Skip to main content

Vendor/product archive

bitcoin / bitcoin_core CVEs

Beta · best-effort

54 CVEs tagged to bitcoin / bitcoin_core0 Critical, 26 High, 28 Medium, 0 Low, 0 Unrated.

CVE-2024-55563

Published Dec 9, 2024

Bitcoin Core through 27.2 allows transaction-relay jamming via an off-chain protocol attack, a related issue to CVE-2024-52913. For example, the outcome of an HTLC (Hashed Timeloc…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52922

Published Nov 18, 2024

In Bitcoin Core before 25.1, an attacker can cause a node to not download the latest block, because there can be minutes of delay when an announcing peer stalls instead of complyi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52921

Published Nov 18, 2024

In Bitcoin Core before 25.0, a peer can affect the download state of other peers by sending a mutated block.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52920

Published Nov 18, 2024

Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed GETDATA message.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52919

Published Nov 18, 2024

Bitcoin Core before 22.0 has a CAddrMan nIdCount integer overflow and resultant assertion failure (and daemon exit) via a flood of addr messages.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52917

Published Nov 18, 2024

Bitcoin Core before 22.0 has a miniupnp infinite loop in which it allocates memory on the basis of random data received over the network, e.g., large M-SEARCH replies from a fake…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52916

Published Nov 18, 2024

Bitcoin Core before 0.15.0 allows a denial of service (OOM kill of a daemon process) via a flood of minimum difficulty headers.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52915

Published Nov 18, 2024

Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption) via a crafted INV message.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52914

Published Nov 18, 2024

In Bitcoin Core before 0.18.0, a node could be stalled for hours when processing the orphans of a crafted unconfirmed transaction.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-52913

Published Nov 18, 2024

In Bitcoin Core before 0.21.0, an attacker could prevent a node from seeing a specific unconfirmed transaction, because transaction re-requests are mishandled.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52912

Published Nov 18, 2024

Bitcoin Core before 0.21.0 allows a network split that is resultant from an integer overflow (calculating the time offset for newly connecting peers) and an abs64 logic bug.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-25220

Published Nov 18, 2024

Bitcoin Core before 24.0.1 allows remote attackers to cause a denial of service (daemon crash) via a flood of low-difficulty header chains (aka a "Chain Width Expansion" attack) b…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-35202

Published Oct 10, 2024

Bitcoin Core before 25.0 allows remote attackers to cause a denial of service (blocktxn message-handling assertion and node exit) by including transactions in a blocktxn message t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50428

Published Dec 9, 2023

In Bitcoin Core through 26.0 and Bitcoin Knots before 25.1.knots20231115, datacarrier size limits can be bypassed by obfuscating data as code (e.g., with OP_FALSE OP_IF), as explo…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37192

Published Jul 7, 2023

Memory management and protection issues in Bitcoin Core v22 allows attackers to modify the stored sending address within the app's memory, potentially allowing them to redirect Bi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-33297

Published May 22, 2023

Bitcoin Core before 24.1, when debug mode is not used, allows attackers to cause a denial of service (e.g., CPU consumption) because draining the inventory-to-send queue is ineffi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-3195

Published Jan 26, 2021

bitcoind in Bitcoin Core through 0.21.0 can create a new file in an arbitrary directory (e.g., outside the ~/.bitcoin directory) via a dumpwallet RPC call. NOTE: this reportedly d…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12842

Published Mar 16, 2020

Bitcoin Core before 0.14 allows an attacker to create an ostensibly valid SPV proof for a payment to a victim who uses an SPV wallet, even if that payment did not actually occur.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-20586

Published Mar 12, 2020

bitcoind and Bitcoin-Qt prior to 0.17.1 allow injection of arbitrary data into the debug log via an RPC call.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 54 CVEsPage 1 of 3