Monitor
Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed GETDATA message.
HighCVSS 7.5No exploitEPSS 1%bitcoin · bitcoin coreNov 18, 2024
- CVE-2023-3719230Monitor
Memory management and protection issues in Bitcoin Core v22 allows attackers to modify the stored sending address within the app's memory, p
HighCVSS 7.5No exploitEPSS 1%bitcoin · bitcoin coreJul 6, 2023
- CVE-2024-5291430Monitor
In Bitcoin Core before 0.18.0, a node could be stalled for hours when processing the orphans of a crafted unconfirmed transaction.
HighCVSS 7.5No exploitEPSS 1%bitcoin · bitcoin coreNov 18, 2024
- CVE-2024-5291630Monitor
Bitcoin Core before 0.15.0 allows a denial of service (OOM kill of a daemon process) via a flood of minimum difficulty headers.
HighCVSS 7.5No exploitEPSS 1%bitcoin · bitcoin coreNov 18, 2024